Libvirt

Vendor:

First CVE: Mar 15, 2011 · Active for 15 years

73
Total CVEs
More Total CVEs than 99% of tracked products
5.2
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Libvirt over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2011
15 years ago
Most Recent CVE
Aug 30, 2024
693 days ago

CVE Severity & Scoring

Libvirt73 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local14 (19.2%)
Network19 (26.0%)
Unknown38 (52.1%)
Physical0 (0.0%)
Adjacent Network2 (2.7%)
Attack Complexity
Low29 (39.7%)
High6 (8.2%)
Unknown38 (52.1%)
User Interaction
None35 (47.9%)
Unknown38 (52.1%)
Required0 (0.0%)
Privileges Required
Low26 (35.6%)
High1 (1.4%)
None8 (11.0%)
Unknown38 (52.1%)

Top CVEs

Signals from CVEs in this product scope (73 CVEs).

73 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and e
Jul 13, 20169.832NONO
A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on
May 22, 20198.828NONO
libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a diff
Apr 18, 20197.526NONO
The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation
Aug 2, 20197.825NONO
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would perm
Aug 2, 20197.825NONO
It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which wo
Jul 30, 20197.825NONO
qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply.
Jan 25, 20187.525NONO
libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates b
Oct 31, 20178.125NONO
Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.0.6 allows remote attackers to cause a denial of service (li
Sep 30, 20135.025NOYES
The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the pr
Aug 2, 20197.824NONO

Exploit Exposure

Signals from CVEs in this product scope (73 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.4% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (73 CVEs).

Media Mentions

Signals from CVEs in this product scope (73 CVEs).

Top CNAs Publishing CVEs For Libvirt

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.5.015.50.3%00
1.2.924.31.8%00
1.2.824.31.8%00
1.2.724.31.8%00
1.2.624.31.8%00
1.2.524.31.8%00
1.2.442.91.2%00
1.2.342.91.2%00
1.2.242.91.2%00
1.2.1916.51.4%00
1.2.1816.51.4%00
1.2.1716.51.4%00
1.2.1616.51.4%00
1.2.1516.51.4%00
1.2.1416.51.4%00
1.2.1013.51.8%00
1.2.153.51.1%00
1.2.073.40.9%00
1.1.483.80.8%00
1.1.3104.60.8%00