Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

609 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4)1.3%—Openstack Glance14/8/201517/6/2026
OpenStack Glance before 2015.1.1 (kilo) allows remote authenticated users to cause a denial of service (disk consumption) by repeatedly using the import task flow API to create images and then deleting them.
ModificadaAlta (9.3)13%—XENFedoraproject FedoraSuse Linux Enterprise DebuginfoSuse Linux Enterprise Server+2012/8/201517/6/2026
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
ModificadaMedia (5)4.4%—Debian LinuxHaproxyCanonical Ubuntu LinuxOpensuse Openstack Cloud+86/7/201517/6/2026
The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.
ModificadaMedia (6.8)2.6%—Canonical Ubuntu LinuxOpenstack IcehouseOpenstack JunoOpenstack Kilo25/6/201517/6/2026
OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.
ModificadaAlta (7.5)9.7%—QemuJuniper Junos SpaceCanonical Ubuntu LinuxDebian Linux+1415/6/201517/6/2026
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
ModificadaBaja (3.5)1.8%—Openstack HorizonOracle Solaris19/5/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the metadata to a (1) Glance image, (2) Nova flavor or (3) Host Aggregate.
ModificadaAlta (7.7)15%💥 ExploitQemuRedhat Enterprise VirtualizationRedhat OpenstackRedhat Enterprise Linux+113/5/201517/6/2026
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.
ModificadaMedia (4)2.9%—Openstack KeystoneOracle Solaris12/5/201517/6/2026
OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.
ModificadaMedia (5.5)4.0%—Openstack SwiftCanonical Ubuntu Linux17/4/201517/6/2026
OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.
ModificadaMedia (4.3)2.6%—Openstack KeystonemiddlewareOpenstack Python-keystoneclientCanonical Ubuntu Linux17/4/201517/6/2026
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a…
ModificadaAlta (10)5.2%—Redhat Openstack10/4/201517/6/2026
The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANGEME for the pcsd daemon, which allows remote attackers to execute arbitrary shell commands via unspecified vectors.
ModificadaMedia (5.1)1.1%—Openstack Nova1/4/201517/6/2026
OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for access to consoles via a crafted webpage.
ModificadaMedia (4)1.7%—Redhat Openstack10/3/201517/6/2026
The log-viewing function in the Red Hat redhat-access-plugin before 6.0.3 for OpenStack Dashboard (horizon) allows remote attackers to read arbitrary files via a crafted path.
ModificadaAlta (7.5)1.7%—Redhat OpenstackTheforeman Foreman9/3/201517/6/2026
Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allows remote attackers to bypass intended authentication and execute arbitrary API requests via a request without a certificate.
ModificadaMedia (4)2.1%—Openstack Image Registry AND Delivery Service (glance)24/2/201517/6/2026
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them, a different vulnerability than…
ModificadaMedia (4)2.0%—Openstack Image Registry AND Delivery Service (glance)24/2/201517/6/2026
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them before the uploads finish, a…
ModificadaMedia (4)2.9%—Redhat OpenstackOpenstack Image Registry AND Delivery Service (glance)23/1/201517/6/2026
OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.
ModificadaMedia (6.5)2.8%—Openstack Image Registry AND Delivery Service (glance)21/1/201517/6/2026
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.1.4 and 2014.2.x before 2014.2.2 allows remote authenticated users to read or delete arbitrary files via a full pathname in a filesystem: URL in the image location property. NOTE: this vulnerability exists because of an incomplete fix for…
ModificadaMedia (4)1.9%—Litech Router Advertisement DaemonOpenstack Neutron15/1/201517/6/2026
The L3 agent in OpenStack Neutron 2014.2.x before 2014.2.2, when using radvd 2.0+, allows remote authenticated users to cause a denial of service (blocked router update processing) by creating eight routers and assigning an ipv6 non-provider subnet to each.
ModificadaMedia (5.5)2.8%—Redhat OpenstackOpenstack Image Registry AND Delivery Service (glance)7/1/201517/6/2026
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image location property.
ModificadaMedia (5)2.9%—Openstack HorizonFedoraproject FedoraOpensuseOracle Solaris12/12/201417/6/2026
OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests to the login page.
ModificadaMedia (4)3.9%—Openstack NeutronFedoraproject FedoraRedhat Openstack24/11/201417/6/2026
OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration.
ModificadaMedia (6.5)1.4%—Openstack Keystone3/11/201417/6/2026
OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.
ModificadaBaja (2.1)0.45%—QemuDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+81/11/201417/6/2026
The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
ModificadaBaja (3.5)1.2%—Openstack Horizon31/10/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Groups panel in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote administrators to inject arbitrary web script or HTML via a user email address, a different vulnerability than CVE-2014-3475.
Orbitaley — Vulnerabilidades