Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2010-2235 |
|
Code Injection in cobbler (CVE-2010-2235)
code injection in cobbler (CVE-2010-2235). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.7` or later.
|
| CVE-2012-2395 |
|
Command Injection in cobbler (CVE-2012-2395)
command injection in cobbler (CVE-2012-2395). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.6.0` or later.
|
| CVE-2011-3587 |
|
Vulnerability in zope2 (CVE-2011-3587)
vulnerability in zope2 (CVE-2011-3587). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.13.10` or later.
|
| CVE-2013-4278 |
|
Vulnerability in nova (CVE-2013-4278)
vulnerability in nova (CVE-2013-4278). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.0.0a0` or later.
|
| CVE-2011-1340 |
|
Cross-Site Scripting (XSS) in plone (CVE-2011-1340)
cross-site scripting in plone (CVE-2011-1340). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.5.3` or later.
|
| CVE-2011-4030 |
|
Vulnerability in plone (CVE-2011-4030)
vulnerability in plone (CVE-2011-4030). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.2a3` or later.
|
| CVE-2014-0056 |
|
Authentication Bypass in neutron (CVE-2014-0056)
authentication bypass in neutron (CVE-2014-0056). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2013.2.3` or later.
|
| CVE-2014-0162 |
|
Vulnerability in glance (CVE-2014-0162)
vulnerability in glance (CVE-2014-0162). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2013.2.4` or later.
|
| CVE-2013-4155 |
|
Buffer Overflow in swift (CVE-2013-4155)
vulnerability in swift (CVE-2013-4155). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2014-3242 |
|
XXE (XML External Entity) in soappy (CVE-2014-3242)
vulnerability in soappy (CVE-2014-3242). Risk of unauthorized operations or information disclosure.
|
| CVE-2013-2209 |
|
Cross-Site Scripting (XSS) in reviewboard (CVE-2013-2209)
cross-site scripting in reviewboard (CVE-2013-2209). Data can be tampered with by attackers. Mitigation: upgrade to `1.7.10` or later.
|
| CVE-2013-2030 |
|
Vulnerability in python-keystoneclient (CVE-2013-2030)
vulnerability in python-keystoneclient (CVE-2013-2030). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.2.4` or later.
|
| CVE-2013-4179 |
|
Buffer Overflow in nova (CVE-2013-4179)
vulnerability in nova (CVE-2013-4179). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2013.2` or later.
|
| CVE-2013-2096 |
|
Vulnerability in nova (CVE-2013-2096)
vulnerability in nova (CVE-2013-2096). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.0.0a0` or later.
|
| CVE-2013-4477 |
|
Vulnerability in keystone (CVE-2013-4477)
vulnerability in keystone (CVE-2013-4477). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.0a0` or later.
|
| CVE-2014-3243 |
|
Buffer Overflow in soappy (CVE-2014-3243)
vulnerability in soappy (CVE-2014-3243). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.12.6` or later.
|
| CVE-2013-4497 |
|
Vulnerability in nova (CVE-2013-4497)
vulnerability in nova (CVE-2013-4497). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.0.0a0` or later.
|
| CVE-2013-6419 |
|
Information Disclosure in nova (CVE-2013-6419)
vulnerability in nova (CVE-2013-6419). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.0.0a0` or later.
|
| CVE-2016-5363 |
|
Vulnerability in neutron (CVE-2016-5363)
vulnerability in neutron (CVE-2016-5363). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.1.0` or later.
|
| CVE-2016-0737 |
|
Vulnerability in swift (CVE-2016-0737)
vulnerability in swift (CVE-2016-0737). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.4.0` or later.
|
| CVE-2014-3497 |
|
Cross-Site Scripting (XSS) in swift (CVE-2014-3497)
cross-site scripting in swift (CVE-2014-3497). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.0` or later.
|
| CVE-2014-0167 |
|
Vulnerability in nova (CVE-2014-0167)
vulnerability in nova (CVE-2014-0167). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2013.2.4` or later.
|
| CVE-2016-0757 |
|
Vulnerability in glance (CVE-2016-0757)
vulnerability in glance (CVE-2016-0757). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.0.2` or later.
|
| CVE-2014-9623 |
|
Vulnerability in glance (CVE-2014-9623)
vulnerability in glance (CVE-2014-9623). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.0.0a0` or later.
|
| CVE-2014-5356 |
|
Vulnerability in glance (CVE-2014-5356)
vulnerability in glance (CVE-2014-5356). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.0.0a0` or later.
