CVE-2012-2652
- EPSS 0.11%
- Published 07.08.2012 20:55:03
- Last modified 11.04.2025 00:51:21
The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.
CVE-2011-1751
- EPSS 0.37%
- Published 21.06.2012 15:55:09
- Last modified 11.04.2025 00:51:21
The pciej_write function in hw/acpi_piix4.c in the PIIX4 Power Management emulation in qemu-kvm does not check if a device is hotpluggable before unplugging the PCI-ISA bridge, which allows privileged guest users to cause a denial of service (guest c...
CVE-2011-2212
- EPSS 0.79%
- Published 21.06.2012 15:55:09
- Last modified 11.04.2025 00:51:21
Buffer overflow in the virtio subsystem in qemu-kvm 0.14.0 and earlier allows privileged guest users to cause a denial of service (guest crash) or gain privileges via a crafted indirect descriptor related to "virtqueue in and out requests."
CVE-2011-2527
- EPSS 0.09%
- Published 21.06.2012 15:55:09
- Last modified 11.04.2025 00:51:21
The change_process_uid function in os-posix.c in Qemu 0.14.0 and earlier does not properly drop group privileges when the -runas option is used, which allows local guest users to access restricted files on the host.
CVE-2011-1750
- EPSS 0.47%
- Published 21.06.2012 15:55:08
- Last modified 11.04.2025 00:51:21
Multiple heap-based buffer overflows in the virtio-blk driver (hw/virtio-blk.c) in qemu-kvm 0.14.0 allow local guest users to cause a denial of service (guest crash) and possibly gain privileges via a (1) write request to the virtio_blk_handle_write ...
CVE-2011-0011
- EPSS 0.5%
- Published 21.06.2012 15:55:05
- Last modified 11.04.2025 00:51:21
qemu-kvm before 0.11.0 disables VNC authentication when the password is cleared, which allows remote attackers to bypass authentication and establish VNC sessions.
CVE-2010-0297
- EPSS 0.09%
- Published 12.02.2010 19:30:00
- Last modified 11.04.2025 00:51:21
Buffer overflow in the usb_host_handle_control function in the USB passthrough handling implementation in usb-linux.c in QEMU before 0.11.1 allows guest OS users to cause a denial of service (guest OS crash or hang) or possibly execute arbitrary code...
CVE-2009-3616
- EPSS 0.86%
- Published 23.10.2009 18:30:00
- Last modified 09.04.2025 00:30:58
Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on the host OS by establishing a connection from a VNC client and then (1) disconnecting during data tr...
CVE-2008-4539
- EPSS 0.05%
- Published 29.12.2008 15:24:23
- Last modified 09.04.2025 00:30:58
Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for a connection, aka the LGD-54XX "bitblt" heap over...
- EPSS 20.88%
- Published 24.12.2008 18:29:15
- Last modified 09.04.2025 00:30:58
The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote attackers to cause a denial of service (infinite loop) via a certain message.