Vulnerabilities (CVE)

Vendor filter

Redhat Subscribe

Product filter

Enterprise Virtualization Subscribe

Filter

33 total CVE
CVE Vendors Products Updated CVSS
CVE-2018-1117 1 Redhat 1 Enterprise Virtualization 2019-10-09 5.0
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an...
CVE-2018-1074 2 Ovirt, Redhat 2 Ovirt, Enterprise Virtualization 2019-10-09 4.0
ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain...
CVE-2017-2614 1 Redhat 1 Enterprise Virtualization 2019-10-09 2.1
When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with...
CVE-2018-1111 2 Redhat, Fedoraproject 7 Enterprise Virtualization, Enterprise Virtualization Host, Fedora and 4 more 2019-10-03 7.9
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local...
CVE-2013-1591 2 Redhat, Palemoon 3 Enterprise Virtualization, Enterprise Linux, Pale Moon 2019-05-22 10.0
Stack-based buffer overflow in libpixman, as used in Pale Moon before 15.4 and possibly other products, has unspecified impact and context-dependent attack vectors. NOTE: this issue might be resultant from an integer overflow in the...
CVE-2012-3405 3 Redhat, Gnu, Canonical 4 Enterprise Virtualization, Ubuntu Linux, Glibc and 1 more 2019-04-22 5.0
The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string...
CVE-2012-3404 3 Redhat, Canonical, Gnu 4 Enterprise Virtualization, Ubuntu Linux, Glibc and 1 more 2019-04-22 5.0
The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string...
CVE-2014-0179 3 Novell, Redhat, Opensuse 5 Libvirt, Enterprise Virtualization, Enterprise Linux and 2 more 2019-04-22 1.9
libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1)...
CVE-2013-4282 2 Spice Project, Redhat 3 Enterprise Virtualization, Enterprise Linux, Spice 2019-04-22 5.0
Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.
CVE-2014-5177 3 Novell, Redhat, Opensuse 5 Libvirt, Enterprise Virtualization, Enterprise Linux and 2 more 2019-04-22 1.2
libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to...
CVE-2012-3406 3 Canonical, Gnu, Redhat 4 Enterprise Virtualization, Ubuntu Linux, Glibc and 1 more 2019-04-22 6.8
The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SPECS array, which allows context-dependent...
CVE-2015-3456 3 Qemu, Xen, Redhat 5 Enterprise Virtualization, Openstack, Enterprise Linux and 2 more 2019-04-22 7.7
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2)...
CVE-2016-6338 1 Redhat 1 Enterprise Virtualization 2017-12-13 4.6
ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin session timeout restriction via vectors related to UI selections,...
CVE-2016-6310 1 Redhat 1 Enterprise Virtualization 2017-08-30 2.1
oVirt Engine discloses the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD in /var/log/ovirt-engine/engine.log file in RHEV before 4.0.
CVE-2014-3561 1 Redhat 1 Enterprise Virtualization 2017-08-29 2.1
The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes.
CVE-2014-3559 1 Redhat 1 Enterprise Virtualization 2017-08-29 3.5
The oVirt storage backend in Red Hat Enterprise Virtualization 3.4 does not wipe memory snapshots when deleting a VM, even when wipe-after-delete (WAD) is configured for the VM's disk, which allows remote authenticated users with certain...
CVE-2013-2152 1 Redhat 1 Enterprise Virtualization 2017-08-29 7.2
Unquoted Windows search path vulnerability in the SPICE service, as used in Red Hat Enterprise Virtualization (RHEV) 3.2, allows local users to gain privileges via a crafted application in an unspecified folder.
CVE-2013-2151 1 Redhat 1 Enterprise Virtualization 2017-08-29 7.2
Unquoted Windows search path vulnerability in Red Hat Enterprise Virtualization (RHEV) 3 and 3.2 allows local users to gain privileges via a crafted application in an unspecified folder.
CVE-2008-3522 2 Jasper Project, Redhat 2 Enterprise Virtualization, Jasper 2017-08-08 10.0
Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via vectors related to the mif_hdr_put function and use of vsprintf.
CVE-2016-4443 1 Redhat 1 Enterprise Virtualization 2016-12-16 2.1
Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file.