Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
609 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4) | 1.3% | — | Openstack Glance | 14/8/2015 | 17/6/2026 | OpenStack Glance before 2015.1.1 (kilo) allows remote authenticated users to cause a denial of service (disk consumption) by repeatedly using the import task flow API to create images and then deleting them. | |
| Modificada | Alta (9.3) | 13% | — | XENFedoraproject FedoraSuse Linux Enterprise DebuginfoSuse Linux Enterprise Server+20 | 12/8/2015 | 17/6/2026 | The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors. | |
| Modificada | Media (5) | 4.4% | — | Debian LinuxHaproxyCanonical Ubuntu LinuxOpensuse Openstack Cloud+8 | 6/7/2015 | 17/6/2026 | The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request. | |
| Modificada | Media (6.8) | 2.6% | — | Canonical Ubuntu LinuxOpenstack IcehouseOpenstack JunoOpenstack Kilo | 25/6/2015 | 17/6/2026 | OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command. | |
| Modificada | Alta (7.5) | 9.7% | — | QemuJuniper Junos SpaceCanonical Ubuntu LinuxDebian Linux+14 | 15/6/2015 | 17/6/2026 | Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set. | |
| Modificada | Baja (3.5) | 1.8% | — | Openstack HorizonOracle Solaris | 19/5/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the metadata to a (1) Glance image, (2) Nova flavor or (3) Host Aggregate. | |
| Modificada | Alta (7.7) | 15% | 💥 Exploit | QemuRedhat Enterprise VirtualizationRedhat OpenstackRedhat Enterprise Linux+1 | 13/5/2015 | 17/6/2026 | The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM. | |
| Modificada | Media (4) | 2.9% | — | Openstack KeystoneOracle Solaris | 12/5/2015 | 17/6/2026 | OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs. | |
| Modificada | Media (5.5) | 4.0% | — | Openstack SwiftCanonical Ubuntu Linux | 17/4/2015 | 17/6/2026 | OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container. | |
| Modificada | Media (4.3) | 2.6% | — | Openstack KeystonemiddlewareOpenstack Python-keystoneclientCanonical Ubuntu Linux | 17/4/2015 | 17/6/2026 | The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a… | |
| Modificada | Alta (10) | 5.2% | — | Redhat Openstack | 10/4/2015 | 17/6/2026 | The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANGEME for the pcsd daemon, which allows remote attackers to execute arbitrary shell commands via unspecified vectors. | |
| Modificada | Media (5.1) | 1.1% | — | Openstack Nova | 1/4/2015 | 17/6/2026 | OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for access to consoles via a crafted webpage. | |
| Modificada | Media (4) | 1.7% | — | Redhat Openstack | 10/3/2015 | 17/6/2026 | The log-viewing function in the Red Hat redhat-access-plugin before 6.0.3 for OpenStack Dashboard (horizon) allows remote attackers to read arbitrary files via a crafted path. | |
| Modificada | Alta (7.5) | 1.7% | — | Redhat OpenstackTheforeman Foreman | 9/3/2015 | 17/6/2026 | Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allows remote attackers to bypass intended authentication and execute arbitrary API requests via a request without a certificate. | |
| Modificada | Media (4) | 2.1% | — | Openstack Image Registry AND Delivery Service (glance) | 24/2/2015 | 17/6/2026 | OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them, a different vulnerability than… | |
| Modificada | Media (4) | 2.0% | — | Openstack Image Registry AND Delivery Service (glance) | 24/2/2015 | 17/6/2026 | OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them before the uploads finish, a… | |
| Modificada | Media (4) | 2.9% | — | Redhat OpenstackOpenstack Image Registry AND Delivery Service (glance) | 23/1/2015 | 17/6/2026 | OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state. | |
| Modificada | Media (6.5) | 2.8% | — | Openstack Image Registry AND Delivery Service (glance) | 21/1/2015 | 17/6/2026 | The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.1.4 and 2014.2.x before 2014.2.2 allows remote authenticated users to read or delete arbitrary files via a full pathname in a filesystem: URL in the image location property. NOTE: this vulnerability exists because of an incomplete fix for… | |
| Modificada | Media (4) | 1.9% | — | Litech Router Advertisement DaemonOpenstack Neutron | 15/1/2015 | 17/6/2026 | The L3 agent in OpenStack Neutron 2014.2.x before 2014.2.2, when using radvd 2.0+, allows remote authenticated users to cause a denial of service (blocked router update processing) by creating eight routers and assigning an ipv6 non-provider subnet to each. | |
| Modificada | Media (5.5) | 2.8% | — | Redhat OpenstackOpenstack Image Registry AND Delivery Service (glance) | 7/1/2015 | 17/6/2026 | The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image location property. | |
| Modificada | Media (5) | 2.9% | — | Openstack HorizonFedoraproject FedoraOpensuseOracle Solaris | 12/12/2014 | 17/6/2026 | OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests to the login page. | |
| Modificada | Media (4) | 3.9% | — | Openstack NeutronFedoraproject FedoraRedhat Openstack | 24/11/2014 | 17/6/2026 | OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration. | |
| Modificada | Media (6.5) | 1.4% | — | Openstack Keystone | 3/11/2014 | 17/6/2026 | OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID. | |
| Modificada | Baja (2.1) | 0.45% | — | QemuDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+8 | 1/11/2014 | 17/6/2026 | The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution. | |
| Modificada | Baja (3.5) | 1.2% | — | Openstack Horizon | 31/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Groups panel in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote administrators to inject arbitrary web script or HTML via a user email address, a different vulnerability than CVE-2014-3475. |