← Back

Virtualization Manager

virtualization_manager

Vendor: Redhat • 13 CVEs

CVEs (13)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
9Ansible Automation Platform Early Access
Ansible EngineEnterprise Linux+6 more
Jun 17, 2026
Mar 3, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulner...Show more
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.Show less
9Canonical
DebianFedoraproject+6 more
160Apollo 2000 Firmware
Apollo 4200 FirmwareCeleron 5305u Firmware+157 more
Jun 17, 2026
Nov 14, 2019
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
5F5
LodashNetapp+2 more
21Active Iq Unified Manager
Banking Extensibility WorkbenchBig Ip Access Policy Manager+18 more
Jun 17, 2026
Jul 26, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
2Ovirt
Redhat
2Ovirt
Virtualization Manager
Jun 17, 2026
Jul 11, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could be disclosed in log files (if playbooks are run with -v) or in playbooks...Show more
Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could be disclosed in log files (if playbooks are run with -v) or in playbooks stored on Metrics or Bastion hosts.Show less
11Backdropcms
DebianDrupal+8 more
105Agile Product Lifecycle Management For Process
Application ExpressApplication Service Level Management+102 more
Jun 17, 2026
Apr 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ p...Show more
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.Show less
4F5
GetbootstrapRedhat+1 more
16Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+13 more
Jun 17, 2026
Feb 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
3Debian
RedhatRsyslog
12Debian Linux
Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+9 more
Nov 21, 2024
Jan 25, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnera...Show more
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable.Show less
4Canonical
DebianQemu+1 more
6Debian Linux
OpenstackQemu+3 more
Nov 21, 2024
Oct 9, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact.
4Canonical
DebianQemu+1 more
5Debian Linux
QemuUbuntu Linux+2 more
Apr 28, 2026
Oct 9, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used.
3Canonical
DebianRedhat
9Ansible Engine
Debian LinuxGluster Storage+6 more
Nov 21, 2024
Jul 19, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2...Show more
Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as 'unsafe' and is not evaluated.Show less
12Arm
CanonicalDebian+9 more
282Atom C
Atom EAtom X5 E3930+279 more
May 29, 2026
May 22, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an atta...Show more
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.Show less
3Canonical
DpdkRedhat
9Ceph Storage
Data Plane Development KitEnterprise Linux+6 more
Nov 21, 2024
Apr 24, 2018
N/A· v4
6.1 MEDIUM· v3
2.9 LOW· v2
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead t...Show more
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.Show less
3Debian
OpenvswitchRedhat
5Debian Linux
OpenstackOpenvswitch+2 more
May 13, 2026
May 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_r...Show more
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.Show less