VYPR

rpm package

suse/qemu&distro=SUSE Linux Enterprise Server 12-LTSS

pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSS

Vulnerabilities (98)

  • CVE-2016-8577MedNov 4, 2016
    affected < 2.0.2-48.25.1fixed 2.0.2-48.25.1

    Memory leak in the v9fs_read function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors related to an I/O read operation.

  • CVE-2016-8576MedNov 4, 2016
    affected < 2.0.2-48.25.1fixed 2.0.2-48.25.1

    The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit the number of link Transfer Request Blocks (TRB) to process.

  • CVE-2016-7909MedOct 5, 2016
    affected < 2.0.2-48.25.1fixed 2.0.2-48.25.1

    The pcnet_rdra_addr function in hw/net/pcnet.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by setting the (1) receive or (2) transmit descriptor ring length to 0.

  • CVE-2016-7908MedOct 5, 2016
    affected < 2.0.2-48.25.1fixed 2.0.2-48.25.1

    The mcf_fec_do_tx function in hw/net/mcf_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via vectors in

  • CVE-2016-7161CriOct 5, 2016
    affected < 2.0.2-48.25.1fixed 2.0.2-48.25.1

    Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code on the QEMU host via a large ethlite packet.

  • CVE-2016-5107MedSep 2, 2016
    affected < 2.0.2-48.22.1fixed 2.0.2-48.22.1

    The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds read and crash) via unspecified vectors.

  • CVE-2016-5106MedSep 2, 2016
    affected < 2.0.2-48.22.1fixed 2.0.2-48.22.1

    The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest administrators to cause a denial of service (out-of-bounds write access) via vectors involving a MegaRAID Firmware In

  • CVE-2016-5105MedSep 2, 2016
    affected < 2.0.2-48.22.1fixed 2.0.2-48.22.1

    The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involving a MegaRAID Firmware Interfac

  • CVE-2016-5403MedAug 2, 2016
    affected < 2.0.2-48.22.1fixed 2.0.2-48.22.1

    The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.

  • CVE-2016-2392MedJun 16, 2016
    affected < 2.0.2-48.22.1fixed 2.0.2-48.22.1

    The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configuration descriptor objects, which allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process cra

  • CVE-2016-2391MedJun 16, 2016
    affected < 2.0.2-48.22.1fixed 2.0.2-48.22.1

    The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors related to multiple eof_timers.

  • CVE-2016-5338HigJun 14, 2016
    affected < 2.0.2-48.22.1fixed 2.0.2-48.22.1

    The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allow local guest OS administrators to cause a denial of service (QEMU process crash) or execute arbitrary code on the QEMU host via vectors related to the information transfer buffer.

  • CVE-2016-5337MedJun 14, 2016
    affected < 2.0.2-48.22.1fixed 2.0.2-48.22.1

    The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory information via vectors related to reading device control information.

  • CVE-2016-5238MedJun 14, 2016
    affected < 2.0.2-48.22.1fixed 2.0.2-48.22.1

    The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to reading from the information transfer buffer in non-DMA mode.

  • CVE-2016-5126HigJun 1, 2016
    affected < 2.0.2-48.22.1fixed 2.0.2-48.22.1

    Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code via a crafted iSCSI asynchronous I/O ioctl call.

  • CVE-2016-4454MedJun 1, 2016
    affected < 2.0.2-48.22.1fixed 2.0.2-48.22.1

    The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to obtain sensitive host memory information or cause a denial of service (QEMU process crash) by changing FIFO registers and issuing a VGA command, which triggers an out-of-b

  • CVE-2016-4453MedJun 1, 2016
    affected < 2.0.2-48.22.1fixed 2.0.2-48.22.1

    The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a VGA command.

  • CVE-2014-5388Nov 15, 2014
    affected < 2.0.2-48.22.1fixed 2.0.2-48.22.1

    Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corruption.

Page 5 of 5