CVE-2016-7907
- EPSS 0.41%
- Veröffentlicht 05.10.2016 16:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
The imx_fec_do_tx function in hw/net/imx_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU...
- EPSS 6.06%
- Veröffentlicht 05.10.2016 16:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code on the QEMU host via a large ethlite packet.
CVE-2016-6351
- EPSS 0.47%
- Veröffentlicht 07.09.2016 18:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or execut...
- EPSS 0.42%
- Veröffentlicht 02.09.2016 14:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds read and crash) via unspecified vectors.
- EPSS 0.39%
- Veröffentlicht 02.09.2016 14:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest administrators to cause a denial of service (out-of-bounds write access) via vectors in...
CVE-2016-5105
- EPSS 0.41%
- Veröffentlicht 02.09.2016 14:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involvin...
- EPSS 0.37%
- Veröffentlicht 02.09.2016 14:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds array access) via vectors related to the (1) PVSCSI_CMD_SETUP_RINGS or (...
CVE-2016-5403
- EPSS 0.52%
- Veröffentlicht 02.08.2016 16:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.
- EPSS 0.39%
- Veröffentlicht 16.06.2016 18:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via crafted values for the PSTART and PSTO...
CVE-2016-2538
- EPSS 0.41%
- Veröffentlicht 16.06.2016 18:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple integer overflows in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 allow local guest OS administrators to cause a denial of service (QEMU process crash) or obtain sensitive host memory information via a remote NDIS ...