CVE-2015-8080
- EPSS 2.73%
- Published 13.04.2016 15:59:04
- Last modified 12.04.2025 10:46:40
Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and appl...
CVE-2016-2857
- EPSS 0.06%
- Published 12.04.2016 02:00:07
- Last modified 12.04.2025 10:46:40
The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and crash) via the payload length in a crafted packet.
CVE-2016-1568
- EPSS 0.33%
- Published 12.04.2016 02:00:05
- Last modified 12.04.2025 10:46:40
Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via an invalid AHCI Native Command Queuing (NCQ)...
CVE-2015-5329
- EPSS 0.45%
- Published 11.04.2016 21:59:05
- Last modified 12.04.2025 10:46:40
The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 7.0, do not properly use the configured RabbitMQ credentials, which makes it easier for remote attackers to obtain access to services in deplo...
CVE-2016-1714
- EPSS 0.12%
- Published 07.04.2016 19:59:02
- Last modified 12.04.2025 10:46:40
The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration device emulation support, allow guest OS users with the CAP_SYS_RAWIO privilege to cause a denial of service (out-o...
CVE-2015-5295
- EPSS 1.64%
- Published 20.01.2016 16:59:00
- Last modified 12.04.2025 10:46:40
The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files ...
- EPSS 14.19%
- Published 08.01.2016 21:59:02
- Last modified 12.04.2025 10:46:40
Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary code via a large packet.
CVE-2015-5225
- EPSS 0.17%
- Published 06.11.2015 21:59:05
- Last modified 12.04.2025 10:46:40
Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service (heap memory corruption and process crash) or possibly execute arbitrary code on the host via ...
CVE-2015-3214
- EPSS 1.47%
- Published 31.08.2015 10:59:07
- Last modified 12.04.2025 10:46:40
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an inva...
CVE-2015-5165
- EPSS 10.86%
- Published 12.08.2015 14:59:24
- Last modified 12.04.2025 10:46:40
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.