Lucene search

K

Qemu Security Vulnerabilities

cve
cve

CVE-2015-8619

The Human Monitor Interface support in QEMU allows remote attackers to cause a denial of service (out-of-bounds write and application...

7.5CVSS

7.7AI Score

0.008EPSS

2017-04-13 05:59 PM
48
cve
cve

CVE-2015-8613

Stack-based buffer overflow in the megasas_ctrl_get_info function in QEMU, when built with SCSI MegaRAID SAS HBA emulation support, allows local guest users to cause a denial of service (QEMU instance crash) via a crafted SCSI controller CTRL_GET_INFO...

6.5CVSS

7.1AI Score

0.001EPSS

2017-04-11 07:59 PM
68
cve
cve

CVE-2015-8568

Memory leak in QEMU, when built with a VMWARE VMXNET3 paravirtual NIC emulator support, allows local guest users to cause a denial of service (host memory consumption) by trying to activate the vmxnet3 device...

6.5CVSS

7AI Score

0.001EPSS

2017-04-11 07:59 PM
65
cve
cve

CVE-2015-8556

Local privilege escalation vulnerability in the Gentoo QEMU package before...

10CVSS

9.1AI Score

0.019EPSS

2017-03-24 02:59 PM
32
cve
cve

CVE-2017-5957

Stack-based buffer overflow in the vrend_decode_set_framebuffer_state function in vrend_decode.c in virglrenderer before 926b9b3460a48f6454d8bbe9e44313d86a65447f, as used in Quick Emulator (QEMU), allows a local guest users to cause a denial of service (application crash) via the "nr_cbufs"...

5.5CVSS

5.8AI Score

0.001EPSS

2017-03-14 02:59 PM
22
2
cve
cve

CVE-2016-9381

Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double fetch"...

7.5CVSS

7.2AI Score

0.001EPSS

2017-01-23 09:59 PM
52
cve
cve

CVE-2016-1922

QEMU (aka Quick Emulator) built with the TPR optimization for 32-bit Windows guests support is vulnerable to a null pointer dereference flaw. It occurs while doing I/O port write operations via hmp interface. In that, 'current_cpu' remains null, which leads to the null pointer dereference. A user.....

5.5CVSS

6.7AI Score

0.001EPSS

2016-12-29 10:59 PM
46
cve
cve

CVE-2016-2198

QEMU (aka Quick Emulator) built with the USB EHCI emulation support is vulnerable to a null pointer dereference flaw. It could occur when an application attempts to write to EHCI capabilities registers. A privileged user inside quest could use this flaw to crash the QEMU process instance resulting....

5.5CVSS

6.5AI Score

0.001EPSS

2016-12-29 10:59 PM
60
4
cve
cve

CVE-2016-9846

QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to a memory leakage issue. It could occur while updating the cursor data in update_cursor_data_virgl. A guest user/process could use this flaw to leak host memory bytes, resulting in DoS for a...

6.5CVSS

6.3AI Score

0.001EPSS

2016-12-29 10:59 PM
39
cve
cve

CVE-2016-9776

QEMU (aka Quick Emulator) built with the ColdFire Fast Ethernet Controller emulator support is vulnerable to an infinite loop issue. It could occur while receiving packets in 'mcf_fec_receive'. A privileged user/process inside guest could use this issue to crash the QEMU process on the host...

5.5CVSS

5.7AI Score

0.001EPSS

2016-12-29 10:59 PM
57
cve
cve

CVE-2015-8743

QEMU (aka Quick Emulator) built with the NE2000 device emulation support is vulnerable to an OOB r/w access issue. It could occur while performing 'ioport' r/w operations. A privileged (CAP_SYS_RAWIO) user/process could use this flaw to leak or corrupt QEMU memory...

7.1CVSS

7.5AI Score

0.001EPSS

2016-12-29 10:59 PM
51
cve
cve

CVE-2016-2197

QEMU (aka Quick Emulator) built with an IDE AHCI emulation support is vulnerable to a null pointer dereference flaw. It occurs while unmapping the Frame Information Structure (FIS) and Command List Block (CLB) entries. A privileged user inside guest could use this flaw to crash the QEMU process...

5.5CVSS

5.9AI Score

0.001EPSS

2016-12-29 10:59 PM
39
cve
cve

CVE-2016-9845

QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET_INFO' command. A guest user/process could use this flaw to leak contents of the host memory...

6.5CVSS

6.2AI Score

0.001EPSS

2016-12-29 10:59 PM
48
cve
cve

CVE-2015-8701

QEMU (aka Quick Emulator) built with the Rocker switch emulation support is vulnerable to an off-by-one error. It happens while processing transmit (tx) descriptors in 'tx_consume' routine, if a descriptor was to have more than allowed (ROCKER_TX_FRAGS_MAX=16) fragments. A privileged user inside...

