cbcvebase.

Redhat Enterprise Virtualization vulnerabilities

36 known vulnerabilities affecting redhat/enterprise_virtualization.

Total CVEs
36
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH7MEDIUM18LOW8

Vulnerabilities

Page 2 of 2
CVE-2010-0431P4MEDIUMCVSS 6.6v2.22010-08-24
CVE-2010-0431 [MEDIUM] CWE-20 CVE-2010-0431: QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and KVM 83, does not properly validate guest QXL driver pointers, which allows guest OS users to cause a denial of service (invalid pointer dereference and guest OS crash) or possibly gain privileges via unspecified vectors.
nvd
CVE-2010-0428P4MEDIUMCVSS 6.6v2.22010-08-24
CVE-2010-0428 [MEDIUM] CWE-20 CVE-2010-0428: libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtuali libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not properly validate guest QXL driver pointers, which allows guest OS users to cause a denial of service (invalid pointer dereference and guest OS crash) or possibly gain privileges via unspecified vectors.
nvd
CVE-2010-2811P4MEDIUMCVSS 5.7v2.22010-08-24
CVE-2010-2811 [MEDIUM] CVE-2010-2811: Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization (RHEV) 2.2 does not prope Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization (RHEV) 2.2 does not properly accept TCP connections for SSL sessions, which allows remote attackers to cause a denial of service (daemon outage) via crafted SSL traffic.
nvd
CVE-2013-4280P4MEDIUMCVSS 5.5v3.02019-11-04
CVE-2013-4280 [MEDIUM] CWE-668 CVE-2013-4280: Insecure temporary file vulnerability in RedHat vsdm 4.9.6. Insecure temporary file vulnerability in RedHat vsdm 4.9.6.
nvd
CVE-2016-6310P4MEDIUMCVSS 5.5≤ 3.62017-08-22
CVE-2016-6310 [MEDIUM] CWE-200 CVE-2016-6310: oVirt Engine discloses the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD in /var/log/ovirt-engine/engine.log oVirt Engine discloses the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD in /var/log/ovirt-engine/engine.log file in RHEV before 4.0.
nvd
CVE-2016-4443P4MEDIUMCVSS 5.5v3.62016-12-14
CVE-2016-4443 [MEDIUM] CWE-532 CVE-2016-4443: Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, c Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file.
nvd
CVE-2013-4181P4MEDIUMCVSS 4.3v3.0v3.22013-09-16
CVE-2013-4181 [MEDIUM] CWE-79 CVE-2013-4181: Cross-site scripting (XSS) vulnerability in the addAlert function in the RedirectServlet servlet in Cross-site scripting (XSS) vulnerability in the addAlert function in the RedirectServlet servlet in oVirt Engine and Red Hat Enterprise Virtualization Manager (RHEV-M), as used in Red Hat Enterprise Virtualization 3 and 3.2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2014-5177P4LOWCVSS 1.2v3.02014-08-03
CVE-2014-5177 [LOW] CVE-2014-5177: libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virDomainDefineXML, (2) virNetworkCreateXML, (3) virNetworkDefineXML, (4) virStoragePoolCreateXML, (5) virStora
nvd
CVE-2014-3559P4LOWCVSS 3.5v3.42014-08-06
CVE-2014-3559 [LOW] CWE-264 CVE-2014-3559: The oVirt storage backend in Red Hat Enterprise Virtualization 3.4 does not wipe memory snapshots wh The oVirt storage backend in Red Hat Enterprise Virtualization 3.4 does not wipe memory snapshots when deleting a VM, even when wipe-after-delete (WAD) is configured for the VM's disk, which allows remote authenticated users with certain credentials to read portions of the deleted VM's memory and obtain sensitive information via an uninitialized storage
nvd
CVE-2010-0435P4MEDIUMCVSS 4.6v2.22010-08-24
CVE-2010-0435 [MEDIUM] CVE-2010-0435: The Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2, and KVM 83, wh The Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2, and KVM 83, when the Intel VT-x extension is enabled, allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via vectors related to instruction emulation.
nvd
CVE-2015-1841P4LOWCVSS 3.7v3.02015-09-08
CVE-2015-1841 [LOW] CWE-17 CVE-2015-1841: The Web Admin interface in Red Hat Enterprise Virtualization Manager (RHEV-M) allows local users to The Web Admin interface in Red Hat Enterprise Virtualization Manager (RHEV-M) allows local users to bypass the timeout function by selecting a VM in the VM grid view.
nvd
CVE-2014-0179P4LOWCVSS 1.9v3.02014-08-03
CVE-2014-0179 [LOW] CWE-20 CVE-2014-0179: libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virConnectCompareCPU or (2) virConnectBaselineCPU API method, related to an XML External Entity (XXE) issue. NOTE: this is
nvd
CVE-2013-0167P4LOWCVSS 2.7v3.0v3.22013-08-19
CVE-2013-0167 [LOW] CVE-2013-0167: VDSM in Red Hat Enterprise Virtualization 3 and 3.2 allows privileged guest users to cause the host VDSM in Red Hat Enterprise Virtualization 3 and 3.2 allows privileged guest users to cause the host to become "unavailable to the managment server" via guestInfo dictionaries with "unexpected fields."
nvd
CVE-2016-5432P4LOWCVSS 3.3v4.02016-10-03
CVE-2016-5432 [LOW] CWE-532 CVE-2016-5432: The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows l The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files.
nvd
CVE-2013-4236P4LOWCVSS 2.7v3.0v3.22013-08-19
CVE-2013-4236 [LOW] CVE-2013-4236: VDSM in Red Hat Enterprise Virtualization 3 and 3.2 allows privileged guest users to cause the host VDSM in Red Hat Enterprise Virtualization 3 and 3.2 allows privileged guest users to cause the host to become "unavailable to the managment server" via invalid XML characters in a guest agent response. NOTE: this issue is due to an incomplete fix for CVE-2013-0167.
nvd
CVE-2014-3561P4LOWCVSS 2.1v3.42014-12-05
CVE-2014-3561 [LOW] CWE-200 CVE-2014-3561: The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL databas The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes.
nvd
Redhat Enterprise Virtualization vulnerabilities | cvebase