← Back

Enterprise Virtualization

enterprise_virtualization

Vendor: Redhat • 36 CVEs

CVEs (36)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
2Enterprise Virtualization
Enterprise Virtualization Hypervisor
Nov 21, 2024
Feb 25, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run...Show more
VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disable-ticketing and a VM is suspended and then restored, allows remote attackers to log in without authentication via unspecified vectors.Show less
1Redhat
3Enterprise Virtualization
VdsclientVirtual Desktop Server Manager
Nov 21, 2024
Nov 13, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack
1Redhat
3Enterprise Virtualization
StorageVirtual Desktop Server Manager
Nov 21, 2024
Nov 4, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Insecure temporary file vulnerability in RedHat vsdm 4.9.6.
1Redhat
1Enterprise Virtualization
Nov 21, 2024
Jul 27, 2018
N/A· v4
6.3 MEDIUM· v3
2.1 LOW· v2
When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the...Show more
When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with expired passwords, gaining access to those accounts.Show less
2Ovirt
Redhat
2Enterprise Virtualization
Ovirt Ansible Roles
Nov 21, 2024
Jun 20, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provis...Show more
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.Show less
2Fedoraproject
Redhat
7Enterprise Linux
Enterprise Linux DesktopEnterprise Linux Server+4 more
Nov 21, 2024
May 17, 2018
N/A· v4
7.5 HIGH· v3
7.9 HIGH· v2
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an at...Show more
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.Show less
2Ovirt
Redhat
2Enterprise Virtualization
Ovirt
Nov 21, 2024
Apr 26, 2018
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator co...Show more
ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control.Show less
1Redhat
1Enterprise Virtualization
May 13, 2026
Aug 22, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
oVirt Engine discloses the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD in /var/log/ovirt-engine/engine.log file in RHEV before 4.0.
1Redhat
1Enterprise Virtualization
May 13, 2026
Apr 20, 2017
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin session timeout restriction via vectors rela...Show more
ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin session timeout restriction via vectors related to UI selections, which trigger repeating queries.Show less
1Redhat
1Enterprise Virtualization
May 6, 2026
Dec 14, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file.
1Redhat
1Enterprise Virtualization
May 6, 2026
Oct 3, 2016
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files.
1Redhat
1Enterprise Virtualization
May 6, 2026
Sep 8, 2015
N/A· v4
N/A· v3
3.7 LOW· v2
The Web Admin interface in Red Hat Enterprise Virtualization Manager (RHEV-M) allows local users to bypass the timeout function by selecting a VM in the VM grid view.
3Qemu
RedhatXen
5Enterprise Linux
Enterprise VirtualizationOpenstack+2 more
May 6, 2026
May 13, 2015
N/A· v4
N/A· v3
7.7 HIGH· v2
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (...Show more
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.Show less
1Redhat
1Enterprise Virtualization
May 6, 2026
Dec 5, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listi...Show more
The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes.Show less
1Redhat
1Enterprise Virtualization
May 6, 2026
Aug 6, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
The oVirt storage backend in Red Hat Enterprise Virtualization 3.4 does not wipe memory snapshots when deleting a VM, even when wipe-after-delete (WAD) is configured for the VM's disk, which allows remote authenticated u...Show more
The oVirt storage backend in Red Hat Enterprise Virtualization 3.4 does not wipe memory snapshots when deleting a VM, even when wipe-after-delete (WAD) is configured for the VM's disk, which allows remote authenticated users with certain credentials to read portions of the deleted VM's memory and obtain sensitive information via an uninitialized storage volume.Show less
2Opensuse
Redhat
4Enterprise Linux
Enterprise VirtualizationLibvirt+1 more
May 6, 2026
Aug 3, 2014
N/A· v4
N/A· v3
1.2 LOW· v2
libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction wi...Show more
libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virDomainDefineXML, (2) virNetworkCreateXML, (3) virNetworkDefineXML, (4) virStoragePoolCreateXML, (5) virStoragePoolDefineXML, (6) virStorageVolCreateXML, (7) virDomainCreateXML, (8) virNodeDeviceCreateXML, (9) virInterfaceDefineXML, (10) virStorageVolCreateXMLFrom, (11) virConnectDomainXMLFromNative, (12) virConnectDomainXMLToNative, (13) virSecretDefineXML, (14) virNWFilterDefineXML, (15) virDomainSnapshotCreateXML, (16) virDomainSaveImageDefineXML, (17) virDomainCreateXMLWithFiles, (18) virConnectCompareCPU, or (19) virConnectBaselineCPU API method, related to an XML External Entity (XXE) issue. NOTE: this issue was SPLIT from CVE-2014-0179 per ADT3 due to different affected versions of some vectors.Show less
2Opensuse
Redhat
4Enterprise Linux
Enterprise VirtualizationLibvirt+1 more
May 6, 2026
Aug 3, 2014
N/A· v4
N/A· v3
1.9 LOW· v2
libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity refere...Show more
libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virConnectCompareCPU or (2) virConnectBaselineCPU API method, related to an XML External Entity (XXE) issue. NOTE: this issue was SPLIT per ADT3 due to different affected versions of some vectors. CVE-2014-5177 is used for other API methods.Show less
1Redhat
1Enterprise Virtualization
May 6, 2026
Jul 11, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, relate...Show more
The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, related to an XML External Entity (XXE) issue.Show less
3Canonical
GnuRedhat
4Enterprise Linux
Enterprise VirtualizationGlibc+1 more
Apr 29, 2026
Feb 10, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SPECS array, which allo...Show more
The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SPECS array, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (crash) or possibly execute arbitrary code via a crafted format string using positional parameters and a large number of format specifiers, a different vulnerability than CVE-2012-3404 and CVE-2012-3405.Show less
3Canonical
GnuRedhat
4Enterprise Linux
Enterprise VirtualizationGlibc+1 more
Apr 29, 2026
Feb 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SO...Show more
The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (segmentation fault and crash) via a format string with a large number of format specifiers that triggers "desynchronization within the buffer size handling," a different vulnerability than CVE-2012-3404.Show less