Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 314 respecto a la semana anterior
Críticas / altas1340▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | — | Redhat Enterprise VirtualizationRedhat Enterprise Virtualization Hypervisor | 25/2/2020 | 17/6/2026 | VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disable-ticketing and a VM is suspended and then restored, allows remote attackers to… | |
| Modificada | Alta (7.5) | 1.9% | — | Python PyxmlRedhat Enterprise Virtualization HypervisorRedhat Enterprise Linux | 22/11/2019 | 16/6/2026 | PyXML: Hash table collisions CPU usage Denial of Service | |
| Modificada | Media (5.9) | 0.73% | — | Redhat Enterprise VirtualizationRedhat VdsclientRedhat Virtual Desktop Server Manager | 13/11/2019 | 17/6/2026 | vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack | |
| Modificada | Baja (3.1) | 0.35% | — | Redhat Enterprise Virtualization Manager | 9/11/2019 | 16/6/2026 | In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterprise Virtualization Manager. An attacker on the local network… | |
| Modificada | Media (5.5) | 0.42% | — | Redhat Virtual Desktop Server ManagerRedhat Enterprise VirtualizationRedhat Storage | 4/11/2019 | 16/6/2026 | Insecure temporary file vulnerability in RedHat vsdm 4.9.6. | |
| Modificada | Media (6.1) | 0.91% | — | Redhat CloudformsRedhat Manageiq Enterprise Virtualization Manager | 1/11/2019 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.5) | 2.7% | — | Redhat Gluster StorageDebian LinuxRedhat Enterprise Virtualization HostRedhat Enterprise Linux Server+1 | 31/10/2018 | 17/6/2026 | The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' translator via the code handling the 'GF_XATTR_CLRLK_CMD' xattr in the 'pl_getxattr' function. A remote authenticated attacker could exploit this on a mounted volume to cause a denial of service. | |
| Modificada | Media (6.3) | 0.28% | — | Redhat Enterprise Virtualization | 27/7/2018 | 17/6/2026 | When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with expired passwords, gaining access to those accounts. | |
| Modificada | Crítica (9.8) | 0.99% | — | OvirtRedhat Enterprise Virtualization Manager | 26/6/2018 | 17/6/2026 | ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext. Sharing the provisioning log might inadvertently leak database passwords. | |
| Modificada | Crítica (9.8) | 1.4% | — | Ovirt-ansible-rolesRedhat Enterprise Virtualization | 20/6/2018 | 17/6/2026 | ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to… | |
| Modificada | Alta (7.5) | 98% | — | Fedoraproject FedoraRedhat Enterprise VirtualizationRedhat Enterprise Virtualization HostRedhat Enterprise Linux+3 | 17/5/2018 | 17/6/2026 | DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary… | |
| Modificada | Alta (7.8) | 18% | — | Debian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+7 | 8/5/2018 | 17/6/2026 | A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferred by MOV SS or POP SS, as demonstrated by (for example)… | |
| Modificada | Alta (8.8) | 0.75% | — | Redhat Manageiq Enterprise Virtualization Manager | 1/5/2018 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors. | |
| Modificada | Alta (7.2) | 1.5% | — | OvirtRedhat Enterprise Virtualization | 26/4/2018 | 17/6/2026 | ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control. | |
| Modificada | Crítica (9.1) | 3.4% | — | Redhat Enterprise Virtualization Manager | 25/9/2017 | 17/6/2026 | redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role on any Entity to execute arbitrary commands on any host in the RHEV environment. | |
| Modificada | Media (5.9) | 1.9% | — | Redhat Enterprise Virtualization Manager | 24/8/2017 | 17/6/2026 | Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which might allow remote attackers to communicate with a system designated to be unreachable. | |
| Modificada | Media (5.5) | 0.36% | — | Redhat Enterprise Virtualization | 22/8/2017 | 17/6/2026 | oVirt Engine discloses the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD in /var/log/ovirt-engine/engine.log file in RHEV before 4.0. | |
| Modificada | Alta (7) | 0.50% | — | Redhat Enterprise Virtualization ServerRedhat OpenshiftRedhat Enterprise LinuxDebian Linux+2 | 19/6/2017 | 17/6/2026 | libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that libffi is used by a number of other libraries. It was previously stated that this affects libffi version 3.2.1 but this appears to be incorrect. libffi prior to version 3.1… | |
| Modificada | Media (6.8) | 0.52% | — | Redhat Enterprise Virtualization | 20/4/2017 | 17/6/2026 | ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin session timeout restriction via vectors related to UI selections, which trigger repeating queries. | |
| Modificada | Media (5.5) | 0.24% | — | Redhat Enterprise Virtualization | 14/12/2016 | 17/6/2026 | Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file. | |
| Modificada | Baja (3.3) | 0.35% | — | Redhat Enterprise Virtualization | 3/10/2016 | 17/6/2026 | The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files. | |
| Modificada | Baja (3.7) | 0.33% | — | Redhat Enterprise Virtualization | 8/9/2015 | 17/6/2026 | The Web Admin interface in Red Hat Enterprise Virtualization Manager (RHEV-M) allows local users to bypass the timeout function by selecting a VM in the VM grid view. | |
| Modificada | Alta (7.7) | 15% | — | QemuRedhat Enterprise VirtualizationRedhat OpenstackRedhat Enterprise Linux+1 | 13/5/2015 | 17/6/2026 | The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM. | |
| Modificada | Baja (2.1) | 0.38% | — | Redhat Enterprise Virtualization Manager | 1/5/2015 | 17/6/2026 | Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin during service startup, which allows local users to obtain sensitive information by reading files in the directory. | |
| Modificada | Media (6.8) | 1.6% | — | Redhat Enterprise Virtualization Manager | 1/5/2015 | 17/6/2026 | Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 ignores the permission to deny snapshot creation during live storage migration between domains, which allows remote authenticated users to cause a denial of service (prevent host start) by creating a long snapshot chain. |