Tagged “pip”
CVEs tagged pip, newest first.
4668 CVEsRSS
CVE-2013-4155MediumOpenStack Swift allows authenticated users to cause a denial of service
OpenStack Swift allows authenticated users to cause a denial of service
CVE-2014-0162MediumOpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability
OpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability
CVE-2013-1664MediumXML Entity Expansion (XEE) in Django
XML Entity Expansion (XEE) in Django
CVE-2011-0728LowLoggerhead XSS via filename
Loggerhead XSS via filename
CVE-2013-4510High· 7.5Tryton Directory Traversal vulnerability
Tryton Directory Traversal vulnerability
CVE-2014-3641MediumOpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2015-5251MediumOpenStack Image Service (Glance) allows remote authenticated users to bypass access restrictions
OpenStack Image Service (Glance) allows remote authenticated users to bypass access restrictions
CVE-2013-2030Medium· 4.3OpenStack Nova uses insecure keystone middleware tmpdir by default
OpenStack Nova uses insecure keystone middleware tmpdir by default
CVE-2011-4030HighPlone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable
Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable
CVE-2016-4807Medium· 4.8PoCWeb2py Reflected XSS vulnerability
Web2py Reflected XSS vulnerability
CVE-2008-6954HighCobbler Web Interface Kickstart Template Remote Privilege Escalation Vulnerability
Cobbler Web Interface Kickstart Template Remote Privilege Escalation Vulnerability
CVE-2014-0167MediumOpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requests
OpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requests
CVE-2012-4413MediumOpenStack Keystone does not invalidate existing tokens when granting or revoking roles
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles
CVE-2013-2096MediumOpenStack Compute (Nova) does not verify the virtual size of a QCOW2 image
OpenStack Compute (Nova) does not verify the virtual size of a QCOW2 image
CVE-2010-2235HighCobbler is vulnerable to code injection
Cobbler is vulnerable to code injection
CVE-2013-4179MediumOpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack
OpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack
CVE-2017-7266Medium· 6.1Netflix Security Monkey Open Redirect vulnerability
Netflix Security Monkey Open Redirect vulnerability
CVE-2014-9623MediumOpenStack Glance Bypass the storage quota and Denial of service
OpenStack Glance Bypass the storage quota and Denial of service
CVE-2011-4953MediumCobbler vulnerable to code injection via unsafe YAML loading
Cobbler vulnerable to code injection via unsafe YAML loading
CVE-2015-5240LowOpenStack Neutron Race condition vulnerability
OpenStack Neutron Race condition vulnerability
CVE-2015-5286MediumOpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service
OpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service
CVE-2016-4808Medium· 4.5PoCWeb2py Cross-Site Request Forgery vulnerability
Web2py Cross-Site Request Forgery vulnerability
CVE-2014-7960MediumOpenStack Swift metadata constraints are not correctly enforced
OpenStack Swift metadata constraints are not correctly enforced
CVE-2012-2395HighCobbler subject to Command Injection
Cobbler subject to Command Injection
CVE-2016-0738High· 7.5OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service
OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service
CVE-2013-4477LowOpenStack Identity Keystone Privilege Escalation vulnerability
OpenStack Identity Keystone Privilege Escalation vulnerability
CVE-2011-1340MediumPlone XSS Vulnerability
Plone XSS Vulnerability
CVE-2016-5363High· 8.2OpenStack Neutron Intended MAC-spoofing protection mechanism bypass
OpenStack Neutron Intended MAC-spoofing protection mechanism bypass
CVE-2015-1851MediumOpenStack Cinder file disclosure in image convert
OpenStack Cinder file disclosure in image convert
CVE-2015-3156Medium· 5.5Openstack DBaaS (Trove) Improper Link Resolution Before File Access
Openstack DBaaS (Trove) Improper Link Resolution Before File Access