CVE-2016-9907
- EPSS 0.14%
- Veröffentlicht 23.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw. It could occur while destroying the USB redirector in 'usbredir_handle_destroy'. A guest user/process could use this issue to leak host memo...
CVE-2016-9911
- EPSS 0.14%
- Veröffentlicht 23.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Quick Emulator (Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage issue. It could occur while processing packet data in 'ehci_init_transfer'. A guest user/process could use this issue to leak host memory, resulting in ...
CVE-2016-9921
- EPSS 0.07%
- Veröffentlicht 23.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide by zero issue. It could occur while copying VGA data when cirrus graphics mode was set to be VGA. A privileged user inside guest could use this flaw ...
CVE-2013-1430
- EPSS 0.35%
- Veröffentlicht 16.12.2016 09:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES encrypted with a know...
CVE-2016-9964
- EPSS 1.09%
- Veröffentlicht 16.12.2016 09:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CRLF attack, as demonstrated by a redirect("233\r\nSet-Cookie: name=salt") call.
CVE-2016-6313
- EPSS 4.1%
- Veröffentlicht 13.12.2016 20:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of 160 bits by leveraging knowledge of the previous 46...
CVE-2016-7440
- EPSS 0.14%
- Veröffentlicht 13.12.2016 16:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.
CVE-2016-9427
- EPSS 2.41%
- Veröffentlicht 12.12.2016 02:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and possibly execute arbitrary code via huge allocation.
CVE-2016-7421
- EPSS 0.12%
- Veröffentlicht 10.12.2016 00:59:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit process IO loop to the...
CVE-2016-7170
- EPSS 0.11%
- Veröffentlicht 10.12.2016 00:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to cursor.mask[] and cursor.image[...