Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): cpe:2.3:a:ovirt:vdsm:4.19.26:*:*:*:*:*:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2019-3831 |
A vulnerability was discovered in vdsm, version 4.19 through 4.30.3 and 4.30.5 through 4.30.8. The systemd_run function exposed to the vdsm system user could be abused to execute arbitrary commands as root. Published: March 25, 2019; 2:29:00 PM -0400 |
V4.0:(not available) V3.1: 6.7 MEDIUM V2.0: 9.0 HIGH |
CVE-2018-10908 |
It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By uploading a specially crafted image, an attacker could cause the qemu-img process to consume unbounded amounts of memory of CPU time, causing a denial of service condition that could potentially impact other users of the host. Published: August 09, 2018; 3:29:00 PM -0400 |
V4.0:(not available) V3.0: 6.3 MEDIUM V2.0: 7.1 HIGH |