Skip to main content

Vendor/product archive

redhat / enterprise_virtualization_manager CVEs

Beta · best-effort

19 CVEs tagged to redhat / enterprise_virtualization_manager1 Critical, 1 High, 10 Medium, 7 Low, 0 Unrated.

CVE-2009-3552

Published Nov 9, 2019

In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-8897

Published May 8, 2018

A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-sy…

CVSS 7.8 · High
evidence mentions
3
Buzz score
20.4

CVE-2015-7544

Published Sep 25, 2017

redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role on any Entity to ex…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-5293

Published Aug 24, 2017

Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which might allow remote attackers to…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0257

Published May 1, 2015

Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin during service startup,…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-0237

Published May 1, 2015

Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 ignores the permission to deny snapshot creation during live storage migration between domains, which allows remote a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3573

Published Oct 18, 2014

The oVirt Engine backend module, as used in Red Hat Enterprise Virtualization Manager before 3.4.2, uses an "insecure DocumentBuilderFactory," which allows remote attackers to rea…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6434

Published Jan 24, 2014

The remote-viewer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.3, when using a native SPICE client invocation method, initially makes insecure connections to the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2144

Published Jul 3, 2013

Red Hat Enterprise Virtualization Manager (RHEVM) before 3.2 does not properly check permissions for the target storage domain, which allows attackers to cause a denial of service…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0168

Published Mar 12, 2013

The MoveDisk command in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier does not properly check permissions on storage domains, which allows remote authenticate…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6115

Published Mar 12, 2013

The domain management tool (rhevm-manage-domains) in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier, when the validate action is enabled, logs the administrati…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-5516

Published Jan 4, 2013

Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when moving disks between storage domains, does not properly wipe-after-delete, which prevents disks from being secu…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-2696

Published Jan 4, 2013

The backend in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1 does not properly check privileges, which allows remote authenticated users to query arbitrary informa…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-0861

Published Jan 4, 2013

The vds_installer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, uses the -k curl parameter when downloading deployUtil.py and vds_bootstrap…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0860

Published Jan 4, 2013

Multiple untrusted search path vulnerabilities in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, allow local users to gain privileges via a Tro…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4316

Published Jan 4, 2013

Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, in certain unspecified conditions, does not lock the desktop screen between SPICE sessions, which allows local users…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-2224

Published Jun 24, 2010

The snapshot merging functionality in Red Hat Enterprise Virtualization Manager (aka RHEV-M) before 2.2 does not properly pass the postzero parameter during operations on deleted…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1