← Vulnerability feed

Vulnerability record · CVE-2013-1664 · published 3 April 2013

CVE-2013-1664: Openstack cinder folsom memory buffer overflow vulnerability

Openstack · Cinder Folsom

The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.

5.0 CVSS 2.0 Medium EPSS 4.9% · top 8.2% CWE-119 · Memory buffer overflow
5.0CVSS 2.0 base score
4.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
20References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-1664 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2013-0261Openstack essex link following vulnerabilityA flaw was found in PackStack. A local user could exploit a symlink attack on a temporary file with a predictable name in the `/tmp` directory. This …EPSS 0.34%7.6CVE-2013-0335Openstack essex insufficient session expiration vulnerabilityOpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circu…EPSS 2.1%7.5CVE-2013-2161Openstack folsom code injection vulnerabilityXML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift r…EPSS 1.9%7.1CVE-2013-7130Openstack compute information exposure vulnerabilityThe i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, w…EPSS 2.4%6.8CVE-2013-1865Openstack folsom improper authentication vulnerabilityOpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remot…EPSS 2.6%6.5CVE-2013-0208Openstack essex permissions and access controls vulnerabilityThe boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from ot…EPSS 2.5%6.4CVE-2013-4497Openstack havana permissions and access controls vulnerabilityThe XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an…EPSS 1.8%5.5CVE-2013-0266Openstack essex incorrect default permissions vulnerabilityA flaw was found in the `puppetlabs-cinder` module, as used in PackStack. This vulnerability is due to incorrect file permissions, specifically world…EPSS 0.27%

Source: NIST National Vulnerability Database (record CVE-2013-1664), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.