CVEs (36)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 2Enterprise Virtualization Enterprise Virtualization HypervisorNov 21, 2024 Feb 25, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run...Show more |
1Redhat 3Enterprise Virtualization VdsclientVirtual Desktop Server ManagerNov 21, 2024 Nov 13, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack |
1Redhat 3Enterprise Virtualization StorageVirtual Desktop Server ManagerNov 21, 2024 Nov 4, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Insecure temporary file vulnerability in RedHat vsdm 4.9.6. |
1Redhat 1Enterprise Virtualization Nov 21, 2024 Jul 27, 2018 N/A· v4 6.3 MEDIUM· v3 2.1 LOW· v2 When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the...Show more |
2Ovirt Redhat2Enterprise Virtualization Ovirt Ansible RolesNov 21, 2024 Jun 20, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provis...Show more |
2Fedoraproject Redhat7Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 May 17, 2018 N/A· v4 7.5 HIGH· v3 7.9 HIGH· v2 DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an at...Show more |
2Ovirt Redhat2Enterprise Virtualization OvirtNov 21, 2024 Apr 26, 2018 N/A· v4 7.2 HIGH· v3 4.0 MEDIUM· v2 ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator co...Show more |
1Redhat 1Enterprise Virtualization May 13, 2026 Aug 22, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 oVirt Engine discloses the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD in /var/log/ovirt-engine/engine.log file in RHEV before 4.0. |
1Redhat 1Enterprise Virtualization May 13, 2026 Apr 20, 2017 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin session timeout restriction via vectors rela...Show more |
1Redhat 1Enterprise Virtualization May 6, 2026 Dec 14, 2016 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file. |
The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files. |
The Web Admin interface in Red Hat Enterprise Virtualization Manager (RHEV-M) allows local users to bypass the timeout function by selecting a VM in the VM grid view. |
3Qemu RedhatXen5Enterprise Linux Enterprise VirtualizationOpenstack+2 moreMay 6, 2026 May 13, 2015 N/A· v4 N/A· v3 7.7 HIGH· v2 The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (...Show more |
The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listi...Show more |
The oVirt storage backend in Red Hat Enterprise Virtualization 3.4 does not wipe memory snapshots when deleting a VM, even when wipe-after-delete (WAD) is configured for the VM's disk, which allows remote authenticated u...Show more |
2Opensuse Redhat4Enterprise Linux Enterprise VirtualizationLibvirt+1 moreMay 6, 2026 Aug 3, 2014 N/A· v4 N/A· v3 1.2 LOW· v2 libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction wi...Show more |
2Opensuse Redhat4Enterprise Linux Enterprise VirtualizationLibvirt+1 moreMay 6, 2026 Aug 3, 2014 N/A· v4 N/A· v3 1.9 LOW· v2 libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity refere...Show more |
The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, relate...Show more |
3Canonical GnuRedhat4Enterprise Linux Enterprise VirtualizationGlibc+1 moreApr 29, 2026 Feb 10, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SPECS array, which allo...Show more |
3Canonical GnuRedhat4Enterprise Linux Enterprise VirtualizationGlibc+1 moreApr 29, 2026 Feb 10, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SO...Show more |