CVE-2014-3640
- EPSS 0.41%
- Veröffentlicht 07.11.2014 19:55:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized s...
CVE-2013-4542
- EPSS 4.95%
- Veröffentlicht 04.11.2014 21:55:25
- Zuletzt bearbeitet 06.05.2026 22:30:45
The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds array access.
CVE-2013-6399
- EPSS 3.87%
- Veröffentlicht 04.11.2014 21:55:25
- Zuletzt bearbeitet 06.05.2026 22:30:45
Array index error in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image.
CVE-2014-0182
- EPSS 5.41%
- Veröffentlicht 04.11.2014 21:55:25
- Zuletzt bearbeitet 06.05.2026 22:30:45
Heap-based buffer overflow in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted config length in a savevm image.
CVE-2014-0222
- EPSS 2.12%
- Veröffentlicht 04.11.2014 21:55:25
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service (crash) via a large L2 table in a QCOW version 1 image.
CVE-2014-0223
- EPSS 0.61%
- Veröffentlicht 04.11.2014 21:55:25
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a large image size, which triggers a buffer overflow or out-of-bounds read...
CVE-2014-3461
- EPSS 2.7%
- Veröffentlicht 04.11.2014 21:55:25
- Zuletzt bearbeitet 06.05.2026 22:30:45
hw/usb/bus.c in QEMU 1.6.2 allows remote attackers to execute arbitrary code via crafted savevm data, which triggers a heap-based buffer overflow, related to "USB post load checks."
CVE-2013-4148
- EPSS 4.94%
- Veröffentlicht 04.11.2014 21:55:24
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer signedness error in the virtio_net_load function in hw/net/virtio-net.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, which triggers a buffer overflow.
CVE-2013-4149
- EPSS 5.26%
- Veröffentlicht 04.11.2014 21:55:24
- Zuletzt bearbeitet 06.05.2026 22:30:45
Buffer overflow in virtio_net_load function in net/virtio-net.c in QEMU 1.3.0 through 1.7.x before 1.7.2 might allow remote attackers to execute arbitrary code via a large MAC table.
CVE-2013-4150
- EPSS 4.95%
- Veröffentlicht 04.11.2014 21:55:24
- Zuletzt bearbeitet 06.05.2026 22:30:45
The virtio_net_load function in hw/net/virtio-net.c in QEMU 1.5.0 through 1.7.x before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via vectors in which the value of curr_queues is greater than max_que...