Redhat

Virtualization

124 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Published 23.12.2021 21:15:08
  • Last modified 21.11.2024 06:22:00

A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as...

  • EPSS 0.12%
  • Published 31.08.2021 17:15:08
  • Last modified 21.11.2024 06:22:02

A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during the lifetime of the session. One of them is called secret_hash and the other session_id. Initially, both of them are the same, but a...

  • EPSS 0.04%
  • Published 06.05.2021 13:15:12
  • Last modified 21.11.2024 06:21:41

A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat f...

Exploit
  • EPSS 0.4%
  • Published 18.03.2021 19:15:12
  • Last modified 21.11.2024 04:27:29

A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by simply opening a connection to th...

  • EPSS 0.42%
  • Published 18.03.2021 17:15:13
  • Last modified 21.11.2024 05:21:53

A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerabilit...

  • EPSS 0.41%
  • Published 12.01.2021 15:15:13
  • Last modified 21.11.2024 05:18:22

A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to con...

  • EPSS 0.32%
  • Published 21.12.2020 17:15:12
  • Last modified 21.11.2024 05:27:25

A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email and public SSH key.

  • EPSS 0.31%
  • Published 19.03.2020 14:15:11
  • Last modified 21.11.2024 04:34:36

A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were included in the HTML response without escaping. This flaw would allow an attacker to craft malicious HTML p...

  • EPSS 0.38%
  • Published 11.02.2020 16:15:12
  • Last modified 21.11.2024 01:55:46

The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm image, related to virtio-block or virtio-serial read.

Exploit
  • EPSS 0.07%
  • Published 02.01.2020 15:15:11
  • Last modified 21.11.2024 04:27:30

A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper ve...