8.8

CVE-2016-3710

The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.

Data is provided by the National Vulnerability Database (NVD)
DebianDebian Linux Version8.0
HpHelion Openstack Version2.0.0
HpHelion Openstack Version2.1.0
HpHelion Openstack Version2.1.2
HpHelion Openstack Version2.1.4
CanonicalUbuntu Linux Version12.04 SwEditionlts
CanonicalUbuntu Linux Version14.04 SwEditionlts
CanonicalUbuntu Linux Version15.10
CanonicalUbuntu Linux Version16.04 SwEditionlts
QemuQemu Version <= 2.5.1
QemuQemu Version2.6.0 Updaterc0
QemuQemu Version2.6.0 Updaterc1
QemuQemu Version2.6.0 Updaterc2
QemuQemu Version2.6.0 Updaterc3
QemuQemu Version2.6.0 Updaterc4
OracleVm Server Version3.2 HwPlatformx86
OracleVm Server Version3.3 HwPlatformx86
OracleVm Server Version3.4 HwPlatformx86
OracleLinux Version5 Update-
OracleLinux Version6 Update-
OracleLinux Version7 Update-
CitrixXenserver Version <= 7.0
RedhatOpenstack Version5.0
RedhatOpenstack Version6.0
RedhatOpenstack Version7.0
RedhatOpenstack Version8
RedhatVirtualization Version3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.09% 0.259
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://www.securityfocus.com/bid/90316
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1035794
Third Party Advisory
VDB Entry