Redhat
Redhat Enterprise Virtualization: vulnerabilidades y CVE
Redhat Enterprise Virtualization tiene 36 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE36
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2015-5201 | Alta (7.5) | 1.5% | — | 25 feb 2020 | VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is… |
| CVE-2014-8167 | Media (5.9) | 0.73% | — | 13 nov 2019 | vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack |
| CVE-2013-4280 | Media (5.5) | 0.42% | — | 4 nov 2019 | Insecure temporary file vulnerability in RedHat vsdm 4.9.6. |
| CVE-2017-2614 | Media (6.3) | 0.28% | — | 27 jul 2018 | When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change… |
| CVE-2018-1117 | Crítica (9.8) | 1.4% | — | 20 jun 2018 | ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the… |
| CVE-2018-1111 | Alta (7.5) | 98% | — | 17 may 2018 | DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an… |
| CVE-2018-1074 | Alta (7.2) | 1.5% | — | 26 abr 2018 | ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator… |
| CVE-2016-6310 | Media (5.5) | 0.36% | — | 22 ago 2017 | oVirt Engine discloses the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD in /var/log/ovirt-engine/engine.log file in RHEV before 4.0. |
| CVE-2016-6338 | Media (6.8) | 0.52% | — | 20 abr 2017 | ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin session timeout restriction via vectors… |
| CVE-2016-4443 | Media (5.5) | 0.24% | — | 14 dic 2016 | Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file. |
| CVE-2016-5432 | Baja (3.3) | 0.35% | — | 3 oct 2016 | The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files. |
| CVE-2015-1841 | Baja (3.7) | 0.33% | — | 8 sept 2015 | The Web Admin interface in Red Hat Enterprise Virtualization Manager (RHEV-M) allows local users to bypass the timeout function by selecting a VM in the VM grid view. |
| CVE-2015-3456 | Alta (7.7) | 15% | — | 13 may 2015 | The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the… |
| CVE-2014-3561 | Baja (2.1) | 0.38% | — | 5 dic 2014 | The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by… |
| CVE-2014-3559 | Baja (3.5) | 1.4% | — | 6 ago 2014 | The oVirt storage backend in Red Hat Enterprise Virtualization 3.4 does not wipe memory snapshots when deleting a VM, even when wipe-after-delete (WAD) is configured for the VM's disk, which allows remote authenticated… |
| CVE-2014-5177 | Baja (1.2) | 0.53% | — | 3 ago 2014 | libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction… |
| CVE-2014-0179 | Baja (1.9) | 0.56% | — | 3 ago 2014 | libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity… |
| CVE-2014-3485 | Media (4) | 1.5% | — | 11 jul 2014 | The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors,… |
| CVE-2012-3406 | Media (6.8) | 3.2% | — | 10 feb 2014 | The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SPECS array, which… |
| CVE-2012-3405 | Media (5) | 2.1% | — | 10 feb 2014 | The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the… |
| CVE-2012-3404 | Media (5) | 2.2% | — | 10 feb 2014 | The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the… |
| CVE-2013-2152 | Alta (7.2) | 0.41% | — | 21 ene 2014 | Unquoted Windows search path vulnerability in the SPICE service, as used in Red Hat Enterprise Virtualization (RHEV) 3.2, allows local users to gain privileges via a crafted application in an unspecified folder. |
| CVE-2013-2151 | Alta (7.2) | 0.41% | — | 21 ene 2014 | Unquoted Windows search path vulnerability in Red Hat Enterprise Virtualization (RHEV) 3 and 3.2 allows local users to gain privileges via a crafted application in an unspecified folder. |
| CVE-2013-4282 | Media (5) | 2.7% | — | 2 nov 2013 | Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket. |
| CVE-2013-4181 | Media (4.3) | 1.4% | — | 16 sept 2013 | Cross-site scripting (XSS) vulnerability in the addAlert function in the RedirectServlet servlet in oVirt Engine and Red Hat Enterprise Virtualization Manager (RHEV-M), as used in Red Hat Enterprise Virtualization 3 and… |
| CVE-2013-2176 | Alta (7.2) | 0.46% | — | 28 ago 2013 | Unquoted Windows search path vulnerability in the Red Hat Enterprise Virtualization Application Provisioning Tool (RHEV-APT) in the rhev-guest-tools-iso package 3.2 allows local users to gain privileges via a Trojan… |
| CVE-2013-4236 | Baja (2.7) | 0.56% | — | 19 ago 2013 | VDSM in Red Hat Enterprise Virtualization 3 and 3.2 allows privileged guest users to cause the host to become "unavailable to the managment server" via invalid XML characters in a guest agent response. NOTE: this issue… |
| CVE-2013-0167 | Baja (2.7) | 0.56% | — | 19 ago 2013 | VDSM in Red Hat Enterprise Virtualization 3 and 3.2 allows privileged guest users to cause the host to become "unavailable to the managment server" via guestInfo dictionaries with "unexpected fields." |
| CVE-2013-1591 | Crítica (9.8) | 3.6% | — | 31 ene 2013 | Stack-based buffer overflow in libpixman, as used in Pale Moon before 15.4 and possibly other products, has unspecified impact and context-dependent attack vectors. NOTE: this issue might be resultant from an integer… |
| CVE-2010-2811 | Media (5.7) | 1.00% | — | 24 ago 2010 | Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization (RHEV) 2.2 does not properly accept TCP connections for SSL sessions, which allows remote attackers to cause a denial of service (daemon outage)… |
Otros productos de Redhat
Enterprise Linux · 1937Enterprise Linux Desktop · 1928Enterprise Linux Server · 1891Enterprise Linux Workstation · 1845Enterprise Linux Server AUS · 1059Enterprise Linux EUS · 787Enterprise Linux Server TUS · 768Enterprise Linux Server EUS · 622Openshift Container Platform · 328Jboss Enterprise Application Platform · 244Satellite · 238Linux · 230