Show filters
38 Total Results
Displaying 21-30 of 38
Sort by:
Attacker Value
Unknown

CVE-2015-5163

Disclosure Date: August 19, 2015 (last updated October 05, 2023)
The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticated users to read arbitrary files via a crafted backing file for a qcow2 image.
0
Attacker Value
Unknown

CVE-2015-3289

Disclosure Date: August 14, 2015 (last updated October 05, 2023)
OpenStack Glance before 2015.1.1 (kilo) allows remote authenticated users to cause a denial of service (disk consumption) by repeatedly using the import task flow API to create images and then deleting them.
0
Attacker Value
Unknown

CVE-2015-1881

Disclosure Date: February 24, 2015 (last updated October 05, 2023)
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them, a different vulnerability than CVE-2014-9684.
0
Attacker Value
Unknown

CVE-2014-9684

Disclosure Date: February 24, 2015 (last updated October 05, 2023)
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them before the uploads finish, a different vulnerability than CVE-2015-1881.
0
Attacker Value
Unknown

CVE-2014-9623

Disclosure Date: January 23, 2015 (last updated October 05, 2023)
OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.
0
Attacker Value
Unknown

CVE-2015-1195

Disclosure Date: January 21, 2015 (last updated October 05, 2023)
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.1.4 and 2014.2.x before 2014.2.2 allows remote authenticated users to read or delete arbitrary files via a full pathname in a filesystem: URL in the image location property. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9493.
0
Attacker Value
Unknown

CVE-2014-9493

Disclosure Date: January 07, 2015 (last updated October 05, 2023)
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image location property.
0
Attacker Value
Unknown

CVE-2014-5356

Disclosure Date: August 25, 2014 (last updated October 05, 2023)
OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image.
0
Attacker Value
Unknown

CVE-2014-0162

Disclosure Date: April 27, 2014 (last updated October 05, 2023)
The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or modify an image to execute arbitrary commands via a crafted location.
0
Attacker Value
Unknown

CVE-2014-1948

Disclosure Date: February 14, 2014 (last updated October 05, 2023)
OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARNING level logging is enabled, which allows local users to obtain sensitive information by reading the log.
0