Vulnerability index

Browse CVEs

113 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Qemu MEDIUM 5.5
CVE-2017-5898

Integer overflow in the emulated_apdu_from_guest function in usb/dev-smartcard-reader.c in Quick Emulator (Qemu), when built with the CCID Card devic…

Fix: after 2.8.1.1
Fix from $1,600 2017-03-15
Qemu MEDIUM 6.5
CVE-2017-5552

Memory leak in the virgl_resource_attach_backing function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS users to c…

Fix: after 2.8.1.1
Fix from $1,600 2017-03-15
Qemu MEDIUM 6.5
CVE-2017-5578

Memory leak in the virtio_gpu_resource_attach_backing function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS users to…

Fix: after 2.8.1.1
Fix from $1,600 2017-03-15
Qemu MEDIUM 6.5
CVE-2017-6505

The ohci_service_ed_list function in hw/usb/hcd-ohci.c in QEMU (aka Quick Emulator) before 2.9.0 allows local guest OS users to cause a denial of ser…

Fix: after 2.8.1.1
Fix from $1,600 2017-03-15
Qemu MEDIUM 5.5
CVE-2016-10028

The virgl_cmd_get_capset function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) built with Virtio GPU Device emulator support allows loc…

Fix: after 2.8.1.1
Fix from $1,600 2017-02-27
Qemu MEDIUM 5.5
CVE-2016-10029

The virtio_gpu_set_scanout function in QEMU (aka Quick Emulator) built with Virtio GPU Device emulator support allows local guest OS users to cause a…

Fix: after 2.6.2
Fix from $1,600 2017-02-27
Qemu MEDIUM 6.5
CVE-2015-8701

QEMU (aka Quick Emulator) built with the Rocker switch emulation support is vulnerable to an off-by-one error. It happens while processing transmit (…

Fix: after 2.5.1.1
Fix from $1,600 2016-12-29
Qemu MEDIUM 6.5
CVE-2016-9845

QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while proce…

Fix: 2.8.0+
Fix from $1,600 2016-12-29
Qemu MEDIUM 6.5
CVE-2016-9846

QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to a memory leakage issue. It could occur while updating th…

Fix: after 2.7.1
Fix from $1,600 2016-12-29
Qemu MEDIUM 6.5
CVE-2016-9913

Memory leak in the v9fs_device_unrealize_common function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause…

Fix: after 2.7.1
Fix from $1,600 2016-12-29
Qemu MEDIUM 5.5
CVE-2015-8817

QEMU (aka Quick Emulator) built to use 'address_space_translate' to map an address to a MemoryRegionSection is vulnerable to an OOB r/w access issue.…

Patch available
Fix from $1,600 2016-12-29
Qemu MEDIUM 5.5
CVE-2015-8818

The cpu_physical_memory_write_rom_internal function in exec.c in QEMU (aka Quick Emulator) does not properly skip MMIO regions, which allows local pr…

Fix: after 2.3.1
Fix from $1,600 2016-12-29
Qemu MEDIUM 5.5
CVE-2016-2197

QEMU (aka Quick Emulator) built with an IDE AHCI emulation support is vulnerable to a null pointer dereference flaw. It occurs while unmapping the Fr…

Fix: after 2.5.1.1
Fix from $1,600 2016-12-29
Qemu MEDIUM 6.5
CVE-2016-9912

Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to a memory leakage issue. It could occur while destroying gpu …

Fix: after 2.8.1.1
Fix from $1,600 2016-12-23
Qemu MEDIUM 5.5
CVE-2016-9923

Quick Emulator (Qemu) built with the 'chardev' backend support is vulnerable to a use after free issue. It could occur while hotplug and unplugging t…

Fix: after 2.7.1
Fix from $1,600 2016-12-23
Qemu MEDIUM 6.0
CVE-2016-7995

Memory leak in the ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial…

Fix: after 2.7.1
Fix from $1,600 2016-12-10
Qemu MEDIUM 6.0
CVE-2016-7994

Memory leak in the virtio_gpu_resource_create_2d function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS administrator…

Fix: after 2.7.1
Fix from $1,600 2016-12-10
Qemu MEDIUM 6.0
CVE-2016-4964

The mptsas_fetch_requests function in hw/scsi/mptsas.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service…

Fix: after 2.6.2
Fix from $1,600 2016-12-10
Qemu MEDIUM 6.0
CVE-2016-8668

The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of servic…

Fix: after 2.7.1
Fix from $1,600 2016-11-04
Qemu HIGH 7.1
CVE-2016-2538

Multiple integer overflows in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 allow local guest OS administrators to cause a …

Fix: after 2.5.0
Fix from $1,950 2016-06-16
Qemu MEDIUM 5.5
CVE-2015-5158

Stack-based buffer overflow in hw/scsi/scsi-bus.c in QEMU, when built with SCSI-device emulation support, allows guest OS users with CAP_SYS_RAWIO pe…

Fix: 2.4.0+
Fix from $1,600 2016-04-12
Qemu HIGH 7.2
CVE-2015-5279

Heap-based buffer overflow in the ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows guest OS users to cause a denial of servic…

Fix: after 2.4.0
Fix from $1,950 2015-09-28
Qemu HIGH 7.5
CVE-2013-4542

The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted…

Fix: after 1.7.1
Fix from $1,950 2014-11-04
Qemu HIGH 7.5
CVE-2013-6399

Array index error in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a craf…

Fix: after 1.7.1
Fix from $1,950 2014-11-04
Qemu HIGH 7.5
CVE-2014-0182EPSS 5%

Heap-based buffer overflow in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary c…

Fix: after 1.7.1
Fix from $1,950 2014-11-04
Qemu MEDIUM 6.8
CVE-2014-3461

hw/usb/bus.c in QEMU 1.6.2 allows remote attackers to execute arbitrary code via crafted savevm data, which triggers a heap-based buffer overflow, re…

Mitigation only
Fix from $1,600 2014-11-04
Qemu HIGH 7.5
CVE-2013-4148

Integer signedness error in the virtio_net_load function in hw/net/virtio-net.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary…

Patch available
Fix from $1,950 2014-11-04
Qemu HIGH 7.5
CVE-2013-4149EPSS 5%

Buffer overflow in virtio_net_load function in net/virtio-net.c in QEMU 1.3.0 through 1.7.x before 1.7.2 might allow remote attackers to execute arbi…

Patch available
Fix from $1,950 2014-11-04
Qemu HIGH 7.5
CVE-2013-4150

The virtio_net_load function in hw/net/virtio-net.c in QEMU 1.5.0 through 1.7.x before 1.7.2 allows remote attackers to cause a denial of service or …

Patch available
Fix from $1,950 2014-11-04
Qemu HIGH 7.5
CVE-2013-4151EPSS 5%

The virtio_load function in virtio/virtio.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, wh…

Patch available
Fix from $1,950 2014-11-04