Enterprise Virtualization Manager

Red Hat · 19 CVEs

CVE-2009-3552
LOW

GUI: Man in the middle attack possible on the GUI to Backend SSL connection

Nov 9, 2019

CVE-2018-1072
CRITICAL

ovirt-engine-setup: unfiltered db password in engine-backup log

Jun 26, 2018

CVE-2018-8897
HIGH

Kernel: error in exception handling leads to DoS

May 8, 2018

CVE-2015-7544
CRITICAL

redhat-support-plugin-rhev: Remote code execution by SuperUser role on hosts in RHEV

Sep 25, 2017

CVE-2015-5293
MEDIUM

RHEV: When "boot protocol" is set to None on an interface, interface still gets IPv6 address

Aug 24, 2017

CVE-2015-0257
LOW

ovirt-engine-dwh: incorrect permissions on plugin file containing passwords

May 1, 2015

CVE-2015-0237
MEDIUM

vdsm: Users attempting a live storage migration create snapshot without snapshot creation permissions

May 1, 2015

CVE-2014-3573
MEDIUM

Engine: XML eXternal Entity (XXE) flaw in backend module

Oct 18, 2014

CVE-2013-6434
MEDIUM

rhev: remote-viewer spice tls-stripping issue

Jan 24, 2014

CVE-2013-2144
MEDIUM

rhevm: insufficient target domain permission check when cloning a VM from a snapshot

Jul 3, 2013

CVE-2013-0168
MEDIUM

rhev-m: insufficient MoveDisk target domain permission checks

Mar 12, 2013

CVE-2012-6115
LOW

rhev: rhevm-manage-domains logs admin passwords

Mar 12, 2013

CVE-2012-5516
LOW

rhev-m: MoveDisk ignores the disk's wipe-after-delete property

Jan 4, 2013

CVE-2012-2696
LOW

rhev: backend allows unprivileged queries

Jan 4, 2013

CVE-2012-0861
MEDIUM

rhev: vds_installer is prone to MITM when downloading 2nd stage installer

Jan 4, 2013

CVE-2012-0860
MEDIUM

rhev: vds_installer insecure /tmp use

Jan 4, 2013

CVE-2011-4316
LOW

Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, in certain unspecified conditions, does not lock the des…

Jan 4, 2013

CVE-2010-2793
MEDIUM

spice activex/spicec named pipe races

Dec 8, 2010

CVE-2010-2224
LOW

rhev-m: merge snapshot does not pass postzero parameter for deleted volumes

Jun 24, 2010

Showing 1 to 19 of 19 CVEs