Known vulnerabilities in qemu-kvm (Red Hat package) - page 2

Software CPE: cpe:2.3:o:red_hat:qemu-kvm_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 33
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting qemu-kvm (Red Hat package) qemu-kvm (Red Hat package) is affected by 33 known vulnerabilities: 2 high, 16 medium, 15 low Critical High Medium Low

Vulnerabilities (33)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU45985 - Out-of-bounds write
CVE-2020-14364
CWE-787 Medium
Available
No
0.12.1.2-2.415.el6_5.21, 0.12.1.2-2.448.el6_6.9, 0.12.1.2-2.506.el6_10.8, 1.5.3-105.el7_2.20, 1.5.3-126.el7_3.18, 1.5.3-141.el7_4.11, 1.5.3-160.el7_6.8, 1.5.3-167.el7_7.7, 1.5.3-175.el7_9.1 24.08.2020 SB2020082410
SB2020090715
SB2020091121
and 35 more
#VU27389 - Use After Free
CVE-2020-1983
CWE-416 Medium
Available
No
1.5.3-175.el7_9.1 28.04.2020 SB2020042818
SB2020043016
SB2020050725
and 16 more
#VU27388 - Missing release of memory after effective lifetime
CVE-2019-20382
CWE-401 Medium
No
No
1.5.3-175.el7 28.04.2020 SB2019090618
SB2020040749
SB2020043016
and 8 more
#VU25458 - Heap-based Buffer Overflow
CVE-2020-7039
CWE-122 Low
No
No
1.5.3-167.el7_7.6, 1.5.3-173.el7 19.02.2020 SB2020021912
SB2020031117
SB2020031053
and 25 more
#VU25456 - Memory corruption
CVE-2020-8608
CWE-119 Low
No
No
0.12.1.2-2.506.el6_10.7, 1.5.3-160.el7_6.7, 1.5.3-167.el7_7.6, 1.5.3-173.el7_8.1 19.02.2020 SB2020021912
SB2020033013
SB2020040146
and 24 more
#VU20446 - Heap-based Buffer Overflow
CVE-2019-14378
CWE-122 Medium
No
No
1.5.3-160.el7_6.6 28.08.2019 SB2019082401
SB2019090204
SB2019090303
and 22 more
#VU28395 - Exposure of sensitive information to an unauthorized actor
CVE-2018-12127
CWE-200 Low
No
No
0.12.1.2-2.415.el6_5.20, 0.12.1.2-2.448.el6_6.8, 0.12.1.2-2.506.el6_10.3, 1.5.3-105.el7_2.19, 1.5.3-126.el7_3.17, 1.5.3-141.el7_4.10, 1.5.3-156.el7_5.7, 1.5.3-160.el7_6.2 30.05.2019 SB2019053010
SB2019051422
SB2019072469
and 67 more
#VU28396 - Exposure of sensitive information to an unauthorized actor
CVE-2018-12130
CWE-200 Low
No
No
0.12.1.2-2.415.el6_5.20, 0.12.1.2-2.448.el6_6.8, 0.12.1.2-2.506.el6_10.3, 1.5.3-105.el7_2.19, 1.5.3-126.el7_3.17, 1.5.3-141.el7_4.10, 1.5.3-156.el7_5.7, 1.5.3-160.el7_6.2 30.05.2019 SB2019053011
SB2019051422
SB2019072469
and 67 more
#VU28397 - Exposure of sensitive information to an unauthorized actor
CVE-2018-12126
CWE-200 Low
No
No
0.12.1.2-2.415.el6_5.20, 0.12.1.2-2.448.el6_6.8, 0.12.1.2-2.506.el6_10.3, 1.5.3-105.el7_2.19, 1.5.3-126.el7_3.17, 1.5.3-141.el7_4.10, 1.5.3-156.el7_5.7, 1.5.3-160.el7_6.2 30.05.2019 SB2019053012
SB2019051422
SB2019072469
and 67 more
#VU28398 - Exposure of sensitive information to an unauthorized actor
CVE-2019-11091
CWE-200 Low
No
No
0.12.1.2-2.415.el6_5.20, 0.12.1.2-2.448.el6_6.8, 0.12.1.2-2.506.el6_10.3, 1.5.3-105.el7_2.19, 1.5.3-126.el7_3.17, 1.5.3-141.el7_4.10, 1.5.3-156.el7_5.7, 1.5.3-160.el7_6.2 30.05.2019 SB2019053013
SB2019051422
SB2019072469
and 67 more
#VU16553 - Improper input validation
CVE-2018-15746
CWE-20 Low
No
No
1.5.3-175.el7 16.12.2018 SB2018121712
SB2018120730
SB2019080903
and 4 more
#VU12911 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2018-3639
CWE-362 Low
No
No
0.12.1.2-2.355.el6_4.11, 0.12.1.2-2.355.el6_4.12, 0.12.1.2-2.415.el6_5.18, 0.12.1.2-2.415.el6_5.19, 0.12.1.2-2.448.el6_6.6, 1.5.3-105.el7_2.17 22.05.2018 SB2018052201
SB2018052207
SB2018052208
and 142 more
#VU32259 - Resource exhaustion
CVE-2016-5403
CWE-400 Low
No
No
0.12.1.2-2.491.el6_8.3 02.08.2016 SB2016080207
SB2016081107
SB2016080949
and 2 more


Showing elements 21 - 40 out of 33