Skip to main content

Vendor/product archive

redhat / enterprise_virtualization CVEs

Beta · best-effort

37 CVEs tagged to redhat / enterprise_virtualization2 Critical, 8 High, 19 Medium, 8 Low, 0 Unrated.

CVE-2017-2614

Published Jul 27, 2018

When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1111

Published May 17, 2018

DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4

CVE-2016-6338

Published Apr 20, 2017

ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin ses…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4443

Published Dec 14, 2016

Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log fi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1841

Published Sep 8, 2015

The Web Admin interface in Red Hat Enterprise Virtualization Manager (RHEV-M) allows local users to bypass the timeout function by selecting a VM in the VM grid view.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3561

Published Dec 5, 2014

The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3559

Published Aug 6, 2014

The oVirt storage backend in Red Hat Enterprise Virtualization 3.4 does not wipe memory snapshots when deleting a VM, even when wipe-after-delete (WAD) is configured for the VM's…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3485

Published Jul 11, 2014

The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspe…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2152

Published Jan 21, 2014

Unquoted Windows search path vulnerability in the SPICE service, as used in Red Hat Enterprise Virtualization (RHEV) 3.2, allows local users to gain privileges via a crafted appli…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2013-2151

Published Jan 21, 2014

Unquoted Windows search path vulnerability in Red Hat Enterprise Virtualization (RHEV) 3 and 3.2 allows local users to gain privileges via a crafted application in an unspecified…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 37 CVEsPage 1 of 2