CVE-2016-5008
- EPSS 2.82%
- Veröffentlicht 13.07.2016 15:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.
CVE-2014-3672
- EPSS 0.03%
- Veröffentlicht 25.05.2016 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The qemu implementation in libvirt before 1.3.0 and Xen allows local guest OS users to cause a denial of service (host disk consumption) by writing to stdout or stderr.
CVE-2015-5247
- EPSS 0.49%
- Veröffentlicht 14.04.2016 15:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS po...
CVE-2011-4600
- EPSS 0.31%
- Veröffentlicht 14.04.2016 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restriction...
CVE-2015-5313
- EPSS 0.06%
- Veröffentlicht 11.04.2016 21:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Directory traversal vulnerability in the virStorageBackendFileSystemVolCreate function in storage/storage_backend_fs.c in libvirt, when fine-grained Access Control Lists (ACL) are in effect, allows local users with storage_vol:create ACL but not doma...
CVE-2015-0236
- EPSS 0.65%
- Veröffentlicht 29.01.2015 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interf...
- EPSS 0.37%
- Veröffentlicht 06.01.2015 15:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The qemu implementation of virConnectGetAllDomainStats in libvirt before 1.2.11 does not properly handle locks when a domain is skipped due to ACL restrictions, which allows a remote authenticated users to cause a denial of service (deadlock or segme...
CVE-2014-8136
- EPSS 0.13%
- Veröffentlicht 19.12.2014 15:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.
CVE-2014-8135
- EPSS 0.16%
- Veröffentlicht 19.12.2014 15:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The storageVolUpload function in storage/storage_driver.c in libvirt before 1.2.11 does not check a certain return value, which allows local users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted offset value in ...
CVE-2013-4399
- EPSS 0.68%
- Veröffentlicht 12.12.2014 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cause a denial of service (use-after-free and crash) b...