Vulnerability index

Browse CVEs

113 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Qemu HIGH 7.5
CVE-2013-4526

Buffer overflow in hw/ide/ahci.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via ve…

Fix: after 1.7.1
Fix from $1,950 2014-11-04
Qemu HIGH 7.5
CVE-2013-4527EPSS 5%

Buffer overflow in hw/timer/hpet.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via vectors related to the number of t…

Fix: after 1.7.1
Fix from $1,950 2014-11-04
Qemu HIGH 7.5
CVE-2013-4529

Buffer overflow in hw/pci/pcie_aer.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code vi…

Fix: after 1.7.1
Fix from $1,950 2014-11-04
Qemu HIGH 7.5
CVE-2013-4530EPSS 5%

Buffer overflow in hw/ssi/pl022.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via cr…

Fix: after 1.7.1
Fix from $1,950 2014-11-04
Qemu HIGH 7.5
CVE-2013-4531

Buffer overflow in target-arm/machine.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code…

Fix: after 1.7.1
Fix from $1,950 2014-11-04
Qemu HIGH 7.5
CVE-2013-4533

Buffer overflow in the pxa2xx_ssp_load function in hw/arm/pxa2xx.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possi…

Fix: after 1.7.1
Fix from $1,950 2014-11-04
Qemu HIGH 7.5
CVE-2013-4534

Buffer overflow in hw/intc/openpic.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via…

Fix: after 1.7.1
Fix from $1,950 2014-11-04
Qemu HIGH 7.5
CVE-2013-4537

The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a…

Fix: after 1.7.1
Fix from $1,950 2014-11-04
Qemu HIGH 7.5
CVE-2013-4538

Multiple buffer overflows in the ssd0323_load function in hw/display/ssd0323.c in QEMU before 1.7.2 allow remote attackers to cause a denial of servi…

Fix: after 1.7.1
Fix from $1,950 2014-11-04
Qemu HIGH 7.5
CVE-2013-4539

Multiple buffer overflows in the tsc210x_load function in hw/input/tsc210x.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary c…

Fix: after 1.7.1
Fix from $1,950 2014-11-04
Qemu HIGH 7.5
CVE-2013-4540

Buffer overflow in scoop_gpio_handler_update in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a large (1) prev_level, …

Fix: after 1.7.1
Fix from $1,950 2014-11-04
Qemu HIGH 7.5
CVE-2013-4541

The usb_device_post_load function in hw/usb/bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm im…

Fix: after 1.7.1
Fix from $1,950 2014-11-04
Qemu MEDIUM 6.8
CVE-2014-5263

vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the list with the VMSTATE_END_OF_LIST macro, which allows attackers to cause…

Patch available
Fix from $1,600 2014-08-26
Qemu HIGH 7.2
CVE-2014-2894

Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact v…

Fix: after 1.7.1
Fix from $1,950 2014-04-23
Qemu MEDIUM 6.9
CVE-2013-2007

The qemu guest agent in Qemu 1.4.1 and earlier, as used by Xen, when started in daemon mode, uses weak permissions for certain files, which allows lo…

Mitigation only
Fix from $1,600 2013-05-21
Qemu HIGH 7.4
CVE-2011-1751

The pciej_write function in hw/acpi_piix4.c in the PIIX4 Power Management emulation in qemu-kvm does not check if a device is hotpluggable before unp…

Mitigation only
Fix from $1,950 2012-06-21
Qemu HIGH 7.4
CVE-2011-2212

Buffer overflow in the virtio subsystem in qemu-kvm 0.14.0 and earlier allows privileged guest users to cause a denial of service (guest crash) or ga…

Fix: after 0.14.0
Fix from $1,950 2012-06-21
Qemu HIGH 7.4
CVE-2011-1750

Multiple heap-based buffer overflows in the virtio-blk driver (hw/virtio-blk.c) in qemu-kvm 0.14.0 allow local guest users to cause a denial of servi…

Mitigation only
Fix from $1,950 2012-06-21
Qemu HIGH 7.2
CVE-2010-0297

Buffer overflow in the usb_host_handle_control function in the USB passthrough handling implementation in usb-linux.c in QEMU before 0.11.1 allows gu…

Fix: after 0.11.0
Fix from $1,950 2010-02-12
Qemu HIGH 7.8
CVE-2008-5714

Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote attackers to guess the VNC password, which is limited to seven characters…

Mitigation only
Fix from $1,950 2008-12-24
Qemu MEDIUM 5.0
CVE-2008-2382EPSS 7%

The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote attackers to c…

Fix: after 79
Fix from $1,600 2008-12-24
Qemu HIGH 7.2
CVE-2008-4553

qemu-make-debian-root in qemu 0.9.1-5 on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on temporary files and…

No fix yet
Fix from $1,950 2008-10-15
Qemu HIGH 7.2
CVE-2007-6227

QEMU 0.9.0 allows local users of a Windows XP SP2 guest operating system to overwrite the TranslationBlock (code_gen_buffer) buffer, and probably hav…

Mitigation only
Fix from $1,950 2007-12-04