Qemu

Qemu

422 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2%
  • Veröffentlicht 04.11.2014 21:55:24
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Buffer overflow in the pxa2xx_ssp_load function in hw/arm/pxa2xx.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted s->rx_level value in a savevm image.

  • EPSS 2%
  • Veröffentlicht 04.11.2014 21:55:24
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Buffer overflow in hw/intc/openpic.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via vectors related to IRQDest elements.

  • EPSS 1.9%
  • Veröffentlicht 04.11.2014 21:55:24
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a savevm image.

  • EPSS 2.55%
  • Veröffentlicht 04.11.2014 21:55:24
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple buffer overflows in the ssd0323_load function in hw/display/ssd0323.c in QEMU before 1.7.2 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted (1) cmd_len, (2) row, or (3) co...

  • EPSS 4.29%
  • Veröffentlicht 04.11.2014 21:55:24
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple buffer overflows in the tsc210x_load function in hw/input/tsc210x.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted (1) precision, (2) nextprecision, (3) function, or (4) nextfunction value in a save...

  • EPSS 3.84%
  • Veröffentlicht 04.11.2014 21:55:24
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Buffer overflow in scoop_gpio_handler_update in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a large (1) prev_level, (2) gpio_level, or (3) gpio_dir value in a savevm image.

  • EPSS 1.73%
  • Veröffentlicht 04.11.2014 21:55:24
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The usb_device_post_load function in hw/usb/bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, related to a negative setup_len or setup_index value.

  • EPSS 0.09%
  • Veröffentlicht 01.11.2014 23:55:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.

  • EPSS 0.41%
  • Veröffentlicht 26.08.2014 14:55:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the list with the VMSTATE_END_OF_LIST macro, which allows attackers to cause a denial of service (out-of-bounds access, infinite loop, and memory corruption) and possibly gain p...

  • EPSS 0.13%
  • Veröffentlicht 08.05.2014 14:29:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

hw/net/vmxnet3.c in QEMU 2.0.0-rc0, 1.7.1, and earlier allows local guest users to cause a denial of service or possibly execute arbitrary code via vectors related to (1) RX or (2) TX queue numbers or (3) interrupt indices. NOTE: some of these detai...