OpenVZ is a containerization and virtualization platform whose vulnerability exposure concentrates in its kernel module and control utilities, particularly vzkernel and vzctl, where the recurring pattern centers on access-control and symlink-resolution weaknesses. These weakness classes reflect the privilege-boundary and filesystem-handling demands of system-level container management. Live severity, exploitation, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openvz over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-6838HIGH An unspecified Enghouse Interactive Professional Services "addon product" in Enghouse Interactive IVR Pro (VIP2000) 9.0.3 (rel903), when using OpenVZ and fallback customization, us | Jan 28, 2014 | 10.0 | 31 | NO | NO |
CVE-2014-3519MEDIUM The open_by_handle_at function in vzkernel before 042stab090.5 in the OpenVZ modification for the Linux kernel 2.6.32, when using simfs, might allow local container users with CAP_ | Feb 1, 2018 | 6.5 | 19 | NO | NO |
CVE-2013-2239MEDIUM vzkernel before 042stab080.2 in the OpenVZ modification for the Linux kernel 2.6.32 does not initialize certain length variables, which allows local users to obtain sensitive infor | Nov 12, 2013 | 4.7 | 14 | NO | NO |
vzctl before 4.9.4 determines the virtual environment (VE) layout based on the presence of root.hdd/DiskDescriptor.xml in the VE private directory, which allows local simfs contain | Sep 28, 2015 | 3.6 | 13 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openvz.
Media articles that mention a CVE ID that affects a product developed by Openvz — matched by CVE ID, not by vendor name.