Enterprise Virtualization Manager

Vendor:

First CVE: Jun 24, 2010 · Active for 16 years

19
Total CVEs
More Total CVEs than 93% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
5.1
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Enterprise Virtualization Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 24, 2010
16 years ago
Most Recent CVE
Nov 9, 2019
2,451 days ago

CVE Severity & Scoring

Enterprise Virtualization Manager19 CVEs
All CVEs352,719 CVEs
LowMediumHighCritical
Attack Vector
Local1 (5.3%)
Network3 (15.8%)
Unknown14 (73.7%)
Physical0 (0.0%)
Adjacent Network1 (5.3%)
Attack Complexity
Low3 (15.8%)
High2 (10.5%)
Unknown14 (73.7%)
User Interaction
None5 (26.3%)
Unknown14 (73.7%)
Required0 (0.0%)
Privileges Required
Low1 (5.3%)
High1 (5.3%)
None3 (15.8%)
Unknown14 (73.7%)

Top CVEs

Signals from CVEs in this product scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-sys
May 8, 20187.856NOYES
ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the databas
Jun 26, 20189.830NONO
redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role on any Entity to exe
Sep 25, 20179.123NONO
Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 ignores the permission to deny snapshot creation during live storage migration between domains, which allows remote au
May 1, 20156.822NONO
The vds_installer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, uses the -k curl parameter when downloading deployUtil.py and vds_bootstrap.
Jan 4, 20136.822NONO
Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certai
Dec 8, 20106.821NONO
Multiple untrusted search path vulnerabilities in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, allow local users to gain privileges via a Troj
Jan 4, 20136.220NONO
The oVirt Engine backend module, as used in Red Hat Enterprise Virtualization Manager before 3.4.2, uses an "insecure DocumentBuilderFactory," which allows remote attackers to read
Oct 18, 20146.518NONO
Red Hat Enterprise Virtualization Manager (RHEVM) before 3.2 does not properly check permissions for the target storage domain, which allows attackers to cause a denial of service
Jul 3, 20135.018NONO
Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which might allow remote attackers to
Aug 24, 20175.917NONO

Exploit Exposure

Signals from CVEs in this product scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
5.3% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
5.3% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (19 CVEs).

Media Mentions

Signals from CVEs in this product scope (19 CVEs).

Top CNAs Publishing CVEs For Enterprise Virtualization Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.219.81.0%00
3.5.019.13.4%00
3.4.119.13.4%00
3.419.13.4%00
3.114.31.0%00
3.054.64.7%01
2.2.412.10.4%00
2.2.394.10.8%00
2.2114.30.8%00
2.1104.40.8%00