CVE-2016-7103
- EPSS 1.38%
- Veröffentlicht 15.03.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
CVE-2016-9907
- EPSS 0.14%
- Veröffentlicht 23.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw. It could occur while destroying the USB redirector in 'usbredir_handle_destroy'. A guest user/process could use this issue to leak host memo...
CVE-2016-9911
- EPSS 0.14%
- Veröffentlicht 23.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Quick Emulator (Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage issue. It could occur while processing packet data in 'ehci_init_transfer'. A guest user/process could use this issue to leak host memory, resulting in ...
CVE-2016-9921
- EPSS 0.07%
- Veröffentlicht 23.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide by zero issue. It could occur while copying VGA data when cirrus graphics mode was set to be VGA. A privileged user inside guest could use this flaw ...
- EPSS 0.09%
- Veröffentlicht 10.12.2016 00:59:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator), when the xhci uses msix, allows local guest OS administrators to cause a denial of service (memory consumption and possibly QEMU process crash) by repeatedly...
- EPSS 0.09%
- Veröffentlicht 10.12.2016 00:59:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via a large I/O descriptor buffer length value.
CVE-2016-6888
- EPSS 0.1%
- Veröffentlicht 10.12.2016 00:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU process crash) via the maximum fragmentation count, which triggers an uncheck...
- EPSS 0.1%
- Veröffentlicht 04.11.2016 21:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) by leveraging failure to limit the ring descriptor count.
- EPSS 0.04%
- Veröffentlicht 04.11.2016 21:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via an entry with the same value for buffer length and pointer posi...
- EPSS 0.07%
- Veröffentlicht 04.11.2016 21:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via vectors involving a value of divider greater th...