The goal of this project is to make virtual world a safer and better place without child pornography, major computer crime and RIAA.
Login As
You can log in if you are registered at one of these services:
Security Bulletins
Latest Malware Updates

Infostealer.Posteal

02/26/2015

Downloader.Busadom

02/26/2015

Trojan.Ladocosm

02/26/2015

SONAR.SuspDocRun

02/25/2015

SONAR.SuspHelpRun

02/25/2015
06/12/2018

CVE-2018-1075

ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.

Attack vector:  Local
Product: 
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt
  • ovirt: ovirt

References: 
Severity:  Low
CVSS Score:  2.1
CVSS Vector:  (AV:L/AC:L/Au:N/C:P/I:N/A:N)
Security Advisories Database

Remote Code Execution Vulnerability in Microsoft OpenType Font Driver

A remote attacker can execute arbitrary code on the target system.

07/21/2015

SQL Injection Vulnerability in Piwigo

SQL inection vulnerability has been discovered in Piwigo.

02/05/2015

Cross-site Scripting Vulnerability in DotNetNuke

A cross-site scripting (XSS) vulnerability has been discovered in DotNetNuke.

02/05/2015

Cross-site Scripting Vulnerability in Hitachi Command Suite

A cross-site scripting vulnerability was found in Hitachi Command Suite.

02/02/2015

Denial of service vulnerability in FreeBSD SCTP RE_CONFIG Chunk Handling

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in Apache Traffic Server HTTP TRACE Max-Forwards

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in MalwareBytes Anti-Exploit "mbae.sys"

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in Linux Kernel splice

An attacker can perform a denial of service attack.

01/29/2015

Denial of service vulnerability in Python Pillow Module PNG Text Chunks Decompression

An attacker can perform a denial of service attack.

01/20/2015