Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2012-3445

The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers an out-of-bounds read or a free of an invalid pointer.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.013
EPSS Ranking 79.2%
CVSS Severity
CVSS v2 Score 3.5
References
Products affected by CVE-2012-3445
  • Redhat » Libvirt » Version: 0.9.13
    cpe:2.3:a:redhat:libvirt:0.9.13


Contact Us

Shodan ® - All rights reserved