CVE-2013-4400
- EPSS 0.05%
- Veröffentlicht 09.12.2013 16:36:46
- Zuletzt bearbeitet 11.04.2025 00:51:21
virt-login-shell in libvirt 1.1.2 through 1.1.3 allows local users to overwrite arbitrary files and possibly gain privileges via unspecified environment variables or command-line arguments.
CVE-2013-4401
- EPSS 1.46%
- Veröffentlicht 02.11.2013 18:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3 checks for the connect:read permission instead of the connect:write permission, which allows attackers to gain domain:write privileges and execute Qemu binaries via crafted X...
CVE-2013-4311
- EPSS 0.02%
- Veröffentlicht 03.10.2013 21:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2)...
- EPSS 0.58%
- Veröffentlicht 30.09.2013 21:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
The virFileNBDDeviceAssociate function in util/virfile.c in libvirt 1.1.2 and earlier allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via unspecified vectors.
- EPSS 0.58%
- Veröffentlicht 30.09.2013 21:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
The qemu driver (qemu/qemu_driver.c) in libvirt before 1.1.1 allows remote authenticated users to cause a denial of service (daemon crash) via unspecified vectors involving "multiple events registration."
- EPSS 0.64%
- Veröffentlicht 30.09.2013 21:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
Double free vulnerability in the qemuAgentGetVCPUs function in qemu/qemu_agent.c in libvirt 1.0.6 through 1.1.0 allows remote attackers to cause a denial of service (daemon crash) via a cpu count request, as demonstrated by the "virsh vcpucount dom -...
CVE-2013-4154
- EPSS 0.73%
- Veröffentlicht 30.09.2013 21:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
The qemuAgentCommand function in libvirt before 1.1.1, when a guest agent is not configured, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to "agent based cpu (un)plug," as demonstrated ...
- EPSS 0.58%
- Veröffentlicht 30.09.2013 21:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
The xenDaemonListDefinedDomains function in xen/xend_internal.c in libvirt 1.1.1 allows remote authenticated users to cause a denial of service (memory corruption and crash) via vectors involving the virConnectListDefinedDomains API function.
CVE-2013-4291
- EPSS 0.05%
- Veröffentlicht 30.09.2013 21:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:gid label, does not properly set group memberships, which allows local users to gain privileges.
CVE-2013-4292
- EPSS 0.07%
- Veröffentlicht 30.09.2013 21:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
libvirt 1.1.0 and 1.1.1 allows local users to cause a denial of service (memory consumption) via a large number of domain migrate parameters in certain RPC calls in (1) daemon/remote.c and (2) remote/remote_driver.c.