CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

redhat

enterprise_virtualization

7 known vulnerabilities · sorted by CVSS score

CVE-2018-1074
HIGH7.7

ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control.

ovirt / ovirt+1
Network
Published Apr 26, 2018
CVE-2018-1111
HIGH7.5

DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.

fedoraproject / fedora+21
Adjacent
Published May 17, 2018
CVE-2015-5201
HIGH7.5

VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disable-ticketing and a VM is suspended and then restored, allows remote attackers to log in without authentication via unspecified vectors.

redhat / enterprise_virtualization+2
Network
Published Feb 25, 2020
CVE-2017-2614
MEDIUM6.8

When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with expired passwords, gaining access to those accounts.

redhat / enterprise_virtualization
Local
Published Jul 27, 2018
CVE-2014-8167
MEDIUM5.9

vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack

redhat / enterprise_virtualization+2
Network
Published Nov 13, 2019
CVE-2013-4280
MEDIUM5.5

Insecure temporary file vulnerability in RedHat vsdm 4.9.6.

redhat / virtual_desktop_server_manager+3
Local
Published Nov 4, 2019
CVE-2018-1117
MEDIUM5.0

ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.

ovirt / ovirt-ansible-roles+1
Local
Published Jun 20, 2018