Search CVE reports


Toggle filters

21 – 25 of 25 results

Status is adjusted based on your filters.


CVE-2014-0157

Medium priority

Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or...

1 affected package

horizon

Package 22.04 LTS
horizon —
Show less packages

CVE-2013-6858

Medium priority

Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2013.2 and earlier allow local users to inject arbitrary web script or HTML via an instance name to (1) "Volumes" or (2) "Network Topology" page.

1 affected package

horizon

Package 22.04 LTS
horizon —
Show less packages

CVE-2012-3540

Medium priority

Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to...

1 affected package

horizon

Package 22.04 LTS
horizon —
Show less packages

CVE-2012-2144

Medium priority

Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 allows remote attackers to hijack web sessions via the sessionid cookie.

1 affected package

horizon

Package 22.04 LTS
horizon —
Show less packages

CVE-2012-2094

Medium priority

Cross-site scripting (XSS) vulnerability in the refresh mechanism in the log viewer in horizon/static/horizon/js/horizon.js in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 and earlier allows remote attackers to...

1 affected package

horizon

Package 22.04 LTS
horizon —
Show less packages