Vulnerabilities > Redhat > Libvirt > 0.10.2

DATE CVE VULNERABILITY TITLE RISK
2018-03-28 CVE-2018-1064 Resource Exhaustion vulnerability in multiple products
libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.
network
low complexity
debian redhat CWE-400
7.5
2016-07-13 CVE-2016-5008 Improper Access Control vulnerability in multiple products
libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.
network
low complexity
redhat debian CWE-284
critical
9.8
2016-05-25 CVE-2014-3672 Resource Exhaustion vulnerability in multiple products
The qemu implementation in libvirt before 1.3.0 and Xen allows local guest OS users to cause a denial of service (host disk consumption) by writing to stdout or stderr.
local
low complexity
redhat xen CWE-400
6.5
2015-01-06 CVE-2014-8131 Permissions, Privileges, and Access Controls vulnerability in Redhat Libvirt
The qemu implementation of virConnectGetAllDomainStats in libvirt before 1.2.11 does not properly handle locks when a domain is skipped due to ACL restrictions, which allows a remote authenticated users to cause a denial of service (deadlock or segmentation fault and crash) via a request to access the users does not have privileges to access.
network
low complexity
redhat CWE-264
4.0
2014-11-13 CVE-2014-7823 Credentials Management vulnerability in Redhat Libvirt
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.
network
low complexity
redhat CWE-255
5.0
2014-01-24 CVE-2014-1447 Race Condition vulnerability in Redhat Libvirt
Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent.
low complexity
redhat CWE-362
3.3
2014-01-24 CVE-2013-6458 Race Condition vulnerability in Redhat Libvirt
Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify that the disk is attached, which allows remote read-only attackers to cause a denial of service (libvirtd crash) via the virDomainDetachDeviceFlags command.
high complexity
redhat CWE-362
6.8
2014-01-24 CVE-2013-6457 Permissions, Privileges, and Access Controls vulnerability in Redhat Libvirt
The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt before 1.2.1 does not properly initialize the nodemap, which allows local users to cause a denial of service (invalid free operation and crash) or possibly execute arbitrary code via an inactive domain to the virsh numatune command.
low complexity
redhat CWE-264
5.2
2013-10-03 CVE-2013-4311 Permissions, Privileges, and Access Controls vulnerability in multiple products
libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
local
low complexity
redhat canonical CWE-264
4.6
2013-03-20 CVE-2013-1766 Permissions, Privileges, and Access Controls vulnerability in Redhat Libvirt
libvirt 1.0.2 and earlier sets the group owner to kvm for device files, which allows local users to write to these files via unspecified vectors.
local
low complexity
redhat CWE-264
3.6