Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2024-0822
An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to …
Ovirt Engine
Patch available
MEDIUM 6.1
CVE-2022-3193
An HTML injection/reflected Cross-site scripting (XSS) vulnerability was found in the ovirt-engine. A parameter "error_description" fails to sanitize…
Ovirt Engine
Mitigation only
MEDIUM 6.1
CVE-2020-14333
A flaw was found in Ovirt Engine's web interface in ovirt 4.4 and earlier, where it did not filter user-controllable parameters completely, resulting…
Ovirt Engine
after 4.4.0
HIGH 7.8
CVE-2013-0293
oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation
Node
Mitigation only
HIGH 7.5
CVE-2012-5518
vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate)
Vdsm
Mitigation only
HIGH 7.8
CVE-2013-4367
ovirt-engine 3.2 running on Linux kernel 3.1 and newer creates certain files world-writeable due to an upstream kernel change which impacted how pyth…
Ovirt Engine
Patch available
HIGH 7.8
CVE-2019-10139
During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-setup/cockpit/ansibleVarFileXX…
Cockpit Ovirt
Mitigation only
HIGH 7.8
CVE-2018-1075
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one choo…
Ovirt
4.2.3+
HIGH 7.8
CVE-2018-1000018
An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file.
Ovirt Hosted Engine Setup
2.2.7+
HIGH 8.8
CVE-2014-8170
ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in ovirt-node 3.0.0-474-gb852fd7 as packaged in Red Hat Enterprise Virt…
Ovirt Node
Mitigation only
MEDIUM 5.5
CVE-2016-6341
oVirt Engine before 4.0.3 does not include DWH_DB_PASSWORD in the list of keys to hide in log files, which allows local users to obtain sensitive pas…
Ovirt
after 4.0.2
MEDIUM 5.0
CVE-2014-0154
oVirt Engine before 3.5.0 does not include the HTTPOnly flag in a Set-Cookie header for the session IDs, which makes it easier for remote attackers t…
Ovirt
after 3.4.4
MEDIUM 5.0
CVE-2012-3533
The python SDK before 3.1.0.6 and CLI before 3.1.0.8 for oVirt 3.1 does not check the server SSL certificate against the client keys, which allows re…
Ovirt
after 3.1.0.5