Логотип exploitDog
bind:"CVE-2019-10161" OR bind:"CVE-2019-10166" OR bind:"CVE-2019-10167" OR bind:"CVE-2019-10168"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2019-10161" OR bind:"CVE-2019-10166" OR bind:"CVE-2019-10167" OR bind:"CVE-2019-10168"

Количество 40

Количество 40

fstec логотип

BDU:2019-02852

почти 6 лет назад

Уязвимость функции virDomainSaveImageGetXMLDesc() библиотеки управления виртуализацией Libvirt, позволяющая нарушителю вызвать отказ в обслуживании, выполнить произвольный код или определить наличие и размер произвольных файлов

CVSS3: 7.4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:14097-1

около 6 лет назад

Security update for libvirt

EPSS: Низкий
ubuntu логотип

CVE-2019-10166

почти 6 лет назад

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2019-10166

около 6 лет назад

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2019-10166

почти 6 лет назад

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2019-10166

почти 6 лет назад

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x. ...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-g9cg-gvh5-48hm

около 3 лет назад

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.

EPSS: Низкий
fstec логотип

BDU:2019-02445

около 6 лет назад

Уязвимость функции virDomainManagedSaveDefineXML библиотеки libvirtd, позволяющая нарушителю изменять произвольные файлы

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2019-10168

почти 6 лет назад

The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2019-10168

около 6 лет назад

The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-10168

почти 6 лет назад

The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2019-10168

почти 6 лет назад

The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorC ...

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2019-10167

почти 6 лет назад

The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2019-10167

около 6 лет назад

The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-10167

почти 6 лет назад

The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2019-10167

почти 6 лет назад

The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x befo ...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-v3hc-v42h-rp66

около 3 лет назад

The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.

EPSS: Низкий
fstec логотип

BDU:2019-02854

около 6 лет назад

Уязвимость функций virConnectBaselineHypervisorCPU() и virConnectCompareHypervisorCPU() библиотеки управления виртуализацией Libvirt, позволяющая нарушителю выполнить произвольный код или повысить свои привилегии

CVSS2: 4.6
EPSS: Низкий
github логотип

GHSA-5p5j-3wqp-w634

около 3 лет назад

The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.

CVSS3: 7.8
EPSS: Низкий
fstec логотип

BDU:2019-02853

почти 6 лет назад

Уязвимость функции virConnectGetDomainCapabilities() библиотеки управления виртуализацией Libvirt, позволяющая нарушителю выполнить произвольный код или повысить свои привилегии

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2019-02852

Уязвимость функции virDomainSaveImageGetXMLDesc() библиотеки управления виртуализацией Libvirt, позволяющая нарушителю вызвать отказ в обслуживании, выполнить произвольный код или определить наличие и размер произвольных файлов

CVSS3: 7.4
0%
Низкий
почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:14097-1

Security update for libvirt

около 6 лет назад
ubuntu логотип
CVE-2019-10166

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.

CVSS3: 7.8
0%
Низкий
почти 6 лет назад
redhat логотип
CVE-2019-10166

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.

CVSS3: 7.8
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-10166

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.

CVSS3: 7.8
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-10166

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x. ...

CVSS3: 7.8
0%
Низкий
почти 6 лет назад
github логотип
GHSA-g9cg-gvh5-48hm

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.

0%
Низкий
около 3 лет назад
fstec логотип
BDU:2019-02445

Уязвимость функции virDomainManagedSaveDefineXML библиотеки libvirtd, позволяющая нарушителю изменять произвольные файлы

CVSS2: 4.6
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2019-10168

The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.

CVSS3: 7.8
0%
Низкий
почти 6 лет назад
redhat логотип
CVE-2019-10168

The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.

CVSS3: 8.8
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-10168

The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.

CVSS3: 7.8
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-10168

The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorC ...

CVSS3: 7.8
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-10167

The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.

CVSS3: 7.8
0%
Низкий
почти 6 лет назад
redhat логотип
CVE-2019-10167

The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.

CVSS3: 8.8
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-10167

The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.

CVSS3: 7.8
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-10167

The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x befo ...

CVSS3: 7.8
0%
Низкий
почти 6 лет назад
github логотип
GHSA-v3hc-v42h-rp66

The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.

0%
Низкий
около 3 лет назад
fstec логотип
BDU:2019-02854

Уязвимость функций virConnectBaselineHypervisorCPU() и virConnectCompareHypervisorCPU() библиотеки управления виртуализацией Libvirt, позволяющая нарушителю выполнить произвольный код или повысить свои привилегии

CVSS2: 4.6
0%
Низкий
около 6 лет назад
github логотип
GHSA-5p5j-3wqp-w634

The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2019-02853

Уязвимость функции virConnectGetDomainCapabilities() библиотеки управления виртуализацией Libvirt, позволяющая нарушителю выполнить произвольный код или повысить свои привилегии

CVSS3: 4.9
0%
Низкий
почти 6 лет назад

Уязвимостей на страницу