Skip to main content

Vendor archive

qemu CVEs

Beta · best-effort

421 CVEs tagged to vendor qemu14 Critical, 122 High, 248 Medium, 37 Low, 0 Unrated.

CVE-2017-7718

Published Apr 20, 2017

hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vector…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8619

Published Apr 13, 2017

The Human Monitor Interface support in QEMU allows remote attackers to cause a denial of service (out-of-bounds write and application crash).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8345

Published Apr 13, 2017

The eepro100 emulator in QEMU qemu-kvm blank allows local guest users to cause a denial of service (application crash and infinite loop) via vectors involving the command block li…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8613

Published Apr 11, 2017

Stack-based buffer overflow in the megasas_ctrl_get_info function in QEMU, when built with SCSI MegaRAID SAS HBA emulation support, allows local guest users to cause a denial of s…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8568

Published Apr 11, 2017

Memory leak in QEMU, when built with a VMWARE VMXNET3 paravirtual NIC emulator support, allows local guest users to cause a denial of service (host memory consumption) by trying t…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8504

Published Apr 11, 2017

Qemu, when built with VNC display driver support, allows remote attackers to cause a denial of service (arithmetic exception and application crash) via crafted SetPixelFormat mess…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7377

Published Apr 10, 2017

The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a denial of service (file descriptor…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5931

Published Mar 27, 2017

Integer overflow in hw/virtio/virtio-crypto.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (QEMU process crash) or possibly exe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9922

Published Mar 27, 2017

The cirrus_do_copy function in hw/display/cirrus_vga.c in QEMU (aka Quick Emulator), when cirrus graphics mode is VGA, allows local guest OS privileged users to cause a denial of…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8556

Published Mar 24, 2017

Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-6058

Published Mar 20, 2017

Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 device, allows remote attackers to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5987

Published Mar 20, 2017

The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local OS guest privileged users to cause a denial of service (infinite loop and…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5857

Published Mar 16, 2017

Memory leak in the virgl_cmd_resource_unref function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5856

Published Mar 16, 2017

Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5667

Published Mar 16, 2017

The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds heap…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5579

Published Mar 15, 2017

Memory leak in the serial_exit_core function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory cons…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5578

Published Mar 15, 2017

Memory leak in the virtio_gpu_resource_attach_backing function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (ho…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5552

Published Mar 15, 2017

Memory leak in the virgl_resource_attach_backing function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5526

Published Mar 15, 2017

Memory leak in hw/audio/es1370.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash)…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5525

Published Mar 15, 2017

Memory leak in hw/audio/ac97.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) vi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10155

Published Mar 15, 2017

Memory leak in hw/watchdog/wdt_i6300esb.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU proces…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 226-250 of 421 CVEsPage 10 of 17