Known vulnerabilities in qemu-kvm-rhev (Red Hat package)
Vendor:
Red Hat Inc.
Software:
qemu-kvm-rhev (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:qemu-kvm-rhev_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
28
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
2.9.0-16.el7_4.11
0.12.1.2-2.491.el6_8.6
0.12.1.2-2.491.el6_8.3
0.12.1.2-2.479.el6_7.5
0.12.1.2-2.491.el6_8.1
2.3.0-31.el7_2.13
0.12.1.2-2.479.el6_7.4
2.3.0-31.el7_2.7
0.12.1.2-2.479.el6_7.3
2.1.2-23.el7_1.10
2.9.0-16.el7_4.3
0.12.1.2-2.503.el6_9.3
2.6.0-28.el7_3.10
2.3.0-31.el7_2.21
2.6.0-28.el7_3.6
0.12.1.2-2.491.el6_8.7
2.6.0-28.el7_3.9
0.12.1.2-2.479.el6_7.2
2.1.2-23.el7_1.9
0.12.1.2-2.479.el6_7.1
2.1.2-23.el7_1.8
2.1.2-23.el7_1.6
0.12.1.2-2.448.el6_6.4
0.12.1.2-2.448.el6_6.3
0.12.1.2-2.448.el6_6.2
1.5.3-60.el7_0.10
1.5.3-60.el7_0.7
0.12.1.2-2.415.el6_5.14
0.12.1.2-2.415.el6_5.10
0.12.1.2-2.415.el6_5.8
0.12.1.2-2.355.el6_4.2
0.12.1.2-2.295.el6_3.2
2.12.0-18.el7_6.5
2.6.0-28.el7_3.17
2.12.0-48.el7_9.3
2.12.0-48.el7_9.2
2.12.0-33.el7_7.12
2.12.0-48.el7_9.1
2.12.0-48.el7
2.12.0-18.el7_6.11
2.12.0-44.el7_8.1
2.12.0-33.el7_7.10
2.12.0-44.el7
0.12.1.2-2.415.el6
2.9.0-10.el7
2.12.0-33.el7_7
2.12.0-33.el7
2.12.0-18.el7_6
2.12.0-18.el7
2.10.0-21.el7_5
2.10.0-21.el7
2.9.0-16.el7_4
2.9.0-14.el7
2.6.0-28.el7_3
2.6.0-27.el7
2.3.0-31.el7_2
2.3.0-31.el7
2.1.2-23.el7_1
2.1.2-23.el7
1.5.3-60.el7
1.5.3-60.el7_0
Vulnerabilities (28)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU50042 - Out-of-bounds read CVE-2020-29443 |
CWE-125 | Medium | 2.12.0-48.el7_9.3 | 26.01.2021 |
SB2021012636 SB2021060940 SB2021061423 and 2 more |
||
| #VU45985 - Out-of-bounds write CVE-2020-14364 |
CWE-787 | Medium | 2.12.0-33.el7_7.12, 2.12.0-48.el7_9.1 | 24.08.2020 |
SB2020082410 SB2020090715 SB2020091121 and 35 more |
||
| #VU44163 - Reachable Assertion CVE-2020-16092 |
CWE-617 | Medium | 2.12.0-48.el7_9.2 | 11.08.2020 |
SB2020081102 SB2020090715 SB2020101311 and 9 more |
||
| #VU27389 - Use After Free CVE-2020-1983 |
CWE-416 | Medium | 2.12.0-48.el7_9.2 | 28.04.2020 |
SB2020042818 SB2020043016 SB2020050725 and 16 more |
||
| #VU27388 - Missing release of memory after effective lifetime CVE-2019-20382 |
CWE-401 | Medium | 2.12.0-48.el7, 2.12.0-48.el7_9.1 | 28.04.2020 |
SB2019090618 SB2020040749 SB2020043016 and 8 more |
||
| #VU25510 - Heap-based Buffer Overflow CVE-2020-1711 |
CWE-122 | Medium | 2.12.0-33.el7_7.10, 2.12.0-44.el7 | 21.02.2020 |
SB2020022116 SB2020030419 SB2020030612 and 14 more |
||
| #VU25458 - Heap-based Buffer Overflow CVE-2020-7039 |
