CVE-2013-4533
- EPSS 2%
- Veröffentlicht 04.11.2014 21:55:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the pxa2xx_ssp_load function in hw/arm/pxa2xx.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted s->rx_level value in a savevm image.
CVE-2013-4534
- EPSS 2%
- Veröffentlicht 04.11.2014 21:55:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in hw/intc/openpic.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via vectors related to IRQDest elements.
CVE-2013-4537
- EPSS 1.9%
- Veröffentlicht 04.11.2014 21:55:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a savevm image.
CVE-2013-4538
- EPSS 2.55%
- Veröffentlicht 04.11.2014 21:55:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple buffer overflows in the ssd0323_load function in hw/display/ssd0323.c in QEMU before 1.7.2 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted (1) cmd_len, (2) row, or (3) co...
CVE-2013-4539
- EPSS 4.29%
- Veröffentlicht 04.11.2014 21:55:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple buffer overflows in the tsc210x_load function in hw/input/tsc210x.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted (1) precision, (2) nextprecision, (3) function, or (4) nextfunction value in a save...
CVE-2013-4540
- EPSS 3.84%
- Veröffentlicht 04.11.2014 21:55:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in scoop_gpio_handler_update in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a large (1) prev_level, (2) gpio_level, or (3) gpio_dir value in a savevm image.
CVE-2013-4541
- EPSS 1.73%
- Veröffentlicht 04.11.2014 21:55:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
The usb_device_post_load function in hw/usb/bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, related to a negative setup_len or setup_index value.
CVE-2014-3615
- EPSS 0.09%
- Veröffentlicht 01.11.2014 23:55:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
CVE-2014-5263
- EPSS 0.41%
- Veröffentlicht 26.08.2014 14:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the list with the VMSTATE_END_OF_LIST macro, which allows attackers to cause a denial of service (out-of-bounds access, infinite loop, and memory corruption) and possibly gain p...
CVE-2013-4544
- EPSS 0.13%
- Veröffentlicht 08.05.2014 14:29:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
hw/net/vmxnet3.c in QEMU 2.0.0-rc0, 1.7.1, and earlier allows local guest users to cause a denial of service or possibly execute arbitrary code via vectors related to (1) RX or (2) TX queue numbers or (3) interrupt indices. NOTE: some of these detai...