Known vulnerabilities in Red Hat OpenStack 8

Version: 8
Software CPE: cpe:2.3:a:red_hat:red_hat_openstack:*:*:*:*:*:*:*:*
Total vulnerabilities: 17
Public exploits: 3
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Red Hat OpenStack version 8 Red Hat OpenStack 8 is affected by 17 vulnerabilities: 3 high, 2 medium, 12 low Critical High Medium Low

Vulnerabilities (17)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU13375 - Heap-based Buffer Overflow
CVE-2018-11806
CWE-122 Low
No
No
- 16.06.2018 SB2018061802
SB2018080616
SB2018081714
and 9 more
#VU12911 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2018-3639
CWE-362 Low
No
No
- 22.05.2018 SB2018052201
SB2018052207
SB2018052208
and 142 more
#VU12552 - Out-of-bounds read
CVE-2017-11334
CWE-125 Low
No
No
- 10.05.2018 SB2018031522
SB2017121450
SB2017121451
and 5 more
#VU12301 - Data Handling
CVE-2017-10664
CWE-19 Low
No
No
- 30.04.2018 SB2017061210
SB2017121450
SB2017121451
and 5 more
#VU12300 - Memory corruption
CVE-2017-14167
CWE-119 High
No
No
- 30.04.2018 SB2017122006
SB2017121450
SB2017121451
and 6 more
#VU11790 - Out-of-bounds write
CVE-2017-15289
CWE-787 Low
No
No
- 12.04.2018 SB2017112934
SB2017120814
SB2017120815
and 17 more
#VU11818 - Improper input validation
CVE-2017-13673
CWE-20 Low
No
No
- 11.04.2018 SB2018041304
SB2019032903
SB2018041048
and 5 more
#VU11819 - Use After Free
CVE-2017-13711
CWE-416 Low
No
No
- 11.04.2018 SB2018041304
SB2018060814
SB2018041048
and 1 more
#VU11644 - Out-of-bounds read
CVE-2017-13672
CWE-125 Low
No
No
- 10.04.2018 SB2018041005
SB2017120814
SB2017120815
and 12 more
#VU11232 - Uncontrolled Memory Allocation
CVE-2017-15124
CWE-789 Medium
No
No
- 23.03.2018 SB2018032301
SB2018032302
SB2018032704
and 7 more
#VU11231 - Resource exhaustion
CVE-2017-15119
CWE-400 Medium
No
No
- 23.03.2018 SB2018032301
SB2018032302
SB2018032704
and 4 more
#VU11194 - Insufficient Control of Network Message Volume (Network Amplification)
CVE-2018-1000115
CWE-406 Low
Public exploit available
No
- 21.03.2018 SB2018030509
SB2018060712
SB2018082314
and 5 more
#VU8113 - Improper input validation
CVE-2017-7539
CWE-20 Low
No
No
- 06.09.2017 SB2017060234
SB2017090604
SB2017121450
and 5 more
#VU7105 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2017-7233
CWE-79 Low
No
No
- 16.06.2017 SB2017061603
SB2017040601
SB2017040602
and 12 more
#VU6610 - Improper Authentication
CVE-2017-2637
CWE-287 Low
No
No
- 19.05.2017 SB2017051903
SB2017062021
SB2017062022
#VU946 - Permissions, Privileges, and Access Controls
CVE-2016-6662
CWE-264 High
Public exploit available
No
- 12.10.2016 SB2016091324
SB2016091326
SB2016092708
and 12 more
#VU165 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2016-6186
CWE-79 High
Public exploit available
No
- 19.07.2016 SB2016071907
SB2016072204
SB2016072205
and 9 more