CWE-122 | Low | 2.12.0-18.el7_6.11, 2.12.0-33.el7_7.10, 2.12.0-44.el7, 2.12.0-44.el7_8.1 | 19.02.2020 |
SB2020021912 SB2020031117 SB2020031053 and 25 more |
||
| #VU25456 - Memory corruption CVE-2020-8608 |
CWE-119 | Low | 2.12.0-18.el7_6.11, 2.12.0-33.el7_7.10, 2.12.0-44.el7_8.1 | 19.02.2020 |
SB2020021912 SB2020033013 SB2020040146 and 24 more |
||
| #VU20499 - NULL Pointer Dereference CVE-2019-12155 |
CWE-476 | Medium | 2.12.0-44.el7 | 02.09.2019 |
SB2019090204 SB2019090303 SB2019090501 and 11 more |
||
| #VU20446 - Heap-based Buffer Overflow CVE-2019-14378 |
CWE-122 | Medium | 2.12.0-18.el7_6.11, 2.12.0-44.el7 | 28.08.2019 |
SB2019082401 SB2019090204 SB2019090303 and 22 more |
||
| #VU19189 - Memory corruption CVE-2018-20815 |
CWE-119 | Medium | 2.12.0-33.el7 | 16.07.2019 |
SB2019042505 SB2019070604 SB2019073010 and 13 more |
||
| #VU28395 - Exposure of sensitive information to an unauthorized actor CVE-2018-12127 |
CWE-200 | Low | 2.12.0-18.el7_6.5, 2.12.0-33.el7 | 30.05.2019 |
SB2019053010 SB2019051422 SB2019072469 and 67 more |
||
| #VU28396 - Exposure of sensitive information to an unauthorized actor CVE-2018-12130 |
CWE-200 | Low | 2.12.0-18.el7_6.5, 2.12.0-33.el7 | 30.05.2019 |
SB2019053011 SB2019051422 SB2019072469 and 67 more |
||
| #VU28397 - Exposure of sensitive information to an unauthorized actor CVE-2018-12126 |
CWE-200 | Low | 2.12.0-18.el7_6.5, 2.12.0-33.el7 | 30.05.2019 |
SB2019053012 SB2019051422 SB2019072469 and 67 more |
||
| #VU28398 - Exposure of sensitive information to an unauthorized actor CVE-2019-11091 |
CWE-200 | Low | 2.12.0-18.el7_6.5, 2.12.0-33.el7 | 30.05.2019 |
SB2019053013 SB2019051422 SB2019072469 and 67 more |
||
| #VU18303 - Missing release of memory after effective lifetime CVE-2019-9824 |
CWE-401 | Low | 2.12.0-33.el7 | 18.04.2019 |
SB2019041808 SB2019042505 SB2019080626 and 9 more |
||
| #VU18274 - Memory corruption CVE-2019-6501 |
CWE-119 | Low | 2.12.0-33.el7 | 15.04.2019 |
SB2019080806 SB2019080903 SB2019082235 |
||
| #VU16554 - Integer overflow CVE-2018-17958 |
CWE-190 | Low | 2.12.0-33.el7 | 17.12.2018 |
SB2018121712 SB2018120730 SB2019080903 and 2 more |
||
| #VU15997 - Buffer overflow CVE-2018-17963 |
CWE-120 | Low | 2.12.0-33.el7 | 21.11.2018 |
SB2018112121 SB2018121712 SB2018120730 and 4 more |
||
| #VU12911 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2018-3639 |
CWE-362 | Low | 2.6.0-28.el7_3.17 | 22.05.2018 |
SB2018052201 SB2018052207 SB2018052208 and 142 more |
Showing elements 1 - 20 out of 28