CVE-2017-10664
- EPSS 5.03%
- Veröffentlicht 02.08.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
qemu-nbd in QEMU (aka Quick Emulator) does not ignore SIGPIPE, which allows remote attackers to cause a denial of service (daemon crash) by disconnecting during a server-to-client reply attempt.
CVE-2017-7980
- EPSS 0.17%
- Veröffentlicht 25.07.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC client updating its display a...
CVE-2017-9214
- EPSS 7.31%
- Veröffentlicht 23.05.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.
CVE-2017-8309
- EPSS 1.58%
- Veröffentlicht 23.05.2017 04:29:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a denial of service (memory consumption) by repeatedly starting and stopping audio capture.
CVE-2017-8379
- EPSS 0.08%
- Veröffentlicht 23.05.2017 04:29:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) by rapidly generating large keyboard events.
CVE-2016-6519
- EPSS 0.28%
- Veröffentlicht 21.04.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitrary web script or HTML via the Metadata field in the "Create Share" form.
CVE-2008-7313
- EPSS 1.46%
- Veröffentlicht 31.03.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.
CVE-2014-5008
- EPSS 5.55%
- Veröffentlicht 31.03.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Snoopy allows remote attackers to execute arbitrary commands.
CVE-2014-5009
- EPSS 2.69%
- Veröffentlicht 31.03.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.
CVE-2017-5973
- EPSS 0.09%
- Veröffentlicht 27.03.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors related to control transfer descriptor sequence.