Show filters
85 Total Results
Displaying 71-80 of 85
Sort by:
Attacker Value
Unknown
CVE-2013-1766
Disclosure Date: March 20, 2013 (last updated October 05, 2023)
libvirt 1.0.2 and earlier sets the group owner to kvm for device files, which allows local users to write to these files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-0170
Disclosure Date: February 08, 2013 (last updated October 05, 2023)
Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering certain errors during an RPC connection, which causes a message to be freed without being removed from the message queue.
0
Attacker Value
Unknown
CVE-2012-4423
Disclosure Date: November 19, 2012 (last updated October 05, 2023)
The virNetServerProgramDispatchCall function in libvirt before 0.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and segmentation fault) via an RPC call with (1) an event as the RPC number or (2) an RPC number whose value is in a "gap" in the RPC dispatch table.
0
Attacker Value
Unknown
CVE-2012-3445
Disclosure Date: August 07, 2012 (last updated October 04, 2023)
The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers an out-of-bounds read or a free of an invalid pointer.
0
Attacker Value
Unknown
CVE-2012-2693
Disclosure Date: June 17, 2012 (last updated October 04, 2023)
libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associated with a guest and might allow local users to access unintended USB devices.
0
Attacker Value
Unknown
CVE-2011-2178
Disclosure Date: August 10, 2011 (last updated November 08, 2023)
The virSecurityManagerGetPrivateData function in security/security_manager.c in libvirt 0.8.8 through 0.9.1 uses the wrong argument for a sizeof call, which causes incorrect processing of "security manager private data" that "reopens disk probing" and might allow guest OS users to read arbitrary files on the host OS. NOTE: this vulnerability exists because of a CVE-2010-2238 regression.
0
Attacker Value
Unknown
CVE-2011-2511
Disclosure Date: August 10, 2011 (last updated October 04, 2023)
Integer overflow in libvirt before 0.9.3 allows remote authenticated users to cause a denial of service (libvirtd crash) and possibly execute arbitrary code via a crafted VirDomainGetVcpus RPC call that triggers memory corruption.
0
Attacker Value
Unknown
CVE-2011-1486
Disclosure Date: May 31, 2011 (last updated October 04, 2023)
libvirtd in libvirt before 0.9.0 does not use thread-safe error reporting, which allows remote attackers to cause a denial of service (crash) by causing multiple threads to report errors at the same time.
0
Attacker Value
Unknown
CVE-2011-1146
Disclosure Date: March 15, 2011 (last updated October 04, 2023)
libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause a denial of service (host OS crash) or possibly execute arbitrary code via a (1) virNodeDeviceDettach, (2) virNodeDeviceReset, (3) virDomainRevertToSnapshot, (4) virDomainSnapshotDelete, (5) virNodeDeviceReAttach, or (6) virConnectDomainXMLToNative call, a different vulnerability than CVE-2008-5086.
0
Attacker Value
Unknown
CVE-2010-2238
Disclosure Date: August 19, 2010 (last updated October 04, 2023)
Red Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image backing stores without extracting the defined disk backing-store format, which might allow guest OS users to read arbitrary files on the host OS, and possibly have unspecified other impact, via unknown vectors.
0