Redhat

Libvirt

73 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.29%
  • Veröffentlicht 30.09.2013 21:55:09
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The remoteDispatchDomainMemoryStats function in daemon/remote.c in libvirt 0.9.1 through 0.10.1.x, 0.10.2.x before 0.10.2.8, 1.0.x before 1.0.5.6, and 1.1.x before 1.1.2 allows remote authenticated users to cause a denial of service (uninitialized po...

Exploit
  • EPSS 0.64%
  • Veröffentlicht 30.09.2013 21:55:09
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The virBitmapParse function in util/virbitmap.c in libvirt before 1.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via a crafted bitmap, as demonstrated by a large nodeset value to numatune.

Exploit
  • EPSS 10.81%
  • Veröffentlicht 30.09.2013 21:55:08
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.0.6 allows remote attackers to cause a denial of service (libvirtd crash) via a filtering flag that causes an interface to be skip...

  • EPSS 3.78%
  • Veröffentlicht 29.05.2013 00:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The remoteDispatchStoragePoolListAllVolumes function in the storage pool manager in libvirt 1.0.5 allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of requests "to list all volumes for the particula...

  • EPSS 0.06%
  • Veröffentlicht 20.03.2013 15:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

libvirt 1.0.2 and earlier sets the group owner to kvm for device files, which allows local users to write to these files via unspecified vectors.

  • EPSS 20.22%
  • Veröffentlicht 08.02.2013 20:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers to cause a denial of service (c...

  • EPSS 2.83%
  • Veröffentlicht 19.11.2012 12:10:52
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The virNetServerProgramDispatchCall function in libvirt before 0.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and segmentation fault) via an RPC call with (1) an event as the RPC number or (2) an RPC number whos...

  • EPSS 1.32%
  • Veröffentlicht 07.08.2012 21:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams...

  • EPSS 0.06%
  • Veröffentlicht 17.06.2012 03:41:42
  • Zuletzt bearbeitet 11.04.2025 00:51:21

libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associated with a guest and might allow local users to acces...

  • EPSS 2.83%
  • Veröffentlicht 10.08.2011 20:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Integer overflow in libvirt before 0.9.3 allows remote authenticated users to cause a denial of service (libvirtd crash) and possibly execute arbitrary code via a crafted VirDomainGetVcpus RPC call that triggers memory corruption.