Show filters
147 Total Results
Displaying 41-50 of 147
Sort by:
Attacker Value
Unknown
CVE-2015-5741
Disclosure Date: February 08, 2020 (last updated February 21, 2025)
The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request that contains Content-Length and Transfer-Encoding header fields.
0
Attacker Value
Unknown
keystone_json_assignment backend granted access to any project for users in use…
Disclosure Date: January 17, 2020 (last updated February 21, 2025)
The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/keystone/user-project-map.json was assigned full "member" role access to every project. This allowed these users to access, modify, create and delete arbitrary resources, contrary to expectations.
0
Attacker Value
Unknown
CVE-2012-5474
Disclosure Date: December 30, 2019 (last updated November 27, 2024)
The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.
0
Attacker Value
Unknown
CVE-2013-2166
Disclosure Date: December 10, 2019 (last updated November 27, 2024)
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
0
Attacker Value
Unknown
CVE-2013-2167
Disclosure Date: December 10, 2019 (last updated November 27, 2024)
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
0
Attacker Value
Unknown
CVE-2015-5694
Disclosure Date: November 22, 2019 (last updated November 27, 2024)
Designate does not enforce the DNS protocol limit concerning record set sizes
0
Attacker Value
Unknown
CVE-2019-14818
Disclosure Date: November 14, 2019 (last updated November 08, 2023)
A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.
0
Attacker Value
Unknown
CVE-2013-6461
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
0
Attacker Value
Unknown
CVE-2013-6460
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
0
Attacker Value
Unknown
CVE-2013-2255
Disclosure Date: November 01, 2019 (last updated November 27, 2024)
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
0