Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ovirt vulnerabilities and exploits
(subscribe to this query)
4.8
CVSSv3
CVE-2018-1000095
oVirt version 4.2.0 to 4.2.2 contains a Cross Site Scripting (XSS) vulnerability in the name/description of VMs portion of the web admin application. This vulnerability appears to have been fixed in version 4.2.3.
Redhat Ovirt-engine
6.5
CVSSv3
CVE-2016-3077
The VersionMapper.fromKernelVersionString method in oVirt Engine allows remote authenticated users to cause a denial of service (process crash) for all VMs.
Redhat Ovirt-engine -
NA
CVE-2014-0151
Cross-site request forgery (CSRF) vulnerability in oVirt Engine prior to 3.5.0 beta2 allows remote malicious users to hijack the authentication of users for requests that perform unspecified actions via a REST API request.
Redhat Ovirt-engine
7.8
CVSSv3
CVE-2013-0293
oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation
Ovirt Node 2.6.0-1
8.8
CVSSv3
CVE-2017-7510
In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.
Redhat Ovirt-engine 4.1.0
5.3
CVSSv3
CVE-2020-10775
An Open redirect vulnerability was found in ovirt-engine versions 4.4 and previous versions, where it allows remote malicious users to redirect users to arbitrary web sites and attempt phishing attacks. Once the target has opened the malicious URL in their browser, the critical p...
Oracle Virtualization 4.0
Redhat Ovirt-engine
6.5
CVSSv3
CVE-2015-1780
oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
Redhat Ovirt-engine -
Redhat Virtualization 3.0
5.5
CVSSv3
CVE-2022-2806
It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev
Sos Project Sos
Ovirt Log Collector
6.7
CVSSv3
CVE-2019-3831
A vulnerability exists in vdsm, version 4.19 up to and including 4.30.3 and 4.30.5 up to and including 4.30.8. The systemd_run function exposed to the vdsm system user could be abused to execute arbitrary commands as root.
Ovirt Vdsm
Redhat Gluster Storage 3.0
7.8
CVSSv3
CVE-2012-4480
mom creates world-writable pid files in /var/run
Ovirt Mom
Fedoraproject Fedora 17
Fedoraproject Fedora 18
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5248
CVE-2024-3110
CVE-2024-5552
CVE-2024-29415
HTML injection
CVE-2024-3095
TCP
type confusion
CVE-2024-1800
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »