Search CVE reports


Toggle filters

41 – 50 of 68 results


CVE-2013-4469

Low priority

Some fixes available 2 of 4

OpenStack Compute (Nova) Folsom, Grizzly, and Havana, when use_cow_images is set to False, does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system...

1 affected package

nova

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nova
Show less packages

CVE-2013-4463

Low priority

Some fixes available 2 of 4

OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) via a compressed QCOW2...

1 affected package

nova

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nova
Show less packages

CVE-2013-4278

Medium priority
Fixed

The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to boot arbitrary flavors by guessing...

1 affected package

nova

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nova
Show less packages

CVE-2013-4261

Low priority

Some fixes available 1 of 3

OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during messaging, which allows remote attackers to cause a denial of service (connection...

1 affected package

nova

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nova
Show less packages

CVE-2013-4185

Medium priority
Fixed

Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-3 does not properly handle network source security group policy updates, which allows remote authenticated users to cause a...

1 affected package

nova

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nova
Show less packages

CVE-2013-4179

Medium priority
Fixed

The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE)...

1 affected package

nova

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nova
Show less packages

CVE-2013-2256

Medium priority
Fixed

OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to obtain sensitive information (flavor properties),...

1 affected package

nova

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nova
Show less packages

CVE-2013-2255

Low priority
Ignored

HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.

6 affected packages

swift, cinder, keystone, nova, python-keystoneclient, quantum

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
swift
cinder
keystone
nova
python-keystoneclient
quantum
Show less packages

CVE-2013-2096

Medium priority
Fixed

OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by creating an image with a large...

1 affected package

nova

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nova
Show less packages

CVE-2013-2030

Low priority
Ignored

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which...

1 affected package

nova

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nova
Show less packages