Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown

CVE-2013-4399

Disclosure Date: December 12, 2014 (last updated October 05, 2023)
The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cause a denial of service (use-after-free and crash) by registering an event handler and then closing the connection.
0
Attacker Value
Unknown

CVE-2014-0179

Disclosure Date: August 03, 2014 (last updated November 08, 2023)
libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virConnectCompareCPU or (2) virConnectBaselineCPU API method, related to an XML External Entity (XXE) issue. NOTE: this issue was SPLIT per ADT3 due to different affected versions of some vectors. CVE-2014-5177 is used for other API methods.
0
Attacker Value
Unknown

CVE-2014-1447

Disclosure Date: January 24, 2014 (last updated October 05, 2023)
Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent.
0
Attacker Value
Unknown

CVE-2013-6458

Disclosure Date: January 24, 2014 (last updated October 05, 2023)
Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify that the disk is attached, which allows remote read-only attackers to cause a denial of service (libvirtd crash) via the virDomainDetachDeviceFlags command.
0
Attacker Value
Unknown

CVE-2013-6457

Disclosure Date: January 24, 2014 (last updated October 05, 2023)
The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt before 1.2.1 does not properly initialize the nodemap, which allows local users to cause a denial of service (invalid free operation and crash) or possibly execute arbitrary code via an inactive domain to the virsh numatune command.
0
Attacker Value
Unknown

CVE-2013-2230

Disclosure Date: September 30, 2013 (last updated October 05, 2023)
The qemu driver (qemu/qemu_driver.c) in libvirt before 1.1.1 allows remote authenticated users to cause a denial of service (daemon crash) via unspecified vectors involving "multiple events registration."
0
Attacker Value
Unknown

CVE-2013-4297

Disclosure Date: September 30, 2013 (last updated October 05, 2023)
The virFileNBDDeviceAssociate function in util/virfile.c in libvirt 1.1.2 and earlier allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-5651

Disclosure Date: September 30, 2013 (last updated October 05, 2023)
The virBitmapParse function in util/virbitmap.c in libvirt before 1.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via a crafted bitmap, as demonstrated by a large nodeset value to numatune.
0
Attacker Value
Unknown

CVE-2013-1766

Disclosure Date: March 20, 2013 (last updated October 05, 2023)
libvirt 1.0.2 and earlier sets the group owner to kvm for device files, which allows local users to write to these files via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-4423

Disclosure Date: November 19, 2012 (last updated October 05, 2023)
The virNetServerProgramDispatchCall function in libvirt before 0.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and segmentation fault) via an RPC call with (1) an event as the RPC number or (2) an RPC number whose value is in a "gap" in the RPC dispatch table.
0