rpm package
suse/xen&distro=SUSE Linux Enterprise Server 11 SP3-LTSS
pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSS
Vulnerabilities (136)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2015-6855 | Hig | 7.5 | < 4.2.5_20-24.9 | 4.2.5_20-24.9 | Nov 6, 2015 | hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, | |
| CVE-2014-9718 | — | < 4.2.5_20-24.9 | 4.2.5_20-24.9 | Apr 21, 2015 | The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have multiple interpretations of a function's return value, which allows guest OS users to cause a host OS denial of service (memory consumption or infinite loop, and system crash) via a | ||
| CVE-2014-8106 | — | < 4.2.5_21-35.1 | 4.2.5_21-35.1 | Dec 8, 2014 | Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest users to execute arbitrary code via vectors related to blit regions. NOTE: this vulnerability exists because an incomplete fix for CVE-2007-1320. | ||
| CVE-2014-7815 | — | < 4.2.5_20-24.9 | 4.2.5_20-24.9 | Nov 14, 2014 | The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value. | ||
| CVE-2014-3689 | — | < 4.2.5_20-24.9 | 4.2.5_20-24.9 | Nov 14, 2014 | The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecified parameters related to rectangle handling. | ||
| CVE-2014-3640 | — | < 4.2.5_20-24.9 | 4.2.5_20-24.9 | Nov 7, 2014 | The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized socket. | ||
| CVE-2014-0222 | — | < 4.2.5_20-24.9 | 4.2.5_20-24.9 | Nov 4, 2014 | Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service (crash) via a large L2 table in a QCOW version 1 image. | ||
| CVE-2013-4539 | — | < 4.2.5_20-24.9 | 4.2.5_20-24.9 | Nov 4, 2014 | Multiple buffer overflows in the tsc210x_load function in hw/input/tsc210x.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted (1) precision, (2) nextprecision, (3) function, or (4) nextfunction value in a savevm image. | ||
| CVE-2013-4538 | — | < 4.2.5_20-24.9 | 4.2.5_20-24.9 | Nov 4, 2014 | Multiple buffer overflows in the ssd0323_load function in hw/display/ssd0323.c in QEMU before 1.7.2 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted (1) cmd_len, (2) row, or (3) col values; (4) row_start and ro | ||
| CVE-2013-4537 | — | < 4.2.5_20-24.9 | 4.2.5_20-24.9 | Nov 4, 2014 | The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a savevm image. | ||
| CVE-2013-4534 | — | < 4.2.5_20-24.9 | 4.2.5_20-24.9 | Nov 4, 2014 | Buffer overflow in hw/intc/openpic.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via vectors related to IRQDest elements. | ||
| CVE-2013-4533 | — | < 4.2.5_20-24.9 | 4.2.5_20-24.9 | Nov 4, 2014 | Buffer overflow in the pxa2xx_ssp_load function in hw/arm/pxa2xx.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted s->rx_level value in a savevm image. | ||
| CVE-2013-4530 | — | < 4.2.5_20-24.9 | 4.2.5_20-24.9 | Nov 4, 2014 | Buffer overflow in hw/ssi/pl022.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted tx_fifo_head and rx_fifo_head values in a savevm image. | ||
| CVE-2013-4529 | — | < 4.2.5_20-24.9 | 4.2.5_20-24.9 | Nov 4, 2014 | Buffer overflow in hw/pci/pcie_aer.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large log_num value in a savevm image. | ||
| CVE-2013-4527 | — | < 4.2.5_20-24.9 | 4.2.5_20-24.9 | Nov 4, 2014 | Buffer overflow in hw/timer/hpet.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via vectors related to the number of timers. | ||
| CVE-2014-3615 | — | < 4.2.5_21-27.1 | 4.2.5_21-27.1 | Nov 1, 2014 | The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution. |
- affected < 4.2.5_20-24.9fixed 4.2.5_20-24.9
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive,
- CVE-2014-9718Apr 21, 2015affected < 4.2.5_20-24.9fixed 4.2.5_20-24.9
The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have multiple interpretations of a function's return value, which allows guest OS users to cause a host OS denial of service (memory consumption or infinite loop, and system crash) via a
- CVE-2014-8106Dec 8, 2014affected < 4.2.5_21-35.1fixed 4.2.5_21-35.1
Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest users to execute arbitrary code via vectors related to blit regions. NOTE: this vulnerability exists because an incomplete fix for CVE-2007-1320.
- CVE-2014-7815Nov 14, 2014affected < 4.2.5_20-24.9fixed 4.2.5_20-24.9
The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value.
- CVE-2014-3689Nov 14, 2014affected < 4.2.5_20-24.9fixed 4.2.5_20-24.9
The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecified parameters related to rectangle handling.
- CVE-2014-3640Nov 7, 2014affected < 4.2.5_20-24.9fixed 4.2.5_20-24.9
The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized socket.
- CVE-2014-0222Nov 4, 2014affected < 4.2.5_20-24.9fixed 4.2.5_20-24.9
Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service (crash) via a large L2 table in a QCOW version 1 image.
- CVE-2013-4539Nov 4, 2014affected < 4.2.5_20-24.9fixed 4.2.5_20-24.9
Multiple buffer overflows in the tsc210x_load function in hw/input/tsc210x.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted (1) precision, (2) nextprecision, (3) function, or (4) nextfunction value in a savevm image.
- CVE-2013-4538Nov 4, 2014affected < 4.2.5_20-24.9fixed 4.2.5_20-24.9
Multiple buffer overflows in the ssd0323_load function in hw/display/ssd0323.c in QEMU before 1.7.2 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted (1) cmd_len, (2) row, or (3) col values; (4) row_start and ro
- CVE-2013-4537Nov 4, 2014affected < 4.2.5_20-24.9fixed 4.2.5_20-24.9
The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a savevm image.
- CVE-2013-4534Nov 4, 2014affected < 4.2.5_20-24.9fixed 4.2.5_20-24.9
Buffer overflow in hw/intc/openpic.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via vectors related to IRQDest elements.
- CVE-2013-4533Nov 4, 2014affected < 4.2.5_20-24.9fixed 4.2.5_20-24.9
Buffer overflow in the pxa2xx_ssp_load function in hw/arm/pxa2xx.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted s->rx_level value in a savevm image.
- CVE-2013-4530Nov 4, 2014affected < 4.2.5_20-24.9fixed 4.2.5_20-24.9
Buffer overflow in hw/ssi/pl022.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted tx_fifo_head and rx_fifo_head values in a savevm image.
- CVE-2013-4529Nov 4, 2014affected < 4.2.5_20-24.9fixed 4.2.5_20-24.9
Buffer overflow in hw/pci/pcie_aer.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large log_num value in a savevm image.
- CVE-2013-4527Nov 4, 2014affected < 4.2.5_20-24.9fixed 4.2.5_20-24.9
Buffer overflow in hw/timer/hpet.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via vectors related to the number of timers.
- CVE-2014-3615Nov 1, 2014affected < 4.2.5_21-27.1fixed 4.2.5_21-27.1
The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
Page 7 of 7