CVE-2021-3544
- EPSS 0.03%
- Published 02.06.2021 14:15:10
- Last modified 21.11.2024 06:21:48
Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. They exist in contrib/vhost-user-gpu/vhost-user-gpu.c and contrib/vhost-user-gpu/virgl.c due to improper release of memo...
CVE-2021-3545
- EPSS 0.09%
- Published 02.06.2021 14:15:10
- Last modified 21.11.2024 06:21:48
An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw exists in virgl_cmd_get_capset_info() in contrib/vhost-user-gpu/virgl.c and could occur due t...
- EPSS 0.02%
- Published 02.06.2021 14:15:07
- Last modified 21.11.2024 05:27:26
A NULL pointer dereference flaw was found in the megasas-gen2 SCSI host bus adapter emulation of QEMU in versions before and including 6.0. This issue occurs in the megasas_command_cancelled() callback function while dropping a SCSI request. This fla...
CVE-2013-4536
- EPSS 0.04%
- Published 28.05.2021 17:15:07
- Last modified 21.11.2024 01:55:47
An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary code execution on the host with ...
- EPSS 0.02%
- Published 28.05.2021 11:15:07
- Last modified 21.11.2024 05:27:26
A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this v...
CVE-2020-35505
- EPSS 0.02%
- Published 28.05.2021 11:15:07
- Last modified 21.11.2024 05:27:26
A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0. This issue occurs while handling the 'Information Transfer' command. This flaw allows a privileged guest user to crash the QEM...
CVE-2020-35506
- EPSS 0.03%
- Published 28.05.2021 11:15:07
- Last modified 21.11.2024 05:27:27
A use-after-free vulnerability was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0 during the handling of the 'Information Transfer' command (CMD_TI). This flaw allows a privileged guest user to crash the QEMU p...
CVE-2021-3527
- EPSS 0.02%
- Published 26.05.2021 22:15:08
- Last modified 21.11.2024 06:21:45
A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined into a single, large transfer request, to reduce the overhead and improve performance. The combined size of the bulk transfer is used to dynamically all...
CVE-2021-20196
- EPSS 0.03%
- Published 26.05.2021 22:15:07
- Last modified 21.11.2024 05:46:06
A NULL pointer dereference flaw was found in the floppy disk emulator of QEMU. This issue occurs while processing read/write ioport commands if the selected floppy drive is not initialized with a block device. This flaw allows a privileged guest user...
CVE-2021-20181
- EPSS 0.01%
- Published 13.05.2021 16:15:07
- Last modified 21.11.2024 05:46:04
A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a malicious 9p client to cause a use-after-free error, potentially escalating their privileges on the system. The highest threat fro...