Vulnerabilities (CVE)

Filtered by vendor Eucalyptus Subscribe
Total 25 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2010-3905 1 Eucalyptus 1 Eucalyptus 2025-04-11 7.5 HIGH N/A
The password reset feature in the administrator interface for Eucalyptus 2.0.0 and 2.0.1 does not perform authentication, which allows remote attackers to gain privileges by sending password reset requests for other users.
CVE-2016-8528 1 Eucalyptus 1 Eucalyptus 2024-11-21 6.5 MEDIUM 8.8 HIGH
A Remote Escalation of Privilege vulnerability in HPE Helion Eucalyptus version 3.3.0 through 4.3.1 was found.
CVE-2016-8520 1 Eucalyptus 1 Eucalyptus 2024-11-21 6.5 MEDIUM 8.8 HIGH
HPE Helion Eucalyptus v4.3.0 and earlier does not correctly check IAM user's permissions for accessing versioned objects and ACLs. In some cases, authenticated users with S3 permissions could also access versioned data.
CVE-2014-5039 1 Eucalyptus 1 Eucalyptus Management Console 2024-11-21 6.8 MEDIUM 9.6 CRITICAL
Cross-site scripting (XSS) vulnerability in Eucalyptus Management Console (EMC) 4.0.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2013-4770 1 Eucalyptus 1 Eucalyptus Management Console 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Eucalyptus Management Console (EMC) 4.0.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.