Vulnerability index

Browse CVEs

113 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2019-12928EPSS 23% The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote attacker to achieve code exe… Qemu after 4.0.0 Fix from $2,3002019-06-24 CRITICAL 9.8 CVE-2019-12929 The QMP guest_exec command in QEMU 4.0.0 and earlier is prone to OS command injection, which allows the attacker to achieve code execution, denial of… Qemu after 4.0.0 Fix from $2,3002019-06-24 MEDIUM 5.5 CVE-2019-9824 tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure. Qemu Patch available Fix from $1,6002019-06-03 CRITICAL 9.8 CVE-2018-20815 In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated load_image function, which has a buffer overflow risk. Qemu Mitigation only Fix from $2,3002019-05-31 HIGH 7.5 CVE-2019-12155EPSS 6% interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference. Qemu Patch available Fix from $1,9502019-05-24 HIGH 7.5 CVE-2019-12247 QEMU 3.0.0 has an Integer Overflow because the qga/commands*.c files do not check the length of the argument list or the number of environment variab… Qemu Patch available Fix from $1,9502019-05-22 HIGH 7.5 CVE-2019-5008 hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, which allows the attacker to cause a denial of service via a device dr… Qemu Patch available Fix from $1,9502019-04-19 MEDIUM 5.7 CVE-2018-19665 The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption. Qemu after 3.0.1 Fix from $1,6002018-12-06 MEDIUM 5.5 CVE-2018-15746 qemu-seccomp.c in QEMU might allow local OS guest users to cause a denial of service (guest crash) by leveraging mishandling of the seccomp policy fo… Qemu after 3.0.1 Fix from $1,6002018-08-29 HIGH 8.8 CVE-2017-2630 A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2.9 built with the Network Block Device (NBD) client support. The flaw cou… Qemu 2.9+ Fix from $1,9502018-07-27 CRITICAL 9.0 CVE-2017-7471 Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System (9pfs) support, is vulnerable to an improper access contro… Qemu after 2.8.1.1 Fix from $2,3002018-07-09 MEDIUM 5.5 CVE-2014-3471 Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU instance cr… Qemu after 2.1.2 Fix from $1,6002018-01-12 HIGH 7.5 CVE-2017-15124 VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to be vulnerable to an unbounded memory allocation issue, as it did not… Qemu after 2.11.0 Fix from $1,9502018-01-09 MEDIUM 6.0 CVE-2015-7549 The MSI-X MMIO support in hw/pci/msix.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (NULL pointe… Qemu 2.5.0+ Fix from $1,6002017-10-30 MEDIUM 6.0 CVE-2017-15289 The mode4and5 write functions in hw/display/cirrus_vga.c in Qemu allow local OS guest privileged users to cause a denial of service (out-of-bounds wr… Qemu after 2.10.2 Fix from $1,6002017-10-16 HIGH 7.5 CVE-2017-15268 Qemu through 2.10.0 allows remote attackers to cause a memory leak by triggering slow data-channel read operations, related to io/channel-websock.c. Qemu after 2.10.0 Fix from $1,9502017-10-12 MEDIUM 5.6 CVE-2017-15038 Race condition in the v9fs_xattrwalk function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS users to obtain sensitive informatio… Qemu after 2.9.1 Fix from $1,6002017-10-10 MEDIUM 6.5 CVE-2017-13673 The vga display update in mis-calculated the region for the dirty bitmap snapshot in case split screen mode is used causing a denial of service (asse… Qemu Patch available Fix from $1,6002017-08-29 CRITICAL 9.8 CVE-2017-8380 Buffer overflow in the "megasas_mmio_write" function in Qemu 2.9.0 allows remote attackers to have unspecified impact via unknown vectors. Qemu Patch available Fix from $2,3002017-08-28 HIGH 7.8 CVE-2014-0145 Multiple buffer overflows in QEMU before 1.7.2 and 2.x before 2.0.0, allow local users to cause a denial of service (crash) or possibly execute arbit… Qemu after 1.7.1 Fix from $1,9502017-08-10 MEDIUM 5.5 CVE-2014-0142 QEMU, possibly before 2.0.0, allows local users to cause a denial of service (divide-by-zero error and crash) via a zero value in the (1) tracks fiel… Qemu after 2.0.0 Fix from $1,6002017-08-10 MEDIUM 5.5 CVE-2014-0146 The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x before 2.0.0 allows local users to cause a denial of service (NULL pointe… Qemu after 1.7.1 Fix from $1,6002017-08-10 MEDIUM 5.5 CVE-2017-9374 Memory leak in QEMU (aka Quick Emulator), when built with USB EHCI Emulation support, allows local guest OS privileged users to cause a denial of ser… Qemu after 2.8.1.1 Fix from $1,6002017-06-16 MEDIUM 5.5 CVE-2017-9060 Memory leak in the virtio_gpu_set_scanout function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a den… Qemu after 2.8.1.1 Fix from $1,6002017-06-01 HIGH 7.0 CVE-2017-8284 The disas_insn function in target/i386/translate.c in QEMU before 2.9.0, when TCG mode without hardware acceleration is used, does not limit the inst… Qemu after 2.8.1.1 Fix from $1,9502017-04-26 HIGH 8.8 CVE-2017-5931 Integer overflow in hw/virtio/virtio-crypto.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (QEMU … Qemu after 2.8.1.1 Fix from $1,9502017-03-27 MEDIUM 5.5 CVE-2016-9922 The cirrus_do_copy function in hw/display/cirrus_vga.c in QEMU (aka Quick Emulator), when cirrus graphics mode is VGA, allows local guest OS privileg… Qemu after 2.7.1 Fix from $1,6002017-03-27 CRITICAL 10.0 CVE-2015-8556EPSS 13% Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1. Qemu after 2.4.1 Fix from $2,3002017-03-24 HIGH 7.5 CVE-2017-6058 Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 devic… Qemu after 2.8.1.1 Fix from $1,9502017-03-20 MEDIUM 6.5 CVE-2017-5857 Memory leak in the virgl_cmd_resource_unref function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS users to cause … Qemu after 2.8.1.1 Fix from $1,6002017-03-16