NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 39924 | CVE-2013-4297 | The virFileNBDDeviceAssociate function in util/virfile.c in libvirt 1.1.2 and earlier allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via unspecified vectors. | 2 | 4 | Medium | 2017-01-18 | 2015-01-02 | View | |
| 31809 | CVE-2014-3657 | The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command. | 2 | 5 | Medium | 2017-01-19 | 2014-11-18 | View | |
| 35116 | CVE-2014-7823 | The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag. | 2 | 5 | Medium | 2017-01-19 | 2017-01-02 | View | |
| 40013 | CVE-2013-4401 | The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3 checks for the connect:read permission instead of the connect:write permission, which allows attackers to gain domain:write privileges and execute Qemu binaries via crafted XML. NOTE: some of these details are obtained from third party information. | 2 | 8.5 | High | 2017-01-18 | 2015-01-02 | View | |
| 40920 | CVE-2013-5651 | The virBitmapParse function in util/virbitmap.c in libvirt before 1.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via a crafted bitmap, as demonstrated by a large nodeset value to numatune. | 2 | 5 | Medium | 2017-01-18 | 2015-01-02 | View |
Page 2795 of 17672, showing 5 records out of 88360 total, starting on record 13971, ending on 13975