Lucene search

K
cve[email protected]CVE-2014-8106
HistoryDec 08, 2014 - 4:59 p.m.

CVE-2014-8106

2014-12-0816:59:01
CWE-119
web.nvd.nist.gov
57
cve-2014-8106
heap-based buffer overflow
cirrus vga emulator
qemu
cve-2007-1320
nvd

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.6%

Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest users to execute arbitrary code via vectors related to blit regions. NOTE: this vulnerability exists because an incomplete fix for CVE-2007-1320.

Affected configurations

NVD
Node
qemuqemuRange2.1.2
OR
qemuqemuMatch2.1.0
OR
qemuqemuMatch2.1.0rc0
OR
qemuqemuMatch2.1.0rc1
OR
qemuqemuMatch2.1.0rc2
OR
qemuqemuMatch2.1.0rc3
OR
qemuqemuMatch2.1.0rc5
OR
qemuqemuMatch2.1.1

References

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.6%