Show filters
51 Total Results
Displaying 41-50 of 51
Sort by:
Attacker Value
Unknown

CVE-2015-3456

Disclosure Date: May 13, 2015 (last updated October 05, 2023)
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.
0
Attacker Value
Unknown

CVE-2015-0271

Disclosure Date: March 10, 2015 (last updated October 05, 2023)
The log-viewing function in the Red Hat redhat-access-plugin before 6.0.3 for OpenStack Dashboard (horizon) allows remote attackers to read arbitrary files via a crafted path.
0
Attacker Value
Unknown

CVE-2014-3691

Disclosure Date: March 09, 2015 (last updated October 05, 2023)
Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allows remote attackers to bypass intended authentication and execute arbitrary API requests via a request without a certificate.
0
Attacker Value
Unknown

CVE-2014-9623

Disclosure Date: January 23, 2015 (last updated October 05, 2023)
OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.
0
Attacker Value
Unknown

CVE-2014-9493

Disclosure Date: January 07, 2015 (last updated October 05, 2023)
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image location property.
0
Attacker Value
Unknown

CVE-2014-3615

Disclosure Date: November 01, 2014 (last updated October 05, 2023)
The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
0
Attacker Value
Unknown

CVE-2014-8333

Disclosure Date: October 31, 2014 (last updated October 05, 2023)
The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of service (disk consumption) by deleting an instance in the resize state.
0
Attacker Value
Unknown

CVE-2014-3708

Disclosure Date: October 31, 2014 (last updated October 05, 2023)
OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an IP filter in a list active servers API request.
0
Attacker Value
Unknown

CVE-2014-7230

Disclosure Date: October 08, 2014 (last updated October 05, 2023)
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.
0
Attacker Value
Unknown

CVE-2014-7231

Disclosure Date: October 08, 2014 (last updated October 05, 2023)
The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.
0