Red Hat / Libvirt
73 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-8235 | Libvirt: crash of virtinterfaced via virconnectlistinterfaces() | MEDIUM | 6.2 | Aug 30, 2024 |
| CVE-2024-2496 | Libvirt: null pointer dereference in udevconnectlistallinterfaces() | MEDIUM | 5.5 | Mar 18, 2024 |
| CVE-2023-3750 | Libvirt: improper locking in virstoragepoolobjlistsearch may lead to denial of service | MEDIUM | 6.5 | Jul 24, 2023 |
| CVE-2023-2700 | libvirt: Memory leak in virPCIVirtualFunctionList cleanup | MEDIUM | 6.3 | May 15, 2023 |
| CVE-2021-3975 | libvirt: segmentation fault during VM shutdown can lead to vdsm hang | MEDIUM | 6.5 | Aug 23, 2022 |
| CVE-2022-0897 | libvirt: missing locking in nwfilterConnectNumOfNWFilters can lead to denial of service | MEDIUM | 5.0 | Mar 25, 2022 |
| CVE-2021-4147 | libvirt: deadlock and crash in libxl driver | MEDIUM | 6.5 | Mar 25, 2022 |
| CVE-2021-3667 | libvirt: Improper locking on ACL failure in virStoragePoolLookupByTargetPath API | MEDIUM | 6.5 | Mar 2, 2022 |
| CVE-2021-3631 | libvirt: Insecure sVirt label generation | MEDIUM | 6.3 | Mar 2, 2022 |
| CVE-2020-14301 | libvirt: leak of sensitive cookie information via dumpxml | MEDIUM | 6.5 | May 27, 2021 |
| CVE-2020-10701 | libvirt: guest agent timeout can be set under read-only mode leading to DoS | MEDIUM | 6.5 | May 27, 2021 |
| CVE-2021-3559 | libvirt: nodedev-list command may cause libvirt to crash on hosts with GRID driver installed | MEDIUM | 6.5 | May 24, 2021 |
| CVE-2020-14339 | libvirt: leak of /dev/mapper/control into QEMU guests | HIGH | 8.8 | Dec 3, 2020 |
| CVE-2020-25637 | libvirt: double free in qemuAgentGetInterfaces() in qemu_agent.c | MEDIUM | 6.7 | Oct 6, 2020 |
| CVE-2020-10703 | libvirt: Potential denial of service via active pool without target path | MEDIUM | 6.5 | Jun 2, 2020 |
| CVE-2020-12430 | libvirt: memory leak in domstats may allow read-only user to perform DoS attack | MEDIUM | 6.5 | Apr 28, 2020 |
| CVE-2019-20485 | libvirt: Potential DoS by holding a monitor job while querying QEMU guest-agent | MEDIUM | 5.8 | Mar 19, 2020 |
| CVE-2019-10168 | libvirt: arbitrary command execution via virConnectBaselineHypervisorCPU and virConnectCompareHypervisorCPU APIs | HIGH | 7.8 | Aug 2, 2019 |
| CVE-2019-10167 | libvirt: arbitrary command execution via virConnectGetDomainCapabilities API | HIGH | 7.8 | Aug 2, 2019 |
| CVE-2019-10166 | libvirt: virDomainManagedSaveDefineXML API exposed to readonly clients | HIGH | 7.8 | Aug 2, 2019 |
| CVE-2019-10161 | libvirt: arbitrary file read/exec via virDomainSaveImageGetXMLDesc API | HIGH | 7.8 | Jul 30, 2019 |
| CVE-2019-10132 | libvirt: wrong permissions in systemd admin-sock due to missing SocketMode parameter | HIGH | 8.8 | May 22, 2019 |
| CVE-2016-10746 | libvirt: libvirt-domain.c supports virDomainGetTime API calls with an RO connection instead of RW connection | HIGH | 7.5 | Apr 18, 2019 |
| CVE-2019-3886 | libvirt: virsh domhostname command discloses guest hostname in readonly mode | MEDIUM | 5.4 | Apr 4, 2019 |
| CVE-2019-3840 | libvirt: NULL pointer dereference after running qemuAgentCommand in qemuAgentGetInterfaces function | MEDIUM | 6.3 | Mar 27, 2019 |
Showing 1 to 25 of 73 CVEs