CVE-2018-18438
- EPSS 0.09%
- Veröffentlicht 19.10.2018 22:29:02
- Zuletzt bearbeitet 21.11.2024 03:55:56
Qemu has integer overflows because IOReadHandler and its associated functions use a signed integer data type for a size value.
CVE-2018-10839
- EPSS 1.56%
- Veröffentlicht 16.10.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 03:42:06
Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to cra...
CVE-2018-17963
- EPSS 1.53%
- Veröffentlicht 09.10.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:17
qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact.
CVE-2018-17958
- EPSS 0.89%
- Veröffentlicht 09.10.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:16
Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used.
CVE-2018-17962
- EPSS 0.26%
- Veröffentlicht 09.10.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:17
Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used.
CVE-2018-15746
- EPSS 0.05%
- Veröffentlicht 29.08.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:51:23
qemu-seccomp.c in QEMU might allow local OS guest users to cause a denial of service (guest crash) by leveraging mishandling of the seccomp policy for threads other than the main thread.
CVE-2016-9603
- EPSS 1.59%
- Veröffentlicht 27.07.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:01:29
A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged...
CVE-2017-15118
- EPSS 1.61%
- Veröffentlicht 27.07.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:06
A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of size up to 4096 bytes, which in fact should be limited to 256 bytes, causing an out-of-bounds stack ...
CVE-2017-2620
- EPSS 2.41%
- Veröffentlicht 27.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:50
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use t...
CVE-2017-2633
- EPSS 0.56%
- Veröffentlicht 27.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:52
An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use t...