libvirt kayıtları
libvirt üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-399 Resource Management Errors1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
28İzleyin | CVE-2008-5086İstismar yok | Multiple methods in libvirt 0.3.2 through 0.5.1 do not check if a connection is read-only, which allows local users to bypass intended acceslibvirt · libvirt | Yüksek7,2 | — | %0,4 | 19 Ara 2008 |
24İzleyin | CVE-2014-3633İstismar yok | The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the lilibvirt · libvirt · CWE-119 | Orta5,8 | — | %2,8 | 6 Eki 2014 |
22İzleyin | CVE-2015-5160İstismar yok | libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to olibvirt · libvirt · CWE-200 | Orta5,5 | — | %0,4 | 20 Ağu 2018 |
21İzleyin | CVE-2014-3657İstismar yok | The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allibvirt · libvirt · CWE-399 | Orta5,0 | — | %2,8 | 6 Eki 2014 |
17İzleyin | CVE-2009-0036Kavram kanıtı | Buffer overflow in the proxyReadClientSocket function in proxy/libvirt_proxy.c in libvirt_proxy 0.5.1 might allow local users to gain privillibvirt · libvirt · CWE-119 | Orta4,4 | — | %1,2 | 11 Şub 2009 |
17İzleyin | CVE-2010-2239İstismar yok | Red Hat libvirt, possibly 0.6.0 through 0.8.2, creates new images without setting the user-defined backing-store format, which allows guest libvirt · libvirt · CWE-264 | Orta4,4 | — | %0,3 | 19 Ağu 2010 |
17İzleyin | CVE-2010-2238İstismar yok | Red Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image backing stores without extracting the defined disk backing-store forlibvirt · libvirt · CWE-264 | Orta4,4 | — | %0,3 | 19 Ağu 2010 |
17İzleyin | CVE-2010-2237İstismar yok | Red Hat libvirt, possibly 0.6.1 through 0.8.2, looks up disk backing stores without referring to the user-defined main disk format, which milibvirt · libvirt · CWE-264 | Orta4,4 | — | %0,3 | 19 Ağu 2010 |
8İzleyin | CVE-2010-2242İstismar yok | Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users tolibvirt · libvirt · CWE-264 | Düşük2,1 | — | %0,4 | 19 Ağu 2010 |
- CVE-2008-508628İzleyin
Multiple methods in libvirt 0.3.2 through 0.5.1 do not check if a connection is read-only, which allows local users to bypass intended acces
YüksekCVSS 7,2İstismar yokEPSS %0libvirt · libvirt19 Ara 2008
- CVE-2014-363324İzleyin
The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the li
OrtaCVSS 5,8İstismar yokEPSS %3libvirt · libvirt6 Eki 2014
- CVE-2015-516022İzleyin
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to o
OrtaCVSS 5,5İstismar yokEPSS %0libvirt · libvirt20 Ağu 2018
- CVE-2014-365721İzleyin
The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which al
OrtaCVSS 5,0İstismar yokEPSS %3libvirt · libvirt6 Eki 2014
- CVE-2009-003617İzleyin
Buffer overflow in the proxyReadClientSocket function in proxy/libvirt_proxy.c in libvirt_proxy 0.5.1 might allow local users to gain privil
OrtaCVSS 4,4Kavram kanıtıEPSS %1libvirt · libvirt11 Şub 2009
- CVE-2010-223917İzleyin
Red Hat libvirt, possibly 0.6.0 through 0.8.2, creates new images without setting the user-defined backing-store format, which allows guest
OrtaCVSS 4,4İstismar yokEPSS %0libvirt · libvirt19 Ağu 2010
- CVE-2010-223817İzleyin
Red Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image backing stores without extracting the defined disk backing-store for
OrtaCVSS 4,4İstismar yokEPSS %0libvirt · libvirt19 Ağu 2010
- CVE-2010-223717İzleyin
Red Hat libvirt, possibly 0.6.1 through 0.8.2, looks up disk backing stores without referring to the user-defined main disk format, which mi
OrtaCVSS 4,4İstismar yokEPSS %0libvirt · libvirt19 Ağu 2010
- CVE-2010-22428İzleyin
Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to
DüşükCVSS 2,1İstismar yokEPSS %0libvirt · libvirt19 Ağu 2010