cbcvebase.

Redhat Virtualization vulnerabilities

128 known vulnerabilities affecting redhat/virtualization.

Total CVEs
128
CISA KEV
5
actively exploited
Public exploits
11
Exploited in wild
7
Severity breakdown
CRITICAL17HIGH59MEDIUM49LOW3

Vulnerabilities

Page 5 of 7
CVE-2018-5344P4HIGHCVSS 7.8v4.02018-01-12
CVE-2018-5344 [HIGH] CWE-362 CVE-2018-5344: In the Linux kernel through 4.14.13, drivers/block/loop.c mishandles lo_release serialization, which In the Linux kernel through 4.14.13, drivers/block/loop.c mishandles lo_release serialization, which allows attackers to cause a denial of service (__lock_acquire use-after-free) or possibly have unspecified other impact.
nvd
CVE-2021-3609P4HIGHCVSS 7.0v4.02022-03-03
CVE-2021-3609 [HIGH] CWE-362 CVE-2021-3609: .A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can .A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.
nvd
CVE-2020-35497P4MEDIUMCVSS 6.5v4.02020-12-21
CVE-2020-35497 [MEDIUM] CWE-284 CVE-2020-35497: A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other user A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email and public SSH key.
nvd
CVE-2020-25657P4MEDIUMCVSS 5.9v4.02021-01-12
CVE-2020-25657 [MEDIUM] CWE-385 CVE-2020-25657: A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher t A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.
nvd
CVE-2018-14661P4MEDIUMCVSS 6.5v4.02018-10-31
CVE-2018-14661 [MEDIUM] CWE-20 CVE-2018-14661: It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vulnerable to a format string attack. A remote, authenticated attacker could use this flaw to cause remote denial of service.
nvd
CVE-2018-1114P4MEDIUMCVSS 6.5v4.0v4.22018-09-11
CVE-2018-1114 [MEDIUM] CWE-400 CVE-2018-1114: It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when th It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.
nvd
CVE-2021-3501P4HIGHCVSS 7.1v4.02021-05-06
CVE-2021-3501 [HIGH] CWE-787 CVE-2021-3501: A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KV A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.
nvd
CVE-2017-7536P4HIGHCVSS 7.0v4.02018-01-10
CVE-2017-7536 [HIGH] CWE-592 CVE-2017-7536: In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the securi In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernate Validator, a potential privilege escalation can occur. By allowing the calling code to access those private members without the permi
nvd
CVE-2018-10855P4MEDIUMCVSS 5.9v4.02018-07-03
CVE-2018-10855 [MEDIUM] CWE-532 CVE-2018-10855: Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tas Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.
nvd
CVE-2012-3515P4HIGHCVSS 7.2v3.0v5.0+1 more2012-11-23
CVE-2012-3515 [HIGH] CWE-20 CVE-2012-3515: Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a vir Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers the overwrite of a "device model's address space."
nvd
CVE-2013-4344P4HIGHCVSS 7.2v3.02013-10-04
CVE-2013-4344 [HIGH] CWE-120 CVE-2013-4344: Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.
nvd
CVE-2017-15113P4MEDIUMCVSS 6.6v4.12018-07-27
CVE-2017-15113 [MEDIUM] CWE-212 CVE-2017-15113: ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file w ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents a risk when debug-level logs are shared with vendors or other parties to troubleshoot issues.
nvd
CVE-2018-10862P4MEDIUMCVSS 5.5v4.02018-07-27
CVE-2018-10862 [MEDIUM] CWE-22 CVE-2018-10862: WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, all WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.
nvd
CVE-2023-5366P4MEDIUMCVSS 5.5v4.02023-10-06
CVE-2023-5366 [MEDIUM] CWE-345 CVE-2023-5366: A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual m A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.
nvd
CVE-2015-1780P4MEDIUMCVSS 6.5v3.02019-11-22
CVE-2015-1780 [MEDIUM] CWE-863 CVE-2015-1780: oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-cente oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
nvd
CVE-2014-3467P4MEDIUMCVSS 5.0v6.02014-06-05
CVE-2014-3467 [MEDIUM] CVE-2014-3467: Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTL Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service (out-of-bounds read) via crafted ASN.1 data.
nvd
CVE-2018-1073P4MEDIUMCVSS 5.3v4.02018-06-19
CVE-2018-1073 [MEDIUM] CWE-209 CVE-2018-1073: The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-ex The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.
nvd
CVE-2009-3080P4HIGHCVSS 7.2v5.02009-11-20
CVE-2009-3080 [HIGH] CWE-129 CVE-2009-3080: Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.
nvd
CVE-2016-4020P4MEDIUMCVSS 6.5v4.02016-05-25
CVE-2016-4020 [MEDIUM] CVE-2016-4020: The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).
nvd
CVE-2018-1059P4MEDIUMCVSS 6.1v4.0v4.12018-04-24
CVE-2018-1059 [MEDIUM] CWE-200 CVE-2018-1059: The DPDK vhost-user interface does not check to verify that all the requested guest physical range i The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.
nvd
Redhat Virtualization vulnerabilities | cvebase