- EPSS 0.11%
- Published 04.11.2016 21:59:00
- Last modified 12.04.2025 10:46:40
The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit the number of link Transfer Request...
CVE-2016-7423
- EPSS 0.15%
- Published 10.10.2016 16:59:02
- Last modified 12.04.2025 10:46:40
The mptsas_process_scsi_io_request function in QEMU (aka Quick Emulator), when built with LSI SAS1068 Host Bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vecto...
CVE-2016-7909
- EPSS 0.14%
- Published 05.10.2016 16:59:12
- Last modified 12.04.2025 10:46:40
The pcnet_rdra_addr function in hw/net/pcnet.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by setting the (1) receive or (2) transmit descriptor ring length to ...
CVE-2016-7908
- EPSS 0.14%
- Published 05.10.2016 16:59:11
- Last modified 12.04.2025 10:46:40
The mcf_fec_do_tx function in hw/net/mcf_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU...
CVE-2016-7907
- EPSS 0.11%
- Published 05.10.2016 16:59:10
- Last modified 12.04.2025 10:46:40
The imx_fec_do_tx function in hw/net/imx_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU...
- EPSS 5.18%
- Published 05.10.2016 16:59:05
- Last modified 12.04.2025 10:46:40
Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code on the QEMU host via a large ethlite packet.
CVE-2016-6351
- EPSS 0.17%
- Published 07.09.2016 18:59:04
- Last modified 12.04.2025 10:46:40
The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or execut...
- EPSS 0.06%
- Published 02.09.2016 14:59:04
- Last modified 12.04.2025 10:46:40
The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds read and crash) via unspecified vectors.
- EPSS 0.06%
- Published 02.09.2016 14:59:03
- Last modified 12.04.2025 10:46:40
The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest administrators to cause a denial of service (out-of-bounds write access) via vectors in...
CVE-2016-5105
- EPSS 0.06%
- Published 02.09.2016 14:59:02
- Last modified 12.04.2025 10:46:40
The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involvin...