CVE-2016-7156
- EPSS 0.08%
- Veröffentlicht 10.12.2016 00:59:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
The pvscsi_convert_sglist function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging an incorrect cast.
CVE-2016-7155
- EPSS 0.08%
- Veröffentlicht 10.12.2016 00:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds access or infinite loop, and QEMU process crash) via a crafted page count for descriptor rings.
- EPSS 0.86%
- Veröffentlicht 10.12.2016 00:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Directory traversal vulnerability in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to access host files outside the export path via a .. (dot dot) in an unspecified string.
CVE-2016-6888
- EPSS 0.1%
- Veröffentlicht 10.12.2016 00:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU process crash) via the maximum fragmentation count, which triggers an uncheck...
- EPSS 0.08%
- Veröffentlicht 10.12.2016 00:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The vmxnet3_complete_packet function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host memory information by leveraging failure to initialize the txcq_descr object.
- EPSS 0.07%
- Veröffentlicht 10.12.2016 00:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The vmxnet_tx_pkt_parse_headers function in hw/net/vmxnet_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (buffer over-read) by leveraging failure to check IP header length.
CVE-2016-6834
- EPSS 0.11%
- Veröffentlicht 10.12.2016 00:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The net_tx_pkt_do_sw_fragmentation function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a zero length for the current fragment length...
CVE-2016-6833
- EPSS 0.08%
- Veröffentlicht 10.12.2016 00:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the vmxnet3_io_bar0_write function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU instance crash) by leveraging failure to check if the device i...
CVE-2016-6490
- EPSS 0.08%
- Veröffentlicht 10.12.2016 00:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a zero length for the descriptor buffer.
- EPSS 0.06%
- Veröffentlicht 10.12.2016 00:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The mptsas_fetch_requests function in hw/scsi/mptsas.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop, and CPU consumption or QEMU process crash) via vectors involving s->state.