Show filters
22 Total Results
Displaying 11-20 of 22
Sort by:
Attacker Value
Unknown

CVE-2013-6458

Disclosure Date: January 24, 2014 (last updated October 05, 2023)
Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify that the disk is attached, which allows remote read-only attackers to cause a denial of service (libvirtd crash) via the virDomainDetachDeviceFlags command.
0
Attacker Value
Unknown

CVE-2013-6457

Disclosure Date: January 24, 2014 (last updated October 05, 2023)
The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt before 1.2.1 does not properly initialize the nodemap, which allows local users to cause a denial of service (invalid free operation and crash) or possibly execute arbitrary code via an inactive domain to the virsh numatune command.
0
Attacker Value
Unknown

CVE-2013-6436

Disclosure Date: January 07, 2014 (last updated October 05, 2023)
The lxcDomainGetMemoryParameters method in lxc/lxc_driver.c in libvirt 1.0.5 through 1.2.0 does not properly check the status of LXC guests when reading memory tunables, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) via a guest in the shutdown status, as demonstrated by the "virsh memtune" command.
0
Attacker Value
Unknown

CVE-2013-2230

Disclosure Date: September 30, 2013 (last updated October 05, 2023)
The qemu driver (qemu/qemu_driver.c) in libvirt before 1.1.1 allows remote authenticated users to cause a denial of service (daemon crash) via unspecified vectors involving "multiple events registration."
0
Attacker Value
Unknown

CVE-2013-2218

Disclosure Date: September 30, 2013 (last updated October 05, 2023)
Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.0.6 allows remote attackers to cause a denial of service (libvirtd crash) via a filtering flag that causes an interface to be skipped, as demonstrated by the "virsh iface-list --inactive" command.
0
Attacker Value
Unknown

CVE-2013-4153

Disclosure Date: September 30, 2013 (last updated October 05, 2023)
Double free vulnerability in the qemuAgentGetVCPUs function in qemu/qemu_agent.c in libvirt 1.0.6 through 1.1.0 allows remote attackers to cause a denial of service (daemon crash) via a cpu count request, as demonstrated by the "virsh vcpucount dom --guest" command.
0
Attacker Value
Unknown

CVE-2013-4154

Disclosure Date: September 30, 2013 (last updated October 05, 2023)
The qemuAgentCommand function in libvirt before 1.1.1, when a guest agent is not configured, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to "agent based cpu (un)plug," as demonstrated by the "virsh vcpucount foobar --guest" command.
0
Attacker Value
Unknown

CVE-2013-4297

Disclosure Date: September 30, 2013 (last updated October 05, 2023)
The virFileNBDDeviceAssociate function in util/virfile.c in libvirt 1.1.2 and earlier allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-5651

Disclosure Date: September 30, 2013 (last updated October 05, 2023)
The virBitmapParse function in util/virbitmap.c in libvirt before 1.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via a crafted bitmap, as demonstrated by a large nodeset value to numatune.
0
Attacker Value
Unknown

CVE-2011-2085

Disclosure Date: June 04, 2012 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Best Practical Solutions RT before 3.8.12 and 4.x before 4.0.6 allow remote attackers to hijack the authentication of arbitrary users.
0