Lucene search

K

Qemu Security Vulnerabilities

cve
cve

CVE-2016-4964

The mptsas_fetch_requests function in hw/scsi/mptsas.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop, and CPU consumption or QEMU process crash) via vectors involving...

6CVSS

5.9AI Score

0.001EPSS

2016-12-10 12:59 AM
28
4
cve
cve

CVE-2015-8818

The cpu_physical_memory_write_rom_internal function in exec.c in QEMU (aka Quick Emulator) does not properly skip MMIO regions, which allows local privileged guest users to cause a denial of service (guest crash) via unspecified...

5.5CVSS

5.6AI Score

0.001EPSS

2016-12-29 10:59 PM
30
cve
cve

CVE-2018-10839

Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in...

6.5CVSS

8AI Score

0.004EPSS

2018-10-16 02:29 PM
99
cve
cve

CVE-2015-5279

Heap-based buffer overflow in the ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via vectors related to receiving...

7.5AI Score

0.001EPSS

2015-09-28 04:59 PM
80
cve
cve

CVE-2014-2894

Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact via a SMART EXECUTE OFFLINE command that triggers a buffer underflow and memory...

6.8AI Score

0.0004EPSS

2014-04-23 03:55 PM
60
cve
cve

CVE-2014-8106

Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest users to execute arbitrary code via vectors related to blit regions. NOTE: this vulnerability exists because an incomplete fix for...

7.5AI Score

0.001EPSS

2014-12-08 04:59 PM
57
cve
cve

CVE-2014-0142

QEMU, possibly before 2.0.0, allows local users to cause a denial of service (divide-by-zero error and crash) via a zero value in the (1) tracks field to the seek_to_sector function in block/parallels.c or (2) extent_size field in the bochs function in...

5.5CVSS

6.2AI Score

0.0004EPSS

2017-08-10 03:29 PM
50
cve
cve

CVE-2013-4526

Buffer overflow in hw/ide/ahci.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via vectors related to migrating...

8.7AI Score

0.062EPSS

2014-11-04 09:55 PM
43
cve
cve

CVE-2017-7471

Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System (9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing files on a shared host directory. A privileged user inside guest could use this flaw to access host file...

9CVSS

8.7AI Score

0.001EPSS

2018-07-09 02:29 PM
42
cve
cve

CVE-2017-5857

Memory leak in the virgl_cmd_resource_unref function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_UNREF commands sent without detaching the backing storage....

6.5CVSS

5.9AI Score

0.001EPSS

2017-03-16 03:59 PM
76
cve
cve

CVE-2016-9916

Memory leak in hw/9pfs/9p-proxy.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in the proxy...

6.5CVSS

5.9AI Score

0.001EPSS

2016-12-29 10:59 PM
54
4
cve
cve

CVE-2016-2538

Multiple integer overflows in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 allow local guest OS administrators to cause a denial of service (QEMU process crash) or obtain sensitive host memory information via a remote NDIS control message packet that is mishandled in the....

7.1CVSS

7.3AI Score

0.001EPSS

2016-06-16 06:59 PM
53
cve
cve

CVE-2016-10028

The virgl_cmd_get_capset function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) built with Virtio GPU Device emulator support allows local guest OS users to cause a denial of service (out-of-bounds read and process crash) via a VIRTIO_GPU_CMD_GET_CAPSET command with a maximum...

5.5CVSS

5.4AI Score

0.001EPSS

2017-02-27 10:59 PM
53
cve
cve

CVE-2015-8817

QEMU (aka Quick Emulator) built to use 'address_space_translate' to map an address to a MemoryRegionSection is vulnerable to an OOB r/w access issue. It could occur while doing pci_dma_read/write calls. Affects QEMU versions >= 1.6.0 and <= 2.3.1. A privileged user inside guest could use this...

5.5CVSS

6AI Score

0.001EPSS

2016-12-29 10:59 PM
37
cve
cve

CVE-2013-4540

Buffer overflow in scoop_gpio_handler_update in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a large (1) prev_level, (2) gpio_level, or (3) gpio_dir value in a savevm...

