- EPSS 21.06%
- Veröffentlicht 08.01.2016 21:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary code via a large packet.
- EPSS 3.58%
- Veröffentlicht 09.11.2015 16:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable receive buffers are not supported, allows remote attackers to cause a denial of service (guest network consumption) via a flood of jumbo frames on th...
CVE-2015-6855
- EPSS 5.77%
- Veröffentlicht 06.11.2015 21:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_...
CVE-2015-5225
- EPSS 0.17%
- Veröffentlicht 06.11.2015 21:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service (heap memory corruption and process crash) or possibly execute arbitrary code on the host via ...
CVE-2015-5279
- EPSS 10.2%
- Veröffentlicht 28.09.2015 16:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via vectors related to receiving packets.
CVE-2015-3214
- EPSS 1.59%
- Veröffentlicht 31.08.2015 10:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an inva...
CVE-2015-4037
- EPSS 0.1%
- Veröffentlicht 26.08.2015 19:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The slirp_smb function in net/slirp.c in QEMU 2.3.0 and earlier creates temporary files with predictable names, which allows local users to cause a denial of service (instantiation failure) by creating /tmp/qemu-smb.*-* files before the program.
CVE-2015-5154
- EPSS 0.39%
- Veröffentlicht 12.08.2015 14:59:23
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, allows local guest users to execute arbitrary code on the host via unspecified ATAPI commands.
CVE-2015-3209
- EPSS 20.57%
- Veröffentlicht 15.06.2015 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
CVE-2015-4106
- EPSS 0.09%
- Veröffentlicht 03.06.2015 20:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly ha...