Search CVE reports


Toggle filters

51 – 60 of 95 results


CVE-2014-8136

Low priority

Some fixes available 1 of 3

The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.

1 affected package

libvirt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt
Show less packages

CVE-2013-4399

Medium priority
Not affected

The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cause a denial of service...

1 affected package

libvirt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt
Show less packages

CVE-2014-7823

Medium priority
Fixed

The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.

1 affected package

libvirt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt
Show less packages

CVE-2014-3657

Medium priority
Fixed

The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the...

1 affected package

libvirt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt
Show less packages

CVE-2014-3633

Medium priority
Fixed

The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive...

1 affected package

libvirt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt
Show less packages

CVE-2014-5177

Low priority
Fixed

libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an...

1 affected package

libvirt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt
Show less packages

CVE-2014-0179

Low priority

Some fixes available 3 of 5

libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the...

1 affected package

libvirt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt
Show less packages

CVE-2013-7336

Medium priority
Fixed

The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not properly enter a monitor when performing seamless SPICE migration, which allows local users to cause a denial of service (NULL...

1 affected package

libvirt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt
Show less packages

CVE-2013-6456

Medium priority

Some fixes available 1 of 2

The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes...

1 affected package

libvirt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt
Show less packages

CVE-2014-1447

Medium priority

Some fixes available 3 of 4

Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent.

1 affected package

libvirt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libvirt
Show less packages