Redhat Libvirt vulnerabilities
90 known vulnerabilities affecting redhat/libvirt.
Total CVEs
90
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH16MEDIUM58LOW15
Vulnerabilities
Page 5 of 5
CVE-2012-2693P4LOWCVSS 3.7≤ 0.9.11v0.0.1+65 more2012-06-17
CVE-2012-2693 [LOW] CWE-264 CVE-2012-2693: libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multi
libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associated with a guest and might allow local users to access unintended USB devices.
nvdosv
CVE-2013-1766P4LOWCVSS 3.6≤ 1.0.2v0.0.1+70 more2013-03-20
CVE-2013-1766 [LOW] CWE-264 CVE-2013-1766: libvirt 1.0.2 and earlier sets the group owner to kvm for device files, which allows local users to
libvirt 1.0.2 and earlier sets the group owner to kvm for device files, which allows local users to write to these files via unspecified vectors.
nvdosv
CVE-2011-1486P4LOWCVSS 3.3≤ 0.8.8v0.0.1+53 more2011-05-31
CVE-2011-1486 [LOW] CWE-399 CVE-2011-1486: libvirtd in libvirt before 0.9.0 does not use thread-safe error reporting, which allows remote attac
libvirtd in libvirt before 0.9.0 does not use thread-safe error reporting, which allows remote attackers to cause a denial of service (crash) by causing multiple threads to report errors at the same time.
nvdosv
CVE-2014-0179P4LOWCVSS 1.9v0.7.5v0.7.6+69 more2014-08-03
CVE-2014-0179 [LOW] CWE-20 CVE-2014-0179: libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block
libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virConnectCompareCPU or (2) virConnectBaselineCPU API method, related to an XML External Entity (XXE) issue. NOTE: this is
nvdosv
CVE-2010-2242P4LOWCVSS 2.1≥ 0, < 0.8.3-12010-08-19
CVE-2010-2242 [LOW] CVE-2010-2242: Red Hat libvirt 0
Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to bypass intended access restrictions by leveraging IP address and source-port values, as demonstrated by copying and deleting an NFS directory tree.
osv
CVE-2013-4292P4LOWCVSS 2.1v1.1.0v1.1.12013-09-30
CVE-2013-4292 [LOW] CWE-399 CVE-2013-4292: libvirt 1.1.0 and 1.1.1 allows local users to cause a denial of service (memory consumption) via a l
libvirt 1.1.0 and 1.1.1 allows local users to cause a denial of service (memory consumption) via a large number of domain migrate parameters in certain RPC calls in (1) daemon/remote.c and (2) remote/remote_driver.c.
nvdosv
CVE-2014-8135P4LOWCVSS 2.1≥ 0, < 1.2.9-72014-12-19
CVE-2014-8135 [LOW] CVE-2014-8135: The storageVolUpload function in storage/storage_driver
The storageVolUpload function in storage/storage_driver.c in libvirt before 1.2.11 does not check a certain return value, which allows local users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted offset value in a "virsh vol-upload" command.
osv
CVE-2014-8136P4LOWCVSS 2.1≥ 0, < 1.2.9-72014-12-19
CVE-2014-8136 [LOW] CVE-2014-8136: The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver
The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.
osv
CVE-2013-6436P4LOWCVSS 2.1v1.0.5v1.0.5.1+12 more2014-01-07
CVE-2013-6436 [LOW] CWE-264 CVE-2013-6436: The lxcDomainGetMemoryParameters method in lxc/lxc_driver.c in libvirt 1.0.5 through 1.2.0 does not
The lxcDomainGetMemoryParameters method in lxc/lxc_driver.c in libvirt 1.0.5 through 1.2.0 does not properly check the status of LXC guests when reading memory tunables, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) via a guest in the shutdown status, as demonstrated by the "virsh memtune" command.
nvdosv
CVE-2013-7336P4LOWCVSS 1.9≤ 1.1.2v1.0.0+14 more2014-05-07
CVE-2013-7336 [LOW] CVE-2013-7336: The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not pro
The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not properly enter a monitor when performing seamless SPICE migration, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) by causing domblkstat to be called at the same time as the qemuMonitorGetSpiceMigrationStatus functi
nvdosv
← Previous5 / 5