CVE-2015-8701
- EPSS 0.07%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
QEMU (aka Quick Emulator) built with the Rocker switch emulation support is vulnerable to an off-by-one error. It happens while processing transmit (tx) descriptors in 'tx_consume' routine, if a descriptor was to have more than allowed (ROCKER_TX_FRA...
CVE-2015-8743
- EPSS 0.06%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
QEMU (aka Quick Emulator) built with the NE2000 device emulation support is vulnerable to an OOB r/w access issue. It could occur while performing 'ioport' r/w operations. A privileged (CAP_SYS_RAWIO) user/process could use this flaw to leak or corru...
CVE-2015-8744
- EPSS 0.07%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It occurs when a guest sends a Layer-2 packet smaller than 22 bytes. A privileged (CAP_SYS_RAWIO) guest user could use this flaw to c...
CVE-2015-8745
- EPSS 0.07%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It could occur while reading Interrupt Mask Registers (IMR). A privileged (CAP_SYS_RAWIO) guest user could use this flaw to crash the...
CVE-2015-8817
- EPSS 0.09%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
QEMU (aka Quick Emulator) built to use 'address_space_translate' to map an address to a MemoryRegionSection is vulnerable to an OOB r/w access issue. It could occur while doing pci_dma_read/write calls. Affects QEMU versions >= 1.6.0 and <= 2.3.1. A ...
CVE-2015-8818
- EPSS 0.09%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The cpu_physical_memory_write_rom_internal function in exec.c in QEMU (aka Quick Emulator) does not properly skip MMIO regions, which allows local privileged guest users to cause a denial of service (guest crash) via unspecified vectors.
CVE-2016-1922
- EPSS 0.08%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
QEMU (aka Quick Emulator) built with the TPR optimization for 32-bit Windows guests support is vulnerable to a null pointer dereference flaw. It occurs while doing I/O port write operations via hmp interface. In that, 'current_cpu' remains null, whic...
CVE-2016-1981
- EPSS 0.06%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing data via transmit or receive descriptors, provided the initial receive/transmit descriptor head (TDH/RDH) is...
CVE-2016-2197
- EPSS 0.11%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
QEMU (aka Quick Emulator) built with an IDE AHCI emulation support is vulnerable to a null pointer dereference flaw. It occurs while unmapping the Frame Information Structure (FIS) and Command List Block (CLB) entries. A privileged user inside guest ...
CVE-2016-2198
- EPSS 0.1%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
QEMU (aka Quick Emulator) built with the USB EHCI emulation support is vulnerable to a null pointer dereference flaw. It could occur when an application attempts to write to EHCI capabilities registers. A privileged user inside quest could use this f...