CVE-2015-8745
- EPSS 0.07%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It could occur while reading Interrupt Mask Registers (IMR). A privileged (CAP_SYS_RAWIO) guest user could use this flaw to crash the...
CVE-2016-1922
- EPSS 0.08%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
QEMU (aka Quick Emulator) built with the TPR optimization for 32-bit Windows guests support is vulnerable to a null pointer dereference flaw. It occurs while doing I/O port write operations via hmp interface. In that, 'current_cpu' remains null, whic...
CVE-2016-1981
- EPSS 0.06%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing data via transmit or receive descriptors, provided the initial receive/transmit descriptor head (TDH/RDH) is...
CVE-2016-2198
- EPSS 0.1%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
QEMU (aka Quick Emulator) built with the USB EHCI emulation support is vulnerable to a null pointer dereference flaw. It could occur when an application attempts to write to EHCI capabilities registers. A privileged user inside quest could use this f...
CVE-2016-9776
- EPSS 0.06%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
QEMU (aka Quick Emulator) built with the ColdFire Fast Ethernet Controller emulator support is vulnerable to an infinite loop issue. It could occur while receiving packets in 'mcf_fec_receive'. A privileged user/process inside guest could use this is...
CVE-2016-9914
- EPSS 0.07%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in FileOperations.
CVE-2016-9915
- EPSS 0.07%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Memory leak in hw/9pfs/9p-handle.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in the handle back...
CVE-2016-9916
- EPSS 0.07%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Memory leak in hw/9pfs/9p-proxy.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in the proxy backen...
CVE-2016-7966
- EPSS 0.19%
- Veröffentlicht 23.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which gre...
CVE-2016-8707
- EPSS 1.95%
- Veröffentlicht 23.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A crafted TIFF document can lead to an out of bounds write which in particular circumstances could be leveraged into remote code ex...