8.7AI Score

0.055EPSS

2014-11-04 09:55 PM
39
cve
cve

CVE-2016-2392

The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configuration descriptor objects, which allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors...

6.5CVSS

6.3AI Score

0.001EPSS

2016-06-16 06:59 PM
59
cve
cve

CVE-2015-8744

QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It occurs when a guest sends a Layer-2 packet smaller than 22 bytes. A privileged (CAP_SYS_RAWIO) guest user could use this flaw to crash the QEMU process instance resulting in...

5.5CVSS

6.5AI Score

0.001EPSS

2016-12-29 10:59 PM
55
cve
cve

CVE-2016-9102

Memory leak in the v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) via a large number of Txattrcreate messages with the same fid...

6CVSS

5.9AI Score

0.001EPSS

2016-12-09 10:59 PM
76
4
cve
cve

CVE-2016-7421

The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit process IO loop to the ring...

4.4CVSS

5.9AI Score

0.001EPSS

2016-12-10 12:59 AM
51
4
cve
cve

CVE-2015-8745

QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It could occur while reading Interrupt Mask Registers (IMR). A privileged (CAP_SYS_RAWIO) guest user could use this flaw to crash the QEMU process instance resulting in...

5.5CVSS

6.5AI Score

0.001EPSS

2016-12-29 10:59 PM
51
4
cve
cve

CVE-2014-9718

The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have multiple interpretations of a function's return value, which allows guest OS users to cause a host OS denial of service (memory consumption or infinite loop, and system crash) via a PRDT with zero...

7AI Score

0.001EPSS

2015-04-21 04:59 PM
53
cve
cve

CVE-2014-0222

Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service (crash) via a large L2 table in a QCOW version 1...

6.5AI Score

0.036EPSS

2014-11-04 09:55 PM
57
cve
cve

CVE-2017-5579

Memory leak in the serial_exit_core function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug...

6.5CVSS

6.1AI Score

0.001EPSS

2017-03-15 03:59 PM
89
cve
cve

CVE-2017-5526

Memory leak in hw/audio/es1370.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug...

6.5CVSS

5.8AI Score

0.001EPSS

2017-03-15 03:59 PM
57
cve
cve

CVE-2016-9914

Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in...

6.5CVSS

5.9AI Score

0.001EPSS

2016-12-29 10:59 PM
62
4
cve
cve

CVE-2016-6836

The vmxnet3_complete_packet function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host memory information by leveraging failure to initialize the txcq_descr...

6CVSS

5.9AI Score

0.001EPSS

2016-12-10 12:59 AM
56
4
cve
cve

CVE-2016-6833

Use-after-free vulnerability in the vmxnet3_io_bar0_write function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU instance crash) by leveraging failure to check if the device is...

4.4CVSS

5.9AI Score

0.001EPSS

2016-12-10 12:59 AM
50
4
cve
cve

CVE-2014-0143

Multiple integer overflows in the block drivers in QEMU, possibly before 2.0.0, allow local users to cause a denial of service (crash) via a crafted catalog size in (1) the parallels_open function in block/parallels.c or (2) bochs_open function in bochs.c, a large L1 table in the (3)...

7CVSS

6.3AI Score

0.0004EPSS

2017-08-10 03:29 PM
57
cve
cve

CVE-2015-8666

Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC system...

7.9CVSS

6.7AI Score

0.001EPSS

2017-04-11 07:59 PM
49
4
cve
cve

CVE-2017-5667

The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds heap access and crash) or execute arbitrary code on the QEMU host via vectors involving the data transfer...

6.5CVSS

6.6AI Score

0.001EPSS

2017-03-16 03:59 PM
79
cve
cve

CVE-2017-5525

Memory leak in hw/audio/ac97.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug...

6.5CVSS

5.8AI Score

0.001EPSS

2017-03-15 03:59 PM
74
cve
cve

CVE-2016-9103

The v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host heap memory information by reading xattribute values before writing to...

