Skip to main content

Vendor/product archive

spice_project / spice CVEs

Beta · best-effort

15 CVEs tagged to spice_project / spice1 Critical, 9 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2020-14355

Published Oct 7, 2020

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk)…

CVSS 6.6 · Medium

CVE-2019-3813

Published Feb 4, 2019

Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the wors…

CVSS 7.5 · High

CVE-2018-10893

Published Sep 11, 2018

Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, pot…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10873

Published Aug 17, 2018

A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or serve…

CVSS 8.3 · High

CVE-2016-9577

Published Jul 27, 2018

A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap…

CVSS 7.5 · High

CVE-2017-7506

Published Jul 18, 2017

spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2150

Published Jun 9, 2016

SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.

CVSS 7.1 · High

CVE-2016-0749

Published Jun 9, 2016

The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecti…

CVSS 9.8 · Critical

CVE-2015-5261

Published Jun 7, 2016

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creat…

CVSS 7.1 · High

CVE-2015-5260

Published Jun 7, 2016

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrar…

CVSS 7.8 · High

CVE-2013-4130

Published Aug 20, 2013

The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE before 0.12.4 do not properly perform ring loops, which might…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1