Skip to main content

Vendor/product archive

redhat / virtualization CVEs

Beta · best-effort

126 CVEs tagged to redhat / virtualization17 Critical, 57 High, 49 Medium, 3 Low, 0 Unrated.

CVE-2024-7259

Published Sep 26, 2024

A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may be able to use browser developer tools to view Provider pas…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2805

Published Oct 19, 2022

A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style. This flaw allows an attacker with sufficient privileges…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0148

Published Sep 29, 2022

Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for bloc…

CVSS 5.5 · Medium

CVE-2014-0147

Published Sep 29, 2022

Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possible crash caused by signed data types or…

CVSS 6.2 · Medium

CVE-2014-0144

Published Sep 29, 2022

QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/buffer overflows or crash caused…

CVSS 8.6 · High

CVE-2022-27666

Published Mar 23, 2022

A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to ov…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2021-3620

Published Mar 3, 2022

A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error mes…

CVSS 5.5 · Medium

CVE-2021-3560

Published Feb 16, 2022

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be u…

CVSS 7.8 · High
evidence mentions
8
Buzz score
65.5
KEV listedPublic PoC observed

CVE-2021-3621

Published Dec 23, 2021

A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick…

CVSS 8.8 · High
Showing 1-25 of 126 CVEsPage 1 of 6