Enterprise Virtualization

Vendor:

First CVE: Oct 2, 2008 · Active for 17 years

37
Total CVEs
More Total CVEs than 97% of tracked products
3.7
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Enterprise Virtualization over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 2, 2008
17 years ago
Most Recent CVE
Feb 25, 2020
2,341 days ago

CVE Severity & Scoring

Enterprise Virtualization37 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local5 (13.5%)
Network6 (16.2%)
Unknown24 (64.9%)
Physical1 (2.7%)
Adjacent Network1 (2.7%)
Attack Complexity
Low11 (29.7%)
High2 (5.4%)
Unknown24 (64.9%)
User Interaction
None13 (35.1%)
Unknown24 (64.9%)
Required0 (0.0%)
Privileges Required
Low6 (16.2%)
High1 (2.7%)
None6 (16.2%)
Unknown24 (64.9%)

Top CVEs

Signals from CVEs in this product scope (37 CVEs).

37 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP c
May 17, 20187.589NOYES
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or p
May 13, 20157.742NOYES
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently
Jun 20, 20189.829NONO
Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via vectors rel
Oct 2, 200810.026NONO
Stack-based buffer overflow in libpixman, as used in Pale Moon before 15.4 and possibly other products, has unspecified impact and context-dependent attack vectors. NOTE: this iss
Jan 31, 20139.825NONO
VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virt
Feb 25, 20207.523NONO
ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in ovirt-node 3.0.0-474-gb852fd7 as packaged in Red Hat Enterprise Virtualization 3 do not properly qu
Sep 26, 20178.823NONO
ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin sess
Apr 20, 20176.823NONO
The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function whe
Feb 10, 20146.823NONO
Unquoted Windows search path vulnerability in Red Hat Enterprise Virtualization (RHEV) 3 and 3.2 allows local users to gain privileges via a crafted application in an unspecified f
Jan 21, 20147.222NONO

Exploit Exposure

Signals from CVEs in this product scope (37 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.7% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
5.4% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (37 CVEs).

Media Mentions

Signals from CVEs in this product scope (37 CVEs).

Top CNAs Publishing CVEs For Enterprise Virtualization

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.217.598.0%01
4.119.81.4%00
4.056.220.1%01
3.615.50.2%00
3.5110.04.5%00
3.433.21.1%00
3.265.20.6%00
3.0165.12.2%01
2.266.10.4%00