Libvirt
Vendor:
First CVE: Mar 15, 2011 · Active for 15 years
73
Total CVEs
More Total CVEs than 99% of tracked products
5.2
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Libvirt over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2011
15 years ago
Most Recent CVE
Aug 30, 2024
693 days ago
CVE Severity & Scoring
Libvirt73 CVEs
19%
62%
18%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local14 (19.2%)
Network19 (26.0%)
Unknown38 (52.1%)
Physical0 (0.0%)
Adjacent Network2 (2.7%)
Attack Complexity
Low29 (39.7%)
High6 (8.2%)
Unknown38 (52.1%)
User Interaction
None35 (47.9%)
Unknown38 (52.1%)
Required0 (0.0%)
Privileges Required
Low26 (35.6%)
High1 (1.4%)
None8 (11.0%)
Unknown38 (52.1%)
Top CVEs
Signals from CVEs in this product scope (73 CVEs).
73 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-5008CRITICAL libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and e | Jul 13, 2016 | 9.8 | 32 | NO | NO |
CVE-2019-10132HIGH A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on | May 22, 2019 | 8.8 | 28 | NO | NO |
CVE-2016-10746HIGH libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a diff | Apr 18, 2019 | 7.5 | 26 | NO | NO |
CVE-2019-10167HIGH The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation | Aug 2, 2019 | 7.8 | 25 | NO | NO |
CVE-2019-10166HIGH It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would perm | Aug 2, 2019 | 7.8 | 25 | NO | NO |
CVE-2019-10161HIGH It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which wo | Jul 30, 2019 | 7.8 | 25 | NO | NO |
CVE-2018-5748HIGH qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply. | Jan 25, 2018 | 7.5 | 25 | NO | NO |
CVE-2017-1000256HIGH libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates b | Oct 31, 2017 | 8.1 | 25 | NO | NO |
CVE-2013-2218MEDIUM Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.0.6 allows remote attackers to cause a denial of service (li | Sep 30, 2013 | 5.0 | 25 | NO | YES |
CVE-2019-10168HIGH The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the pr | Aug 2, 2019 | 7.8 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (73 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.4% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (73 CVEs).
Media Mentions
Signals from CVEs in this product scope (73 CVEs).
Top CNAs Publishing CVEs For Libvirt
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.5.0 | 1 | 5.5 | 0.3% | 0 | 0 |
| 1.2.9 | 2 | 4.3 | 1.8% | 0 | 0 |
| 1.2.8 | 2 | 4.3 | 1.8% | 0 | 0 |
| 1.2.7 | 2 | 4.3 | 1.8% | 0 | 0 |
| 1.2.6 | 2 | 4.3 | 1.8% | 0 | 0 |
| 1.2.5 | 2 | 4.3 | 1.8% | 0 | 0 |
| 1.2.4 | 4 | 2.9 | 1.2% | 0 | 0 |
| 1.2.3 | 4 | 2.9 | 1.2% | 0 | 0 |
| 1.2.2 | 4 | 2.9 | 1.2% | 0 | 0 |
| 1.2.19 | 1 | 6.5 | 1.4% | 0 | 0 |
| 1.2.18 | 1 | 6.5 | 1.4% | 0 | 0 |
| 1.2.17 | 1 | 6.5 | 1.4% | 0 | 0 |
| 1.2.16 | 1 | 6.5 | 1.4% | 0 | 0 |
| 1.2.15 | 1 | 6.5 | 1.4% | 0 | 0 |
| 1.2.14 | 1 | 6.5 | 1.4% | 0 | 0 |
| 1.2.10 | 1 | 3.5 | 1.8% | 0 | 0 |
| 1.2.1 | 5 | 3.5 | 1.1% | 0 | 0 |
| 1.2.0 | 7 | 3.4 | 0.9% | 0 | 0 |
| 1.1.4 | 8 | 3.8 | 0.8% | 0 | 0 |
| 1.1.3 | 10 | 4.6 | 0.8% | 0 | 0 |