Записи libvirt
9 опубликованных записей вендора libvirt.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-399 Resource Management Errors1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
28Наблюдать | CVE-2008-5086Эксплойта нет | Multiple methods in libvirt 0.3.2 through 0.5.1 do not check if a connection is read-only, which allows local users to bypass intended acceslibvirt · libvirt | Высокая7,2 | — | 0,4 % | 19 дек. 2008 г. |
24Наблюдать | CVE-2014-3633Эксплойта нет | The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the lilibvirt · libvirt · CWE-119 | Средняя5,8 | — | 2,8 % | 6 окт. 2014 г. |
22Наблюдать | CVE-2015-5160Эксплойта нет | libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to olibvirt · libvirt · CWE-200 | Средняя5,5 | — | 0,4 % | 20 авг. 2018 г. |
21Наблюдать | CVE-2014-3657Эксплойта нет | The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allibvirt · libvirt · CWE-399 | Средняя5,0 | — | 2,8 % | 6 окт. 2014 г. |
17Наблюдать | CVE-2009-0036Proof of concept | Buffer overflow in the proxyReadClientSocket function in proxy/libvirt_proxy.c in libvirt_proxy 0.5.1 might allow local users to gain privillibvirt · libvirt · CWE-119 | Средняя4,4 | — | 1,2 % | 11 февр. 2009 г. |
17Наблюдать | CVE-2010-2239Эксплойта нет | Red Hat libvirt, possibly 0.6.0 through 0.8.2, creates new images without setting the user-defined backing-store format, which allows guest libvirt · libvirt · CWE-264 | Средняя4,4 | — | 0,3 % | 19 авг. 2010 г. |
17Наблюдать | CVE-2010-2238Эксплойта нет | Red Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image backing stores without extracting the defined disk backing-store forlibvirt · libvirt · CWE-264 | Средняя4,4 | — | 0,3 % | 19 авг. 2010 г. |
17Наблюдать | CVE-2010-2237Эксплойта нет | Red Hat libvirt, possibly 0.6.1 through 0.8.2, looks up disk backing stores without referring to the user-defined main disk format, which milibvirt · libvirt · CWE-264 | Средняя4,4 | — | 0,3 % | 19 авг. 2010 г. |
8Наблюдать | CVE-2010-2242Эксплойта нет | Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users tolibvirt · libvirt · CWE-264 | Низкая2,1 | — | 0,4 % | 19 авг. 2010 г. |
- CVE-2008-508628Наблюдать
Multiple methods in libvirt 0.3.2 through 0.5.1 do not check if a connection is read-only, which allows local users to bypass intended acces
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %libvirt · libvirt19 дек. 2008 г.
- CVE-2014-363324Наблюдать
The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the li
СредняяCVSS 5,8Эксплойта нетEPSS 3 %libvirt · libvirt6 окт. 2014 г.
- CVE-2015-516022Наблюдать
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to o
СредняяCVSS 5,5Эксплойта нетEPSS 0 %libvirt · libvirt20 авг. 2018 г.
- CVE-2014-365721Наблюдать
The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which al
СредняяCVSS 5,0Эксплойта нетEPSS 3 %libvirt · libvirt6 окт. 2014 г.
- CVE-2009-003617Наблюдать
Buffer overflow in the proxyReadClientSocket function in proxy/libvirt_proxy.c in libvirt_proxy 0.5.1 might allow local users to gain privil
СредняяCVSS 4,4Proof of conceptEPSS 1 %libvirt · libvirt11 февр. 2009 г.
- CVE-2010-223917Наблюдать
Red Hat libvirt, possibly 0.6.0 through 0.8.2, creates new images without setting the user-defined backing-store format, which allows guest
СредняяCVSS 4,4Эксплойта нетEPSS 0 %libvirt · libvirt19 авг. 2010 г.
- CVE-2010-223817Наблюдать
Red Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image backing stores without extracting the defined disk backing-store for
СредняяCVSS 4,4Эксплойта нетEPSS 0 %libvirt · libvirt19 авг. 2010 г.
- CVE-2010-223717Наблюдать
Red Hat libvirt, possibly 0.6.1 through 0.8.2, looks up disk backing stores without referring to the user-defined main disk format, which mi
СредняяCVSS 4,4Эксплойта нетEPSS 0 %libvirt · libvirt19 авг. 2010 г.
- CVE-2010-22428Наблюдать
Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %libvirt · libvirt19 авг. 2010 г.