|
| CVE-2011-4953 |
|
Vulnerability in cobbler (CVE-2011-4953)
vulnerability in cobbler (CVE-2011-4953). Risk of unauthorized operations or information disclosure. Exploitable via ``set_mgmt_parameters``. Mitigation: upgrade to `2.6.0` or later.
|
| CVE-2015-1851 |
|
Information Disclosure in cinder (CVE-2015-1851)
vulnerability in cinder (CVE-2015-1851). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.0.0a0` or later.
|
| CVE-2015-5251 |
|
Authorization Flaw in glance (CVE-2015-5251)
vulnerability in glance (CVE-2015-5251). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2015.1.2` or later.
|
| CVE-2016-4808 |
|
Cross-Site Request Forgery (CSRF) in web2py (CVE-2016-4808)
vulnerability in web2py (CVE-2016-4808). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.14.6` or later.
|
| CVE-2016-4807 |
|
Cross-Site Scripting (XSS) in web2py (CVE-2016-4807)
cross-site scripting in web2py (CVE-2016-4807). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-0738 |
|
Vulnerability in swift (CVE-2016-0738)
vulnerability in swift (CVE-2016-0738). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.5.1` or later.
|
| CVE-2013-4463 |
|
Vulnerability in nova (CVE-2013-4463)
vulnerability in nova (CVE-2013-4463). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.0.0a0` or later.
|
| CVE-2013-4469 |
|
Vulnerability in nova (CVE-2013-4469)
vulnerability in nova (CVE-2013-4469). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.0.0a0` or later.
|
| CVE-2015-5240 |
|
Vulnerability in neutron (CVE-2015-5240)
vulnerability in neutron (CVE-2015-5240). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.0.0` or later.
|
| CVE-2018-10657 |
|
Vulnerability in matrix-synapse (CVE-2018-10657)
vulnerability in matrix-synapse (CVE-2018-10657). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.28.1` or later.
|
| CVE-2011-0728 |
|
Cross-Site Scripting (XSS) in loggerhead (CVE-2011-0728)
cross-site scripting in loggerhead (CVE-2011-0728). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.18.1` or later.
|
| CVE-2015-5223 |
|
Information Disclosure in swift (CVE-2015-5223)
vulnerability in swift (CVE-2015-5223). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.4.0` or later.
|
| CVE-2008-6954 |
|
Code Injection in cobbler (CVE-2008-6954)
code injection in cobbler (CVE-2008-6954). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.9` or later.
|
| CVE-2015-1856 |
|
Vulnerability in swift (CVE-2015-1856)
vulnerability in swift (CVE-2015-1856). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.3.0` or later.
|
| CVE-2014-7960 |
|
Vulnerability in swift (CVE-2014-7960)
vulnerability in swift (CVE-2014-7960). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.2.0` or later.
|
| CVE-2014-3801 |
|
Information Disclosure in openstack-heat (CVE-2014-3801)
vulnerability in openstack-heat (CVE-2014-3801). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.0.0a0` or later.
|
| CVE-2010-4338 |
|
Vulnerability in ocrodjvu (CVE-2010-4338)
vulnerability in ocrodjvu (CVE-2010-4338). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.4.6-2` or later.
|
| CVE-2014-0157 |
|
Cross-Site Scripting (XSS) in horizon (CVE-2014-0157)
cross-site scripting in horizon (CVE-2014-0157). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2013.2.4` or later.
|
| CVE-2013-2161 |
|
Code Injection in swift (CVE-2013-2161)
code injection in swift (CVE-2013-2161). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.9.0` or later.
|
| CVE-2011-4596 |
|
Path Traversal in nova (CVE-2011-4596)
path traversal in nova (CVE-2011-4596). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.0.0a0` or later.
|
| CVE-2013-4185 |
|
Vulnerability in nova (CVE-2013-4185)
vulnerability in nova (CVE-2013-4185). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.0.0a0` or later.
|
| CVE-2012-1585 |
|
Vulnerability in nova (CVE-2012-1585)
vulnerability in nova (CVE-2012-1585). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.0.0a0` or later.
|
| CVE-2014-1934 |
|
Vulnerability in eyed3 (CVE-2014-1934)
vulnerability in eyed3 (CVE-2014-1934). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.7.5` or later.
|
| CVE-2014-3225 |
|
Path Traversal in cobbler (CVE-2014-3225)
path traversal in cobbler (CVE-2014-3225). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.4.7` or later.
|
| CVE-2018-1000225 |
|
Cross-Site Scripting (XSS) in cobbler (CVE-2018-1000225)
cross-site scripting in cobbler (CVE-2018-1000225). Risk of unauthorized operations or information disclosure.
|