Known vulnerabilities in SUSE OpenStack Cloud - page 16

Vendor: SUSE
Software CPE: cpe:2.3:o:suse:suse_openstack_cloud:*:*:*:*:*:*:*:*
Total vulnerabilities: 1686
Public exploits: 73
Known exploited (KEV): 30
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting SUSE OpenStack Cloud SUSE OpenStack Cloud is affected by 1686 known vulnerabilities: 20 critical, 424 high, 541 medium, 701 low Critical High Medium Low

Vulnerabilities (1686)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU71398 - Insufficient Verification of Data Authenticity
CVE-2022-23491
CWE-345 High
No
No
- 20.01.2023 SB2023012034
SB2023012035
SB2023012036
and 51 more
#VU71332 - Improper input validation
CVE-2023-22809
CWE-20 Low
Available
No
- 18.01.2023 SB20230118100
SB20230118104
SB20230118105
and 55 more
#VU71239 - Integer overflow
CVE-2022-23521
CWE-190 High
No
No
- 17.01.2023 SB2023011739
SB2023011741
SB2023011804
and 52 more
#VU71238 - Heap-based Buffer Overflow
CVE-2022-41903
CWE-122 High
No
No
- 17.01.2023 SB2023011739
SB2023011741
SB2023011804
and 51 more
#VU71231 - Memory corruption
CVE-2023-23605
CWE-119 High
No
No
- 17.01.2023 SB2023011728
SB2023011729
SB2023011807
and 37 more
#VU71229 - Incorrect Regular Expression
CVE-2023-23603
CWE-185 Low
No
No
- 17.01.2023 SB2023011728
SB2023011729
SB2023011807
and 37 more
#VU71228 - Security Features
CVE-2023-23602
CWE-254 Medium
No
No
- 17.01.2023 SB2023011728
SB2023011729
SB2023011807
and 40 more
#VU71227 - Permissions, Privileges, and Access Controls
CVE-2023-23601
CWE-264 Low
No
No
- 17.01.2023 SB2023011728
SB2023011729
SB2023011807
and 38 more
#VU71224 - Permissions, Privileges, and Access Controls
CVE-2023-23598
CWE-264 Medium
No
No
- 17.01.2023 SB2023011728
SB2023011729
SB2023011807
and 37 more
#VU70506 - Improper input validation
CVE-2022-41861
CWE-20 Low
No
No
- 27.12.2022 SB2022122727
SB2022122728
SB2022122729
and 13 more
#VU70505 - NULL Pointer Dereference
CVE-2022-41860
CWE-476 Medium
No
No
- 27.12.2022 SB2022122727
SB2022122728
SB2022122729
and 14 more
#VU70504 - Exposure of sensitive information to an unauthorized actor
CVE-2022-41859
CWE-200 Low
No
No
- 27.12.2022 SB2022122727
SB2022122728
SB2022122729
and 14 more
#VU70238 - Out-of-bounds read
CVE-2022-42852
CWE-125 Medium
No
No
- 13.12.2022 SB2022121386
SB2022121387
SB2022121390
and 22 more
#VU70195 - Type confusion
CVE-2022-42856
CWE-843 Critical
No
Exploited
- 13.12.2022 SB2022121376
SB2022121386
SB2022121387
and 21 more
#VU70154 - Insufficient UI Warning of Dangerous Operations
CVE-2022-46877
CWE-357 Medium
No
No
- 13.12.2022 SB2022121330
SB2022121511
SB2023011007
and 36 more
#VU70145 - Memory corruption
CVE-2022-46871
CWE-119 High
No
No
- 13.12.2022 SB2022121330
SB2022121511
SB2023011007
and 37 more
#VU69151 - Security Features
CVE-2022-38023
CWE-254 High
No
No
- 09.11.2022 SB2022110912
SB2022121537
SB2022121801
and 46 more
#VU68967 - Stack-based buffer overflow
CVE-2022-3479
CWE-121 Medium
No
No
- 04.11.2022 SB2022110401
SB2022110406
SB2022121901
and 18 more
#VU67757 - Improper Access Control
CVE-2022-3100
CWE-284 Medium
No
No
- 29.09.2022 SB2022092961
SB2022092965
SB2022100505
and 3 more
#VU65380 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-33891
CWE-78 Medium
Available
Exploited
- 18.07.2022 SB2022071809
SB2023011157
SB2023102324
and 1 more


Showing elements 301 - 320 out of 1686