6CVSS

6AI Score

0.001EPSS

2016-12-09 10:59 PM
70
4
cve
cve

CVE-2016-7908

The mcf_fec_do_tx function in hw/net/mcf_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via vectors involving a buffer...

4.4CVSS

6AI Score

0.001EPSS

2016-10-05 04:59 PM
62
cve
cve

CVE-2016-7116

Directory traversal vulnerability in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to access host files outside the export path via a .. (dot dot) in an unspecified...

6CVSS

6.8AI Score

0.001EPSS

2016-12-10 12:59 AM
57
4
cve
cve

CVE-2016-1981

QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing data via transmit or receive descriptors, provided the initial receive/transmit descriptor head (TDH/RDH) is set outside the allocated descriptor buffer. A.....

5.5CVSS

6.7AI Score

0.001EPSS

2016-12-29 10:59 PM
59
cve
cve

CVE-2015-8558

The ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular isochronous transfer descriptor (iTD)...

5.5CVSS

6.4AI Score

0.001EPSS

2016-05-23 07:59 PM
68
cve
cve

CVE-2014-5388

Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory...

5AI Score

0.001EPSS

2014-11-15 09:59 PM
34
cve
cve

CVE-2014-0223

Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a large image size, which triggers a buffer overflow or out-of-bounds...

7.2AI Score

0.0004EPSS

2014-11-04 09:55 PM
52
cve
cve

CVE-2015-8504

Qemu, when built with VNC display driver support, allows remote attackers to cause a denial of service (arithmetic exception and application crash) via crafted SetPixelFormat messages from a...

6.5CVSS

7.3AI Score

0.008EPSS

2017-04-11 07:59 PM
66
cve
cve

CVE-2017-5856

Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) via MegaRAID Firmware Interface (MFI) commands with the sglist size set to a value over 2...

6.5CVSS

5.9AI Score

0.001EPSS

2017-03-16 03:59 PM
81
cve
cve

CVE-2016-2391

The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors related to multiple...

5CVSS

6AI Score

0.001EPSS

2016-06-16 06:59 PM
56
cve
cve

CVE-2016-9915

Memory leak in hw/9pfs/9p-handle.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in the handle...

6.5CVSS

5.9AI Score

0.001EPSS

2016-12-29 10:59 PM
61
4
cve
cve

CVE-2016-7995

Memory leak in the ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via a large number of crafted buffer page select (PG)...

6CVSS

5.2AI Score

0.001EPSS

2016-12-10 12:59 AM
57
4
cve
cve

CVE-2016-6834

The net_tx_pkt_do_sw_fragmentation function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a zero length for the current fragment...

4.4CVSS

5.9AI Score

0.001EPSS

2016-12-10 12:59 AM
52
4
cve
cve

CVE-2016-2841

The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via crafted values for the PSTART and PSTOP registers, involving ring buffer...

6CVSS

6.8AI Score

0.001EPSS

2016-06-16 06:59 PM
53
cve
cve

CVE-2011-4111

Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR...

7.6AI Score

0.051EPSS

2014-02-26 03:55 PM
27
cve
cve

CVE-2016-9106

Memory leak in the v9fs_write function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) by leveraging failure to free an IO...

6CVSS

5.9AI Score

0.001EPSS

2016-12-09 10:59 PM
66
4
cve
cve

CVE-2014-3689

The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecified parameters related to rectangle...

6.7AI Score

0.001EPSS

2014-11-14 03:59 PM
51
cve
cve

CVE-2016-9105

Memory leak in the v9fs_link function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors involving a reference to the source fid...

6CVSS

5.8AI Score

0.001EPSS

2016-12-09 10:59 PM
80
4
cve
cve

CVE-2019-3812

QEMU, through version 2.10 and through version 3.1.0, is vulnerable to an out-of-bounds read of up to 128 bytes in the hw/i2c/i2c-ddc.c:i2c_ddc() function. A local attacker with permission to execute i2c commands could exploit this to read stack memory of the qemu process on the...

5.5CVSS

5.4AI Score

0.0004EPSS

2019-02-19 02:29 PM
128
Total number of security vulnerabilities411