Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2556▼ 314 respecto a la semana anterior
Críticas / altas1340▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

64 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.5%—Redhat Enterprise VirtualizationRedhat Enterprise Virtualization Hypervisor25/2/202017/6/2026
VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disable-ticketing and a VM is suspended and then restored, allows remote attackers to…
ModificadaAlta (7.5)1.9%—Python PyxmlRedhat Enterprise Virtualization HypervisorRedhat Enterprise Linux22/11/201916/6/2026
PyXML: Hash table collisions CPU usage Denial of Service
ModificadaMedia (5.9)0.73%—Redhat Enterprise VirtualizationRedhat VdsclientRedhat Virtual Desktop Server Manager13/11/201917/6/2026
vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack
ModificadaBaja (3.1)0.35%—Redhat Enterprise Virtualization Manager9/11/201916/6/2026
In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterprise Virtualization Manager. An attacker on the local network…
ModificadaMedia (5.5)0.42%—Redhat Virtual Desktop Server ManagerRedhat Enterprise VirtualizationRedhat Storage4/11/201916/6/2026
Insecure temporary file vulnerability in RedHat vsdm 4.9.6.
ModificadaMedia (6.1)0.91%—Redhat CloudformsRedhat Manageiq Enterprise Virtualization Manager1/11/201916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.5)2.7%—Redhat Gluster StorageDebian LinuxRedhat Enterprise Virtualization HostRedhat Enterprise Linux Server+131/10/201817/6/2026
The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' translator via the code handling the 'GF_XATTR_CLRLK_CMD' xattr in the 'pl_getxattr' function. A remote authenticated attacker could exploit this on a mounted volume to cause a denial of service.
ModificadaMedia (6.3)0.28%—Redhat Enterprise Virtualization27/7/201817/6/2026
When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with expired passwords, gaining access to those accounts.
ModificadaCrítica (9.8)0.99%—OvirtRedhat Enterprise Virtualization Manager26/6/201817/6/2026
ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext. Sharing the provisioning log might inadvertently leak database passwords.
ModificadaCrítica (9.8)1.4%—Ovirt-ansible-rolesRedhat Enterprise Virtualization20/6/201817/6/2026
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to…
ModificadaAlta (7.5)98%—Fedoraproject FedoraRedhat Enterprise VirtualizationRedhat Enterprise Virtualization HostRedhat Enterprise Linux+317/5/201817/6/2026
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary…
ModificadaAlta (7.8)18%—Debian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+78/5/201817/6/2026
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferred by MOV SS or POP SS, as demonstrated by (for example)…
ModificadaAlta (8.8)0.75%—Redhat Manageiq Enterprise Virtualization Manager1/5/201816/6/2026
Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.
ModificadaAlta (7.2)1.5%—OvirtRedhat Enterprise Virtualization26/4/201817/6/2026
ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control.
ModificadaCrítica (9.1)3.4%—Redhat Enterprise Virtualization Manager25/9/201717/6/2026
redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role on any Entity to execute arbitrary commands on any host in the RHEV environment.
ModificadaMedia (5.9)1.9%—Redhat Enterprise Virtualization Manager24/8/201717/6/2026
Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which might allow remote attackers to communicate with a system designated to be unreachable.
ModificadaMedia (5.5)0.36%—Redhat Enterprise Virtualization22/8/201717/6/2026
oVirt Engine discloses the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD in /var/log/ovirt-engine/engine.log file in RHEV before 4.0.
ModificadaAlta (7)0.50%—Redhat Enterprise Virtualization ServerRedhat OpenshiftRedhat Enterprise LinuxDebian Linux+219/6/201717/6/2026
libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that libffi is used by a number of other libraries. It was previously stated that this affects libffi version 3.2.1 but this appears to be incorrect. libffi prior to version 3.1…
ModificadaMedia (6.8)0.52%—Redhat Enterprise Virtualization20/4/201717/6/2026
ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin session timeout restriction via vectors related to UI selections, which trigger repeating queries.
ModificadaMedia (5.5)0.24%—Redhat Enterprise Virtualization14/12/201617/6/2026
Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file.
ModificadaBaja (3.3)0.35%—Redhat Enterprise Virtualization3/10/201617/6/2026
The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files.
ModificadaBaja (3.7)0.33%—Redhat Enterprise Virtualization8/9/201517/6/2026
The Web Admin interface in Red Hat Enterprise Virtualization Manager (RHEV-M) allows local users to bypass the timeout function by selecting a VM in the VM grid view.
ModificadaAlta (7.7)15%—QemuRedhat Enterprise VirtualizationRedhat OpenstackRedhat Enterprise Linux+113/5/201517/6/2026
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.
ModificadaBaja (2.1)0.38%—Redhat Enterprise Virtualization Manager1/5/201517/6/2026
Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin during service startup, which allows local users to obtain sensitive information by reading files in the directory.
ModificadaMedia (6.8)1.6%—Redhat Enterprise Virtualization Manager1/5/201517/6/2026
Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 ignores the permission to deny snapshot creation during live storage migration between domains, which allows remote authenticated users to cause a denial of service (prevent host start) by creating a long snapshot chain.