Known vulnerabilities in Red Hat OpenStack - page 20

Software CPE: cpe:2.3:a:red_hat:red_hat_openstack:*:*:*:*:*:*:*:*
Total vulnerabilities: 406
Public exploits: 29
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.5

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Red Hat OpenStack Red Hat OpenStack is affected by 406 known vulnerabilities: 1 critical, 59 high, 203 medium, 143 low Critical High Medium Low

Vulnerabilities (406)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU31987 - Out-of-bounds read
CVE-2017-2615
CWE-125 Low
No
No
8, 9, 10.0 28.07.2020 SB2018070307
SB2017022707
SB2017022105
and 5 more
#VU31986 - Out-of-bounds read
CVE-2017-2620
CWE-125 Low
No
No
8, 9, 10.0 28.07.2020 SB2018070307
SB2017022708
SB2017032818
and 6 more
#VU11464 - Permissions, Privileges, and Access Controls
CVE-2017-12155
CWE-264 Low
No
No
- 28.03.2018 SB2017091908
#VU10733 - Buffer overflow
CVE-2016-1669
CWE-120 Low
No
No
- 27.02.2018 SB2016042302
SB2017040503
SB2018022115
and 7 more
#VU8433 - Integer underflow
CVE-2017-9214
CWE-191 Low
No
No
10.0, 11.0 14.09.2017 SB2017091404
SB2017101111
SB2017091241
and 7 more
#VU8432 - Improper input validation
CVE-2017-9263
CWE-20 Low
No
No
10.0, 11.0 14.09.2017 SB2017091404
SB2017101111
SB2017081805
and 7 more
#VU8431 - Buffer over-read
CVE-2017-9265
CWE-126 Low
No
No
10.0, 11.0 14.09.2017 SB2017091404
SB2017081805
SB2017091241
and 6 more
#VU7271 - Permissions, Privileges, and Access Controls
CVE-2017-2673
CWE-264 Low
No
No
- 30.06.2017 SB2017063010
SB2017101112
SB2017062821
and 2 more
#VU7105 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2017-7233
CWE-79 Low
No
No
- 16.06.2017 SB2017061603
SB2017040601
SB2017040602
and 12 more
#VU6848 - Exposure of sensitive information to an unauthorized actor
CVE-2017-7214
CWE-200 Medium
No
No
- 31.05.2017 SB2017053119
SB2017053120
SB2017062823
and 2 more
#VU6849 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2017-7400
CWE-79 Low
No
No
- 31.05.2017 SB2017053119
SB2017053120
SB2017062820
and 1 more
#VU38936 - Out-of-bounds read
CVE-2017-9264
CWE-125 High
No
No
10.0, 11.0 29.05.2017 SB2017052919
SB20170613107
SB2017080328
and 2 more
#VU6706 - Resource Management Errors
CVE-2017-7401
CWE-399 Low
No
No
- 24.05.2017 SB2017052420
SB2017021301
SB2017051809
and 8 more
#VU6640 - Improper Control of Generation of Code ('Code Injection')
CVE-2017-7481
CWE-94 Medium
No
No
10.0, 11.0 23.05.2017 SB2017052310
SB2017052601
SB2019022302
and 9 more
#VU6610 - Improper Authentication
CVE-2017-2637
CWE-287 Low
No
No
- 19.05.2017 SB2017051903
SB2017062021
SB2017062022
#VU6609 - Exposure of sensitive information to an unauthorized actor
CVE-2017-2621
CWE-200 Low
No
No
- 19.05.2017 SB2017051903
#VU6639 - Improper input validation
CVE-2017-7466
CWE-20 Medium
Available
No
10.0, 11.0 17.05.2017 SB2017052310
SB2017052601
SB2017070615
and 22 more
#VU7277 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2016-7103
CWE-79 Low
No
No
- 10.12.2016 SB2016072302
SB2017011903
SB2016120801
and 19 more
#VU946 - Permissions, Privileges, and Access Controls
CVE-2016-6662
CWE-264 High
Available
No
- 12.10.2016 SB2016091324
SB2016091326
SB2016092708
and 12 more
#VU698 - Cross-Site Request Forgery (CSRF)
CVE-2016-7401
CWE-352 Medium
No
No
8, 9 30.09.2016 SB2016100101
SB2016092701
SB2016092702
and 12 more


Showing elements 381 - 400 out of 406