Show filters
85 Total Results
Displaying 31-40 of 85
Sort by:
Attacker Value
Unknown

CVE-2018-1064

Disclosure Date: March 28, 2018 (last updated November 08, 2023)
libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.
0
Attacker Value
Unknown

CVE-2018-6764

Disclosure Date: February 23, 2018 (last updated November 26, 2024)
util/virlog.c in libvirt does not properly determine the hostname on LXC container startup, which allows local guest OS users to bypass an intended container protection mechanism and execute arbitrary commands via a crafted NSS module.
0
Attacker Value
Unknown

CVE-2018-5748

Disclosure Date: January 25, 2018 (last updated November 26, 2024)
qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply.
0
Attacker Value
Unknown

CVE-2017-1000256

Disclosure Date: October 31, 2017 (last updated November 08, 2023)
libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default.
Attacker Value
Unknown

CVE-2016-5008

Disclosure Date: July 13, 2016 (last updated November 25, 2024)
libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.
0
Attacker Value
Unknown

CVE-2014-3672

Disclosure Date: May 25, 2016 (last updated November 25, 2024)
The qemu implementation in libvirt before 1.3.0 and Xen allows local guest OS users to cause a denial of service (host disk consumption) by writing to stdout or stderr.
0
Attacker Value
Unknown

CVE-2011-4600

Disclosure Date: April 14, 2016 (last updated November 25, 2024)
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.
0
Attacker Value
Unknown

CVE-2015-5247

Disclosure Date: April 14, 2016 (last updated November 25, 2024)
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS pool.
0
Attacker Value
Unknown

CVE-2015-5313

Disclosure Date: April 11, 2016 (last updated November 25, 2024)
Directory traversal vulnerability in the virStorageBackendFileSystemVolCreate function in storage/storage_backend_fs.c in libvirt, when fine-grained Access Control Lists (ACL) are in effect, allows local users with storage_vol:create ACL but not domain:write permission to write to arbitrary files via a .. (dot dot) in a volume name.
0
Attacker Value
Unknown

CVE-2015-0236

Disclosure Date: January 29, 2015 (last updated October 05, 2023)
libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.
0