- EPSS 0.14%
- Published 09.12.2016 22:59:12
- Last modified 12.04.2025 10:46:40
Memory leak in the v9fs_write function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) by leveraging failure to free an IO vector.
- EPSS 0.11%
- Published 09.12.2016 22:59:11
- Last modified 12.04.2025 10:46:40
Memory leak in the v9fs_link function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors involving a reference to the source fid object.
CVE-2016-9104
- EPSS 0.12%
- Published 09.12.2016 22:59:10
- Last modified 12.04.2025 10:46:40
Multiple integer overflows in the (1) v9fs_xattr_read and (2) v9fs_xattr_write functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS administrators to cause a denial of service (QEMU process crash) via a crafted offset, which tr...
- EPSS 0.11%
- Published 09.12.2016 22:59:09
- Last modified 12.04.2025 10:46:40
The v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host heap memory information by reading xattribute values before writing to them.
- EPSS 0.03%
- Published 09.12.2016 22:59:07
- Last modified 12.04.2025 10:46:40
Memory leak in the v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) via a large number of Txattrcreate messages with t...
- EPSS 0.13%
- Published 09.12.2016 22:59:05
- Last modified 12.04.2025 10:46:40
Memory leak in hw/net/eepro100.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by repeatedly unplugging an i8255x (PRO100) NIC device.
CVE-2016-1248
- EPSS 23.18%
- Published 23.11.2016 15:59:00
- Last modified 12.04.2025 10:46:40
vim before patch 8.0.0056 does not properly validate values for the 'filetype', 'syntax' and 'keymap' options, which may result in the execution of arbitrary code if a file with a specially crafted modeline is opened.
CVE-2016-9376
- EPSS 1.48%
- Published 17.11.2016 05:59:05
- Last modified 12.04.2025 10:46:40
In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the OpenFlow dissector could crash with memory exhaustion, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-openflow_v5.c by ensuring that certain length valu...
CVE-2016-9375
- EPSS 1.48%
- Published 17.11.2016 05:59:04
- Last modified 12.04.2025 10:46:40
In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DTN dissector could go into an infinite loop, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-dtn.c by checking whether SDNV evaluation was successful.
CVE-2016-9374
- EPSS 1.22%
- Published 17.11.2016 05:59:03
- Last modified 12.04.2025 10:46:40
In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the AllJoyn dissector could crash with a buffer over-read, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-alljoyn.c by ensuring that a length variable prope...