Known vulnerabilities in Red Hat OpenStack 9

Version: 9
Software CPE: cpe:2.3:a:red_hat:red_hat_openstack:*:*:*:*:*:*:*:*
Total vulnerabilities: 30
Public exploits: 3
Known exploited (KEV): 1
Highest CVSSv4 Score: 8.8

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Red Hat OpenStack version 9 Red Hat OpenStack 9 is affected by 30 vulnerabilities: 3 high, 5 medium, 22 low Critical High Medium Low

Vulnerabilities (30)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU19193 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2019-10141
CWE-89 High
No
No
- 16.07.2019 SB2019071032
SB2019070914
SB2019081515
and 1 more
#VU19189 - Memory corruption
CVE-2018-20815
CWE-119 Medium
No
No
- 16.07.2019 SB2019042505
SB2019070604
SB2019073010
and 13 more
#VU19167 - Heap-based Buffer Overflow
CVE-2019-10192
CWE-122 Medium
No
No
- 14.07.2019 SB2019071109
SB2019071110
SB2019080804
and 9 more
#VU28395 - Exposure of sensitive information to an unauthorized actor
CVE-2018-12127
CWE-200 Low
No
No
- 30.05.2019 SB2019053010
SB2019051422
SB2019072469
and 67 more
#VU28396 - Exposure of sensitive information to an unauthorized actor
CVE-2018-12130
CWE-200 Low
No
No
- 30.05.2019 SB2019053011
SB2019051422
SB2019072469
and 67 more
#VU28397 - Exposure of sensitive information to an unauthorized actor
CVE-2018-12126
CWE-200 Low
No
No
- 30.05.2019 SB2019053012
SB2019051422
SB2019072469
and 67 more
#VU28398 - Exposure of sensitive information to an unauthorized actor
CVE-2019-11091
CWE-200 Low
No
No
- 30.05.2019 SB2019053013
SB2019051422
SB2019072469
and 67 more
#VU13375 - Heap-based Buffer Overflow
CVE-2018-11806
CWE-122 Low
No
No
- 16.06.2018 SB2018061802
SB2018080616
SB2018081714
and 9 more
#VU12911 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2018-3639
CWE-362 Low
No
No
- 22.05.2018 SB2018052201
SB2018052207
SB2018052208
and 142 more
#VU12552 - Out-of-bounds read
CVE-2017-11334
CWE-125 Low
No
No
- 10.05.2018 SB2018031522
SB2017121450
SB2017121451
and 5 more
#VU12300 - Memory corruption
CVE-2017-14167
CWE-119 High
No
No
- 30.04.2018 SB2017122006
SB2017121450
SB2017121451
and 6 more
#VU11845 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2017-1000385
CWE-300 Low
Public exploit available
Exploited
- 16.04.2018 SB2017120816
SB2018041212
SB2018031524
and 6 more
#VU11790 - Out-of-bounds write
CVE-2017-15289
CWE-787 Low
No
No
- 12.04.2018 SB2017112934
SB2017120814
SB2017120815
and 17 more
#VU11818 - Improper input validation
CVE-2017-13673
CWE-20 Low
No
No
- 11.04.2018 SB2018041304
SB2019032903
SB2018041048
and 5 more
#VU11819 - Use After Free
CVE-2017-13711
CWE-416 Low
No
No
- 11.04.2018 SB2018041304
SB2018060814
SB2018041048
and 1 more
#VU11644 - Out-of-bounds read
CVE-2017-13672
CWE-125 Low
No
No
- 10.04.2018 SB2018041005
SB2017120814
SB2017120815
and 12 more
#VU11232 - Uncontrolled Memory Allocation
CVE-2017-15124
CWE-789 Medium
No
No
- 23.03.2018 SB2018032301
SB2018032302
SB2018032704
and 7 more
#VU11231 - Resource exhaustion
CVE-2017-15119
CWE-400 Medium
No
No
- 23.03.2018 SB2018032301
SB2018032302
SB2018032704
and 4 more
#VU11194 - Insufficient Control of Network Message Volume (Network Amplification)
CVE-2018-1000115
CWE-406 Low
Public exploit available
No
- 21.03.2018 SB2018030509
SB2018060712
SB2018082314
and 5 more
#VU10864 - Improper input validation
CVE-2017-18191
CWE-20 Low
No
No
- 07.03.2018 SB2017122107
SB2018100209
SB2018091705


Showing elements 1 - 20 out of 30