Vulnerabilities > Novell > Suse Cloud

DATE CVE VULNERABILITY TITLE RISK
2014-04-04 CVE-2014-0592 Permissions, Privileges, and Access Controls vulnerability in multiple products
Barclamp (aka barclamp-network) 1.7 for the Crowbar Framework, as used in SUSE Cloud 3, does not enable netfilter on bridges when creating new instances, which allows remote attackers to bypass security group restrictions via unspecified vectors, related to floating IPs.
network
low complexity
crowbar novell CWE-264
7.5
2013-12-02 CVE-2012-0434 Permissions, Privileges, and Access Controls vulnerability in Novell Suse Cloud 1.0
The server in Crowbar, as used in SUSE Cloud 1.0, uses weak permissions for the production.log file, which has unspecified impact and attack vectors.
network
low complexity
novell CWE-264
critical
10.0