cbcvebase.

Redhat Enterprise Virtualization vulnerabilities

36 known vulnerabilities affecting redhat/enterprise_virtualization.

Total CVEs
36
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH7MEDIUM18LOW8

Vulnerabilities

Page 1 of 2
CVE-2018-1111P2HIGHCVSS 7.5ExploitedPoCv4.0v4.22018-05-17
CVE-2018-1111 [HIGH] CWE-77 CVE-2018-1111: DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a comman DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on syst
nvd
CVE-2015-3456P3HIGHCVSS 7.7PoCv3.02015-05-13
CVE-2015-3456 [HIGH] CWE-119 CVE-2015-3456: The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local gue The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.
nvd
CVE-2015-5201P3HIGHCVSS 7.5fixed in 3.5.62020-02-25
CVE-2015-5201 [HIGH] CWE-306 CVE-2015-5201: VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-201 VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disable-ticketing and a VM is suspended and then restored, allows remote attackers to log in without authentication via un
nvd
CVE-2018-1117P3CRITICALCVSS 9.8v4.12018-06-20
CVE-2018-1117 [CRITICAL] CWE-532 CVE-2018-1117: ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resu ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.
nvd
CVE-2018-1074P3HIGHCVSS 7.2v4.02018-04-26
CVE-2018-1074 [HIGH] CWE-200 CVE-2018-1074: ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control.
nvd
CVE-2013-1591P3CRITICALCVSS 9.8v3.02013-01-31
CVE-2013-1591 [CRITICAL] CWE-190 CVE-2013-1591: Stack-based buffer overflow in libpixman, as used in Pale Moon before 15.4 and possibly other produc Stack-based buffer overflow in libpixman, as used in Pale Moon before 15.4 and possibly other products, has unspecified impact and context-dependent attack vectors. NOTE: this issue might be resultant from an integer overflow in the fast_composite_scaled_bilinear function in pixman-inlines.h, which triggers an infinite loop.
nvd
CVE-2008-3522P3CRITICALCVSS 10.0v3.52008-10-02
CVE-2008-3522 [CRITICAL] CWE-119 CVE-2008-3522: Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 m Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via vectors related to the mif_hdr_put function and use of vsprintf.
nvd
CVE-2012-3406P3MEDIUMCVSS 6.8v3.02014-02-10
CVE-2012-3406 [MEDIUM] CVE-2012-3406: The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probabl The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SPECS array, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (crash) or possi
nvd
CVE-2013-4282P4MEDIUMCVSS 5.0v3.02013-11-02
CVE-2013-4282 [MEDIUM] CWE-119 CVE-2013-4282: Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allo Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.
nvd
CVE-2017-2614P4MEDIUMCVSS 6.3v4.02018-07-27
CVE-2017-2614 [MEDIUM] CWE-20 CVE-2017-2614: When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to cor When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with expired passwords, gaining access to those accounts.
nvd
CVE-2013-2176P4HIGHCVSS 7.2v3.0v3.22013-08-28
CVE-2013-2176 [HIGH] CWE-399 CVE-2013-2176: Unquoted Windows search path vulnerability in the Red Hat Enterprise Virtualization Application Prov Unquoted Windows search path vulnerability in the Red Hat Enterprise Virtualization Application Provisioning Tool (RHEV-APT) in the rhev-guest-tools-iso package 3.2 allows local users to gain privileges via a Trojan horse application.
nvd
CVE-2013-2152P4HIGHCVSS 7.2v3.22014-01-21
CVE-2013-2152 [HIGH] CVE-2013-2152: Unquoted Windows search path vulnerability in the SPICE service, as used in Red Hat Enterprise Virtu Unquoted Windows search path vulnerability in the SPICE service, as used in Red Hat Enterprise Virtualization (RHEV) 3.2, allows local users to gain privileges via a crafted application in an unspecified folder.
nvd
CVE-2013-2151P4HIGHCVSS 7.2v3.0v3.22014-01-21
CVE-2013-2151 [HIGH] CVE-2013-2151: Unquoted Windows search path vulnerability in Red Hat Enterprise Virtualization (RHEV) 3 and 3.2 all Unquoted Windows search path vulnerability in Red Hat Enterprise Virtualization (RHEV) 3 and 3.2 allows local users to gain privileges via a crafted application in an unspecified folder.
nvd
CVE-2014-8167P4MEDIUMCVSS 5.9v3.02019-11-13
CVE-2014-8167 [MEDIUM] CWE-295 CVE-2014-8167: vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack
nvd
CVE-2012-3404P4MEDIUMCVSS 5.0v3.02014-02-10
CVE-2012-3404 [MEDIUM] CWE-189 CVE-2012-3404: The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (stack corruption and crash) via a format string that uses posi
nvd
CVE-2012-3405P4MEDIUMCVSS 5.0v3.02014-02-10
CVE-2012-3405 [MEDIUM] CVE-2012-3405: The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (segmentation fault and crash) via a format string with a large number
nvd
CVE-2016-6338P4MEDIUMCVSS 6.8v4.02017-04-20
CVE-2016-6338 [MEDIUM] CWE-284 CVE-2016-6338: ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin session timeout restriction via vectors related to UI selections, which trigger repeating queries.
nvd
CVE-2014-3485P4MEDIUMCVSS 4.0v3.42014-07-11
CVE-2014-3485 [MEDIUM] CWE-200 CVE-2014-3485: The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, related to an XML External Entity (XXE) issue.
nvd
CVE-2010-2784P4MEDIUMCVSS 6.6v2.22010-08-24
CVE-2010-2784 [MEDIUM] CWE-264 CVE-2010-2784: The subpage MMIO initialization functionality in the subpage_register function in exec.c in QEMU-KVM The subpage MMIO initialization functionality in the subpage_register function in exec.c in QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and KVM 83, does not properly select the index for access to the callback array, which allows guest OS users to cause a denial of service (guest OS crash)
nvd
CVE-2010-0429P4MEDIUMCVSS 6.6v2.22010-08-24
CVE-2010-0429 [MEDIUM] CWE-264 CVE-2010-0429: libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtuali libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not properly restrict the addresses upon which memory-management actions are performed, which allows guest OS users to cause a denial of service (guest OS crash) or possibly gain privileges via unspecified vector
nvd
Redhat Enterprise Virtualization vulnerabilities | cvebase