CVE-2016-2198
- EPSS 0.1%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
QEMU (aka Quick Emulator) built with the USB EHCI emulation support is vulnerable to a null pointer dereference flaw. It could occur when an application attempts to write to EHCI capabilities registers. A privileged user inside quest could use this f...
CVE-2016-9776
- EPSS 0.06%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
QEMU (aka Quick Emulator) built with the ColdFire Fast Ethernet Controller emulator support is vulnerable to an infinite loop issue. It could occur while receiving packets in 'mcf_fec_receive'. A privileged user/process inside guest could use this is...
CVE-2016-9914
- EPSS 0.07%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in FileOperations.
CVE-2016-9915
- EPSS 0.07%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Memory leak in hw/9pfs/9p-handle.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in the handle back...
CVE-2016-9916
- EPSS 0.07%
- Veröffentlicht 29.12.2016 22:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Memory leak in hw/9pfs/9p-proxy.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in the proxy backen...
CVE-2016-7966
- EPSS 0.27%
- Veröffentlicht 23.12.2016 22:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which gre...
CVE-2016-8707
- EPSS 2.14%
- Veröffentlicht 23.12.2016 22:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A crafted TIFF document can lead to an out of bounds write which in particular circumstances could be leveraged into remote code ex...
CVE-2016-9907
- EPSS 0.15%
- Veröffentlicht 23.12.2016 22:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw. It could occur while destroying the USB redirector in 'usbredir_handle_destroy'. A guest user/process could use this issue to leak host memo...
CVE-2016-9911
- EPSS 0.15%
- Veröffentlicht 23.12.2016 22:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Quick Emulator (Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage issue. It could occur while processing packet data in 'ehci_init_transfer'. A guest user/process could use this issue to leak host memory, resulting in ...
CVE-2016-9921
- EPSS 0.1%
- Veröffentlicht 23.12.2016 22:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide by zero issue. It could occur while copying VGA data when cirrus graphics mode was set to be VGA. A privileged user inside guest could use this flaw ...