Enterprise Virtualization Manager
Red Hat · 19 CVEs
GUI: Man in the middle attack possible on the GUI to Backend SSL connection
Nov 9, 2019
ovirt-engine-setup: unfiltered db password in engine-backup log
Jun 26, 2018
Kernel: error in exception handling leads to DoS
May 8, 2018
redhat-support-plugin-rhev: Remote code execution by SuperUser role on hosts in RHEV
Sep 25, 2017
RHEV: When "boot protocol" is set to None on an interface, interface still gets IPv6 address
Aug 24, 2017
ovirt-engine-dwh: incorrect permissions on plugin file containing passwords
May 1, 2015
vdsm: Users attempting a live storage migration create snapshot without snapshot creation permissions
May 1, 2015
Engine: XML eXternal Entity (XXE) flaw in backend module
Oct 18, 2014
rhev: remote-viewer spice tls-stripping issue
Jan 24, 2014
rhevm: insufficient target domain permission check when cloning a VM from a snapshot
Jul 3, 2013
rhev-m: insufficient MoveDisk target domain permission checks
Mar 12, 2013
rhev: rhevm-manage-domains logs admin passwords
Mar 12, 2013
rhev-m: MoveDisk ignores the disk's wipe-after-delete property
Jan 4, 2013
rhev: backend allows unprivileged queries
Jan 4, 2013
rhev: vds_installer is prone to MITM when downloading 2nd stage installer
Jan 4, 2013
rhev: vds_installer insecure /tmp use
Jan 4, 2013
Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, in certain unspecified conditions, does not lock the des…
Jan 4, 2013
spice activex/spicec named pipe races
Dec 8, 2010
rhev-m: merge snapshot does not pass postzero parameter for deleted volumes
Jun 24, 2010
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2009-3552 | GUI: Man in the middle attack possible on the GUI to Backend SSL connection | LOW | 0.35% | Nov 9, 2019 |
| CVE-2018-1072 | ovirt-engine-setup: unfiltered db password in engine-backup log | CRITICAL | 0.99% | Jun 26, 2018 |
| CVE-2018-8897 | Kernel: error in exception handling leads to DoS | HIGH | 18.48% | May 8, 2018 |
| CVE-2015-7544 | redhat-support-plugin-rhev: Remote code execution by SuperUser role on hosts in RHEV | CRITICAL | 3.44% | Sep 25, 2017 |
| CVE-2015-5293 | RHEV: When "boot protocol" is set to None on an interface, interface still gets IPv6 address | MEDIUM | 1.88% | Aug 24, 2017 |
| CVE-2015-0257 | ovirt-engine-dwh: incorrect permissions on plugin file containing passwords | LOW | 0.38% | May 1, 2015 |
| CVE-2015-0237 | vdsm: Users attempting a live storage migration create snapshot without snapshot creation permissions | MEDIUM | 1.58% | May 1, 2015 |
| CVE-2014-3573 | Engine: XML eXternal Entity (XXE) flaw in backend module | MEDIUM | 1.76% | Oct 18, 2014 |
| CVE-2013-6434 | rhev: remote-viewer spice tls-stripping issue | MEDIUM | 0.97% | Jan 24, 2014 |
| CVE-2013-2144 | rhevm: insufficient target domain permission check when cloning a VM from a snapshot | MEDIUM | 1.24% | Jul 3, 2013 |
| CVE-2013-0168 | rhev-m: insufficient MoveDisk target domain permission checks | MEDIUM | 1.92% | Mar 12, 2013 |
| CVE-2012-6115 | rhev: rhevm-manage-domains logs admin passwords | LOW | 0.37% | Mar 12, 2013 |
| CVE-2012-5516 | rhev-m: MoveDisk ignores the disk's wipe-after-delete property | LOW | 0.35% | Jan 4, 2013 |
| CVE-2012-2696 | rhev: backend allows unprivileged queries | LOW | 0.78% | Jan 4, 2013 |
| CVE-2012-0861 | rhev: vds_installer is prone to MITM when downloading 2nd stage installer | MEDIUM | 0.90% | Jan 4, 2013 |
| CVE-2012-0860 | rhev: vds_installer insecure /tmp use | MEDIUM | 0.40% | Jan 4, 2013 |
| CVE-2011-4316 | Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, in certain unspecified conditions, does not lock the desktop screen between SPICE sessions, whic… | LOW | 0.33% | Jan 4, 2013 |
| CVE-2010-2793 | spice activex/spicec named pipe races | MEDIUM | 1.02% | Dec 8, 2010 |
| CVE-2010-2224 | rhev-m: merge snapshot does not pass postzero parameter for deleted volumes | LOW | 0.33% | Jun 24, 2010 |
Showing 1 to 19 of 19 CVEs