libvirt records
9 published records for vendor libvirt.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-399 Resource Management Errors1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
28Monitor | CVE-2008-5086No exploit | Multiple methods in libvirt 0.3.2 through 0.5.1 do not check if a connection is read-only, which allows local users to bypass intended acceslibvirt · libvirt | High7.2 | — | 0.4% | Dec 19, 2008 |
24Monitor | CVE-2014-3633No exploit | The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the lilibvirt · libvirt · CWE-119 | Medium5.8 | — | 2.8% | Oct 6, 2014 |
22Monitor | CVE-2015-5160No exploit | libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to olibvirt · libvirt · CWE-200 | Medium5.5 | — | 0.4% | Aug 20, 2018 |
21Monitor | CVE-2014-3657No exploit | The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allibvirt · libvirt · CWE-399 | Medium5.0 | — | 2.8% | Oct 6, 2014 |
17Monitor | CVE-2009-0036Proof of concept | Buffer overflow in the proxyReadClientSocket function in proxy/libvirt_proxy.c in libvirt_proxy 0.5.1 might allow local users to gain privillibvirt · libvirt · CWE-119 | Medium4.4 | — | 1.2% | Feb 11, 2009 |
17Monitor | CVE-2010-2239No exploit | Red Hat libvirt, possibly 0.6.0 through 0.8.2, creates new images without setting the user-defined backing-store format, which allows guest libvirt · libvirt · CWE-264 | Medium4.4 | — | 0.3% | Aug 19, 2010 |
17Monitor | CVE-2010-2238No exploit | Red Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image backing stores without extracting the defined disk backing-store forlibvirt · libvirt · CWE-264 | Medium4.4 | — | 0.3% | Aug 19, 2010 |
17Monitor | CVE-2010-2237No exploit | Red Hat libvirt, possibly 0.6.1 through 0.8.2, looks up disk backing stores without referring to the user-defined main disk format, which milibvirt · libvirt · CWE-264 | Medium4.4 | — | 0.3% | Aug 19, 2010 |
8Monitor | CVE-2010-2242No exploit | Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users tolibvirt · libvirt · CWE-264 | Low2.1 | — | 0.4% | Aug 19, 2010 |
- CVE-2008-508628Monitor
Multiple methods in libvirt 0.3.2 through 0.5.1 do not check if a connection is read-only, which allows local users to bypass intended acces
HighCVSS 7.2No exploitEPSS 0%libvirt · libvirtDec 19, 2008
- CVE-2014-363324Monitor
The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the li
MediumCVSS 5.8No exploitEPSS 3%libvirt · libvirtOct 6, 2014
- CVE-2015-516022Monitor
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to o
MediumCVSS 5.5No exploitEPSS 0%libvirt · libvirtAug 20, 2018
- CVE-2014-365721Monitor
The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which al
MediumCVSS 5.0No exploitEPSS 3%libvirt · libvirtOct 6, 2014
- CVE-2009-003617Monitor
Buffer overflow in the proxyReadClientSocket function in proxy/libvirt_proxy.c in libvirt_proxy 0.5.1 might allow local users to gain privil
MediumCVSS 4.4Proof of conceptEPSS 1%libvirt · libvirtFeb 11, 2009
- CVE-2010-223917Monitor
Red Hat libvirt, possibly 0.6.0 through 0.8.2, creates new images without setting the user-defined backing-store format, which allows guest
MediumCVSS 4.4No exploitEPSS 0%libvirt · libvirtAug 19, 2010
- CVE-2010-223817Monitor
Red Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image backing stores without extracting the defined disk backing-store for
MediumCVSS 4.4No exploitEPSS 0%libvirt · libvirtAug 19, 2010
- CVE-2010-223717Monitor
Red Hat libvirt, possibly 0.6.1 through 0.8.2, looks up disk backing stores without referring to the user-defined main disk format, which mi
MediumCVSS 4.4No exploitEPSS 0%libvirt · libvirtAug 19, 2010
- CVE-2010-22428Monitor
Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to
LowCVSS 2.1No exploitEPSS 0%libvirt · libvirtAug 19, 2010