Red Hat / Virtualization
128 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-5366 | Openvswitch don't match packets on nd_target field | HIGH | 7.1 | Oct 6, 2023 |
| CVE-2023-4911 KEV | Glibc: buffer overflow in ld.so leading to privilege escalation | HIGH | 7.8 | Oct 3, 2023 |
| CVE-2023-1668 | openvswitch: ip proto 0 triggers incorrect handling | HIGH | 8.2 | Apr 10, 2023 |
| CVE-2022-2805 | ovirt-engine: RHVM admin password is logged unfiltered when using otopi-style | MEDIUM | 6.5 | Oct 19, 2022 |
| CVE-2022-2132 | dpdk: DoS when a Vhost header crosses more than two descriptors and exhausts all mbufs | HIGH | 8.6 | Aug 31, 2022 |
| CVE-2022-0207 | vdsm: disclosure of sensitive values in log files | MEDIUM | 4.7 | Aug 26, 2022 |
| CVE-2022-2078 | kernel: buffer overflow in nft_set_desc_concat_parse() | MEDIUM | 5.5 | Jun 30, 2022 |
| CVE-2022-0435 | kernel: remote stack overflow via kernel panic on systems using TIPC may lead to DoS | HIGH | 8.8 | Mar 25, 2022 |
| CVE-2022-0330 | kernel: possible privileges escalation due to missing TLB flush | HIGH | 7.8 | Mar 25, 2022 |
| CVE-2022-27666 | kernel: buffer overflow in IPsec ESP transformation code | HIGH | 7.8 | Mar 23, 2022 |
| CVE-2021-3609 | kernel: race condition in net/can/bcm.c leads to local privilege escalation | HIGH | 7.0 | Mar 3, 2022 |
| CVE-2021-3620 | Ansible: ansible-connection module discloses sensitive info in traceback error message | MEDIUM | 6.8 | Mar 3, 2022 |
| CVE-2021-3677 | postgresql: memory disclosure in certain queries | MEDIUM | 6.5 | Mar 2, 2022 |
| CVE-2020-25717 | samba: Active Directory (AD) domain user could become root on domain members | HIGH | 8.1 | Feb 18, 2022 |
| CVE-2021-3560 KEV | polkit: local privilege escalation using polkit_system_bus_name_get_creds_sync() | HIGH | 7.8 | Feb 16, 2022 |
| CVE-2021-4154 | kernel: local privilege escalation by exploiting the fsconfig syscall parameter leads to container breakout | HIGH | 8.8 | Feb 4, 2022 |
| CVE-2021-3621 | sssd: shell command injection in sssctl | HIGH | 8.8 | Dec 23, 2021 |
| CVE-2021-3634 | libssh: possible heap-based buffer overflow when rekeying | MEDIUM | 6.5 | Aug 31, 2021 |
| CVE-2021-3501 | kernel: userspace applications can misuse the KVM API to cause a write of 16 bytes at an offset up to 32 GB from vcpu->run | HIGH | 7.8 | May 5, 2021 |
| CVE-2019-14850 | nbdkit: denial of service due to premature opening of back-end connection | LOW | 3.7 | Mar 18, 2021 |
| CVE-2020-27827 | lldp/openvswitch: denial of service via externally triggered memory leak | HIGH | 7.5 | Mar 18, 2021 |
| CVE-2020-25657 | m2crypto: bleichenbacher timing attacks in the RSA decryption API | HIGH | 7.5 | Jan 12, 2021 |
| CVE-2020-35497 | ovirt-engine: non-admin user is able to access other users public SSH key | MEDIUM | 6.5 | Dec 21, 2020 |
| CVE-2019-19336 | ovirt-engine: response_type parameter allows reflected XSS | MEDIUM | 6.1 | Mar 19, 2020 |
| CVE-2013-4535 | qemu: virtio: insufficient validation of num_sg when mapping | HIGH | 8.8 | Feb 11, 2020 |
Showing 1 to 25 of 128 CVEs