Show filters
25 Total Results
Displaying 11-20 of 25
Sort by:
Attacker Value
Unknown

CVE-2016-5363

Disclosure Date: June 17, 2016 (last updated November 25, 2024)
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended MAC-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via (1) a crafted DHCP discovery message or (2) crafted non-IP traffic.
0
Attacker Value
Unknown

CVE-2016-5362

Disclosure Date: June 17, 2016 (last updated November 25, 2024)
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended DHCP-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via a crafted DHCP discovery message.
0
Attacker Value
Unknown

CVE-2015-8914

Disclosure Date: June 17, 2016 (last updated November 25, 2024)
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via a link-local source address.
0
Attacker Value
Unknown

CVE-2015-5240

Disclosure Date: October 27, 2015 (last updated October 05, 2023)
Race condition in OpenStack Neutron before 2014.2.4 and 2015.1 before 2015.1.2, when using the ML2 plugin or the security groups AMQP API, allows remote authenticated users to bypass IP anti-spoofing controls by changing the device owner of a port to start with network: before the security group rules are applied.
0
Attacker Value
Unknown

CVE-2015-3221

Disclosure Date: August 26, 2015 (last updated October 05, 2023)
OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool.
0
Attacker Value
Unknown

CVE-2014-8153

Disclosure Date: January 15, 2015 (last updated October 05, 2023)
The L3 agent in OpenStack Neutron 2014.2.x before 2014.2.2, when using radvd 2.0+, allows remote authenticated users to cause a denial of service (blocked router update processing) by creating eight routers and assigning an ipv6 non-provider subnet to each.
0
Attacker Value
Unknown

CVE-2014-7821

Disclosure Date: November 24, 2014 (last updated October 05, 2023)
OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration.
0
Attacker Value
Unknown

CVE-2014-3632

Disclosure Date: October 07, 2014 (last updated November 08, 2023)
The default configuration in a sudoers file in the Red Hat openstack-neutron package before 2014.1.2-4, as used in Red Hat Enterprise Linux Open Stack Platform 5.0 for Red Hat Enterprise Linux 6, allows remote attackers to gain privileges via a crafted configuration file. NOTE: this vulnerability exists because of a CVE-2013-6433 regression.
0
Attacker Value
Unknown

CVE-2014-6414

Disclosure Date: October 02, 2014 (last updated October 05, 2023)
OpenStack Neutron before 2014.2.4 and 2014.1 before 2014.1.2 allows remote authenticated users to set admin network attributes to default values via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-4615

Disclosure Date: August 19, 2014 (last updated October 05, 2023)
The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).
0