6.5CVSS

6.4AI Score

0.001EPSS

2016-12-29 10:59 PM
33
cve
cve

CVE-2016-9912

Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to a memory leakage issue. It could occur while destroying gpu resource object in 'virtio_gpu_resource_destroy'. A guest user/process could use this flaw to leak host memory bytes, resulting in DoS for a...

6.5CVSS

6.4AI Score

0.001EPSS

2016-12-23 10:59 PM
50
cve
cve

CVE-2016-9908

Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET' command. A guest user/process could use this flaw to leak contents of the host memory...

3.3CVSS

4.9AI Score

0.001EPSS

2016-12-23 10:59 PM
50
cve
cve

CVE-2016-9923

Quick Emulator (Qemu) built with the 'chardev' backend support is vulnerable to a use after free issue. It could occur while hotplug and unplugging the device in the guest. A guest user/process could use this flaw to crash a Qemu process on the host resulting in...

5.5CVSS

5.7AI Score

0.001EPSS

2016-12-23 10:59 PM
27
cve
cve

CVE-2016-7994

Memory leak in the virtio_gpu_resource_create_2d function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_CREATE_2D...

6CVSS

5.8AI Score

0.001EPSS

2016-12-10 12:59 AM
52
4
cve
cve

CVE-2016-9104

Multiple integer overflows in the (1) v9fs_xattr_read and (2) v9fs_xattr_write functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS administrators to cause a denial of service (QEMU process crash) via a crafted offset, which triggers an out-of-bounds...

4.4CVSS

5.2AI Score

0.001EPSS

2016-12-09 10:59 PM
72
4
cve
cve

CVE-2016-9101

Memory leak in hw/net/eepro100.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by repeatedly unplugging an i8255x (PRO100) NIC...

6CVSS

5.8AI Score

0.001EPSS

2016-12-09 10:59 PM
65
4
cve
cve

CVE-2016-8668

The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging failure to limit DMA buffer...

6CVSS

6AI Score

0.001EPSS

2016-11-04 09:59 PM
50
cve
cve

CVE-2016-8667

The rc4030_write function in hw/dma/rc4030.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via a large interval timer reload...

6CVSS

5.9AI Score

0.001EPSS

2016-11-04 09:59 PM
69
cve
cve

CVE-2016-8578

The v9fs_iov_vunmarshal function in fsdev/9p-iov-marshal.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) by sending an empty string parameter to a 9P...

6CVSS

5.9AI Score

0.001EPSS

2016-11-04 09:59 PM
61
cve
cve

CVE-2016-7909

The pcnet_rdra_addr function in hw/net/pcnet.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by setting the (1) receive or (2) transmit descriptor ring length to...

4.4CVSS

5.3AI Score

0.001EPSS

2016-10-05 04:59 PM
64
cve
cve

CVE-2016-7907

The imx_fec_do_tx function in hw/net/imx_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via vectors involving a buffer...

4.4CVSS

5.3AI Score

0.001EPSS

2016-10-05 04:59 PM
52
cve
cve

CVE-2016-5107

The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds read and crash) via unspecified...

6CVSS

6.8AI Score

0.001EPSS

2016-09-02 02:59 PM
44
cve
cve

CVE-2016-5106

The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest administrators to cause a denial of service (out-of-bounds write access) via vectors involving a MegaRAID Firmware Interface (MFI)...

6CVSS

6.4AI Score

0.001EPSS

2016-09-02 02:59 PM
50
cve
cve

CVE-2016-5105

The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involving a MegaRAID Firmware Interface (MFI)...

4.4CVSS

5.4AI Score

0.001EPSS

2016-09-02 02:59 PM
56
cve
cve

CVE-2016-4952

QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds array access) via vectors related to the (1) PVSCSI_CMD_SETUP_RINGS or (2) PVSCSI_CMD_SETUP_MSG_RING SCSI...

6CVSS

6.7AI Score

0.001EPSS

2016-09-02 02:59 PM
48
cve
cve

CVE-2016-5403

The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for...

5.5CVSS

5.9AI Score

0.001EPSS

2016-08-02 04:59 PM
136
cve
cve

CVE-2016-5238

The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to reading from the information transfer buffer in non-DMA...

4.4CVSS

6.1AI Score

0.001EPSS

2016-06-14 02:59 PM
41
cve
cve

CVE-2016-4454

The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to obtain sensitive host memory information or cause a denial of service (QEMU process crash) by changing FIFO registers and issuing a VGA command, which triggers an out-of-bounds...

