Redhat

Enterprise Virtualization

35 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 08.09.2015 15:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Web Admin interface in Red Hat Enterprise Virtualization Manager (RHEV-M) allows local users to bypass the timeout function by selecting a VM in the VM grid view.

  • EPSS 33.91%
  • Veröffentlicht 13.05.2015 18:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_...

  • EPSS 0.06%
  • Veröffentlicht 05.12.2014 16:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes.

  • EPSS 0.27%
  • Veröffentlicht 06.08.2014 19:55:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The oVirt storage backend in Red Hat Enterprise Virtualization 3.4 does not wipe memory snapshots when deleting a VM, even when wipe-after-delete (WAD) is configured for the VM's disk, which allows remote authenticated users with certain credentials ...

  • EPSS 0.11%
  • Veröffentlicht 03.08.2014 18:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the ...

  • EPSS 0.11%
  • Veröffentlicht 03.08.2014 18:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virConnectCompa...

  • EPSS 0.27%
  • Veröffentlicht 11.07.2014 14:55:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, related to an XML External Entity (X...

  • EPSS 0.87%
  • Veröffentlicht 10.02.2014 18:15:10
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SPECS array, which allows context-dependent attackers...

  • EPSS 0.67%
  • Veröffentlicht 10.02.2014 18:15:10
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection ...

Exploit
  • EPSS 0.6%
  • Veröffentlicht 10.02.2014 18:15:10
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection ...