CVE List

Id CVE No. Status Description Phase Votes Comments Actions
44807  CVE-2010-2223  Candidate  Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 does not properly perform VM post-zeroing after the removal of a virtual machine"s data, which allows guest OS users to obtain sensitive information by examining the disk blocks associated with a deleted virtual machine.  Assigned (20100609)  None (candidate not yet proposed)    View
45395  CVE-2010-2811  Candidate  Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization (RHEV) 2.2 does not properly accept TCP connections for SSL sessions, which allows remote attackers to cause a denial of service (daemon outage) via crafted SSL traffic.  Assigned (20100722)  None (candidate not yet proposed)    View
24285  CVE-2007-0928  Candidate  Virtual Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an encoded password via a direct request for pwd.txt.  Assigned (20070213)  None (candidate not yet proposed)    View
56604  CVE-2012-3361  Candidate  virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image.  Assigned (20120614)  None (candidate not yet proposed)    View
56690  CVE-2012-3447  Candidate  virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image that uses a symlink that is only readable by root. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3361.  Assigned (20120614)  None (candidate not yet proposed)    View

Page 538 of 20943, showing 5 records out of 104715 total, starting on record 2686, ending on 2690

Actions