- EPSS 0.1%
- Published 10.01.2018 15:29:00
- Last modified 21.11.2024 03:32:06
In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernate Validator, a potential privi...
CVE-2017-10664
- EPSS 5.03%
- Published 02.08.2017 19:29:00
- Last modified 20.04.2025 01:37:25
qemu-nbd in QEMU (aka Quick Emulator) does not ignore SIGPIPE, which allows remote attackers to cause a denial of service (daemon crash) by disconnecting during a server-to-client reply attempt.
CVE-2017-7980
- EPSS 0.17%
- Published 25.07.2017 14:29:00
- Last modified 20.04.2025 01:37:25
Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC client updating its display a...
CVE-2017-9214
- EPSS 7.31%
- Published 23.05.2017 17:29:00
- Last modified 20.04.2025 01:37:25
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.
CVE-2017-5973
- EPSS 0.09%
- Published 27.03.2017 15:59:00
- Last modified 20.04.2025 01:37:25
The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors related to control transfer descriptor sequence.
CVE-2016-9907
- EPSS 0.14%
- Published 23.12.2016 22:59:00
- Last modified 12.04.2025 10:46:40
Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw. It could occur while destroying the USB redirector in 'usbredir_handle_destroy'. A guest user/process could use this issue to leak host memo...
CVE-2016-9911
- EPSS 0.14%
- Published 23.12.2016 22:59:00
- Last modified 12.04.2025 10:46:40
Quick Emulator (Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage issue. It could occur while processing packet data in 'ehci_init_transfer'. A guest user/process could use this issue to leak host memory, resulting in ...
CVE-2016-9921
- EPSS 0.07%
- Published 23.12.2016 22:59:00
- Last modified 12.04.2025 10:46:40
Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide by zero issue. It could occur while copying VGA data when cirrus graphics mode was set to be VGA. A privileged user inside guest could use this flaw ...
- EPSS 0.09%
- Published 10.12.2016 00:59:19
- Last modified 12.04.2025 10:46:40
Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator), when the xhci uses msix, allows local guest OS administrators to cause a denial of service (memory consumption and possibly QEMU process crash) by repeatedly...
- EPSS 0.09%
- Published 10.12.2016 00:59:18
- Last modified 12.04.2025 10:46:40
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via a large I/O descriptor buffer length value.