6CVSS

6.8AI Score

0.001EPSS

2016-06-01 10:59 PM
49
cve
cve

CVE-2016-4453

The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a VGA...

4.4CVSS

5.8AI Score

0.001EPSS

2016-06-01 10:59 PM
58
cve
cve

CVE-2016-4441

The get_cmd function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check DMA length, which allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via unspecified vectors, involving an SCSI...

6CVSS

6AI Score

0.001EPSS

2016-05-20 02:59 PM
44
cve
cve

CVE-2016-4439

The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check command buffer length, which allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or potentially execute arbitrary...

6.7CVSS

7.4AI Score

0.001EPSS

2016-05-20 02:59 PM
45
cve
cve

CVE-2016-3710

The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal"...

8.8CVSS

8.7AI Score

0.002EPSS

2016-05-11 09:59 PM
82
4
cve
cve

CVE-2016-4002

Buffer overflow in the mipsnet_receive function in hw/net/mipsnet.c in QEMU, when the guest NIC is configured to accept large packets, allows remote attackers to cause a denial of service (memory corruption and QEMU crash) or possibly execute arbitrary code via a packet larger than 1514...

9.8CVSS

9.5AI Score

0.049EPSS

2016-04-26 02:59 PM
54
cve
cve

CVE-2015-5158

Stack-based buffer overflow in hw/scsi/scsi-bus.c in QEMU, when built with SCSI-device emulation support, allows guest OS users with CAP_SYS_RAWIO permissions to cause a denial of service (instance crash) via an invalid opcode in a SCSI command descriptor...

5.5CVSS

5.7AI Score

0.001EPSS

2016-04-12 01:59 AM
34
cve
cve

CVE-2015-7295

hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable receive buffers are not supported, allows remote attackers to cause a denial of service (guest network consumption) via a flood of jumbo frames on the (1) tuntap or (2) macvtap...

7.2AI Score

0.076EPSS

2015-11-09 04:59 PM
54
cve
cve

CVE-2015-6855

hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a.....

7.5CVSS

7.4AI Score

0.011EPSS

2015-11-06 09:59 PM
69
cve
cve

CVE-2015-4037

The slirp_smb function in net/slirp.c in QEMU 2.3.0 and earlier creates temporary files with predictable names, which allows local users to cause a denial of service (instantiation failure) by creating /tmp/qemu-smb.- files before the...

5.9AI Score

0.0004EPSS

2015-08-26 07:59 PM
64
cve
cve

CVE-2015-4106

QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact via unknown...

7.6AI Score

0.001EPSS

2015-06-03 08:59 PM
57
cve
cve

CVE-2014-0150

Integer overflow in the virtio_net_handle_mac function in hw/net/virtio-net.c in QEMU 2.0 and earlier allows local guest users to execute arbitrary code via a MAC addresses table update request, which triggers a heap-based buffer...

7.3AI Score

0.001EPSS

2014-04-18 02:55 PM
56
cve
cve

CVE-2013-4375

The qdisk PV disk backend in qemu-xen in Xen 4.2.x and 4.3.x before 4.3.1, and qemu 1.1 and other versions, allows local HVM guests to cause a denial of service (domain grant reference consumption) via unspecified...

6AI Score

0.001EPSS

2014-01-19 06:55 PM
35
cve
cve

CVE-2013-4377

Use-after-free vulnerability in the virtio-pci implementation in Qemu 1.4.0 through 1.6.0 allows local users to cause a denial of service (daemon crash) by "hot-unplugging" a virtio...

7.6AI Score

0.0004EPSS

2013-10-11 10:55 PM
46
cve
cve

CVE-2013-4344

Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS...

8.3AI Score

0.0004EPSS

2013-10-04 05:55 PM
61
cve
cve

CVE-2011-2527

The change_process_uid function in os-posix.c in Qemu 0.14.0 and earlier does not properly drop group privileges when the -runas option is used, which allows local guest users to access restricted files on the...

6AI Score

0.001EPSS

2012-06-21 03:55 PM
39
cve
cve

CVE-2011-0011

qemu-kvm before 0.11.0 disables VNC authentication when the password is cleared, which allows remote attackers to bypass authentication and establish VNC...

6.9AI Score

0.012EPSS

2012-06-21 03:55 PM
41
4
cve
cve

CVE-2008-5714

Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote attackers to guess the VNC password, which is limited to seven characters where eight was...

7.4AI Score

0.007EPSS

2008-12-24 06:29 PM
39
cve
cve

CVE-2008-2382

The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote attackers to cause a denial of service (infinite loop) via a certain...

7.2AI Score

0.085EPSS

2008-12-24 06:29 PM
47
Total number of security vulnerabilities411