Known vulnerabilities in qemu-kvm-rhev (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:qemu-kvm-rhev_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 28
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting qemu-kvm-rhev (Red Hat package) qemu-kvm-rhev (Red Hat package) is affected by 28 known vulnerabilities: 1 high, 9 medium, 18 low Critical High Medium Low

Vulnerabilities (28)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU50042 - Out-of-bounds read
CVE-2020-29443
CWE-125 Medium
No
No
2.12.0-48.el7_9.3 26.01.2021 SB2021012636
SB2021060940
SB2021061423
and 2 more
#VU45985 - Out-of-bounds write
CVE-2020-14364
CWE-787 Medium
Available
No
2.12.0-33.el7_7.12, 2.12.0-48.el7_9.1 24.08.2020 SB2020082410
SB2020090715
SB2020091121
and 35 more
#VU44163 - Reachable Assertion
CVE-2020-16092
CWE-617 Medium
No
No
2.12.0-48.el7_9.2 11.08.2020 SB2020081102
SB2020090715
SB2020101311
and 9 more
#VU27389 - Use After Free
CVE-2020-1983
CWE-416 Medium
Available
No
2.12.0-48.el7_9.2 28.04.2020 SB2020042818
SB2020043016
SB2020050725
and 16 more
#VU27388 - Missing release of memory after effective lifetime
CVE-2019-20382
CWE-401 Medium
No
No
2.12.0-48.el7, 2.12.0-48.el7_9.1 28.04.2020 SB2019090618
SB2020040749
SB2020043016
and 8 more
#VU25510 - Heap-based Buffer Overflow
CVE-2020-1711
CWE-122 Medium
No
No
2.12.0-33.el7_7.10, 2.12.0-44.el7 21.02.2020 SB2020022116
SB2020030419
SB2020030612
and 14 more
#VU25458 - Heap-based Buffer Overflow
CVE-2020-7039
CWE-122 Low
No
No
2.12.0-18.el7_6.11, 2.12.0-33.el7_7.10, 2.12.0-44.el7, 2.12.0-44.el7_8.1 19.02.2020 SB2020021912
SB2020031117
SB2020031053
and 25 more
#VU25456 - Memory corruption
CVE-2020-8608
CWE-119 Low
No
No
2.12.0-18.el7_6.11, 2.12.0-33.el7_7.10, 2.12.0-44.el7_8.1 19.02.2020 SB2020021912
SB2020033013
SB2020040146
and 24 more
#VU20499 - NULL Pointer Dereference
CVE-2019-12155
CWE-476 Medium
No
No
2.12.0-44.el7 02.09.2019 SB2019090204
SB2019090303
SB2019090501
and 11 more
#VU20446 - Heap-based Buffer Overflow
CVE-2019-14378
CWE-122 Medium
No
No
2.12.0-18.el7_6.11, 2.12.0-44.el7 28.08.2019 SB2019082401
SB2019090204
SB2019090303
and 22 more
#VU19189 - Memory corruption
CVE-2018-20815
CWE-119 Medium
No
No
2.12.0-33.el7 16.07.2019 SB2019042505
SB2019070604
SB2019073010
and 13 more
#VU28395 - Exposure of sensitive information to an unauthorized actor
CVE-2018-12127
CWE-200 Low
No
No
2.12.0-18.el7_6.5, 2.12.0-33.el7 30.05.2019 SB2019053010
SB2019051422
SB2019072469
and 67 more
#VU28396 - Exposure of sensitive information to an unauthorized actor
CVE-2018-12130
CWE-200 Low
No
No
2.12.0-18.el7_6.5, 2.12.0-33.el7 30.05.2019 SB2019053011
SB2019051422
SB2019072469
and 67 more
#VU28397 - Exposure of sensitive information to an unauthorized actor
CVE-2018-12126
CWE-200 Low
No
No
2.12.0-18.el7_6.5, 2.12.0-33.el7 30.05.2019 SB2019053012
SB2019051422
SB2019072469
and 67 more
#VU28398 - Exposure of sensitive information to an unauthorized actor
CVE-2019-11091
CWE-200 Low
No
No
2.12.0-18.el7_6.5, 2.12.0-33.el7 30.05.2019 SB2019053013
SB2019051422
SB2019072469
and 67 more
#VU18303 - Missing release of memory after effective lifetime
CVE-2019-9824
CWE-401 Low
No
No
2.12.0-33.el7 18.04.2019 SB2019041808
SB2019042505
SB2019080626
and 9 more
#VU18274 - Memory corruption
CVE-2019-6501
CWE-119 Low
No
No
2.12.0-33.el7 15.04.2019 SB2019080806
SB2019080903
SB2019082235
#VU16554 - Integer overflow
CVE-2018-17958
CWE-190 Low
No
No
2.12.0-33.el7 17.12.2018 SB2018121712
SB2018120730
SB2019080903
and 2 more
#VU15997 - Buffer overflow
CVE-2018-17963
CWE-120 Low
No
No
2.12.0-33.el7 21.11.2018 SB2018112121
SB2018121712
SB2018120730
and 4 more
#VU12911 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2018-3639
CWE-362 Low
No
No
2.6.0-28.el7_3.17 22.05.2018 SB2018052201
SB2018052207
SB2018052208
and 142 more


Showing elements 1 - 20 out of 28