- EPSS 0.11%
- Published 09.12.2016 22:59:09
- Last modified 12.04.2025 10:46:40
The v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host heap memory information by reading xattribute values before writing to them.
- EPSS 0.03%
- Published 09.12.2016 22:59:07
- Last modified 12.04.2025 10:46:40
Memory leak in the v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) via a large number of Txattrcreate messages with t...
- EPSS 0.13%
- Published 09.12.2016 22:59:05
- Last modified 12.04.2025 10:46:40
Memory leak in hw/net/eepro100.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by repeatedly unplugging an i8255x (PRO100) NIC device.
- EPSS 0.1%
- Published 04.11.2016 21:59:10
- Last modified 12.04.2025 10:46:40
The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) by leveraging failure to limit the ring descriptor count.
- EPSS 0.04%
- Published 04.11.2016 21:59:09
- Last modified 12.04.2025 10:46:40
The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via an entry with the same value for buffer length and pointer posi...
- EPSS 0.07%
- Published 04.11.2016 21:59:06
- Last modified 12.04.2025 10:46:40
The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via vectors involving a value of divider greater th...
- EPSS 0.16%
- Published 04.11.2016 21:59:05
- Last modified 12.04.2025 10:46:40
The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging failure to limit DMA buffer size.
- EPSS 0.08%
- Published 04.11.2016 21:59:03
- Last modified 12.04.2025 10:46:40
The rc4030_write function in hw/dma/rc4030.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via a large interval timer reload value.
- EPSS 0.12%
- Published 04.11.2016 21:59:02
- Last modified 12.04.2025 10:46:40
The v9fs_iov_vunmarshal function in fsdev/9p-iov-marshal.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) by sending an empty string parameter to a 9P o...
- EPSS 0.12%
- Published 04.11.2016 21:59:01
- Last modified 12.04.2025 10:46:40
Memory leak in the v9fs_read function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors related to an I/O read operation.