VYPR

rpm package

suse/xen&distro=SUSE Linux Enterprise Software Development Kit 11 SP4

pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4

Vulnerabilities (201)

  • CVE-2017-10806MedAug 2, 2017
    affected < 4.4.4_22-61.9.2fixed 4.4.4_22-61.9.2

    Stack-based buffer overflow in hw/usb/redirect.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU process crash) via vectors related to logging debug messages.

  • CVE-2017-10664HigAug 2, 2017
    affected < 4.4.4_22-61.9.2fixed 4.4.4_22-61.9.2

    qemu-nbd in QEMU (aka Quick Emulator) does not ignore SIGPIPE, which allows remote attackers to cause a denial of service (daemon crash) by disconnecting during a server-to-client reply attempt.

  • CVE-2017-11434MedJul 25, 2017
    affected < 4.4.4_22-61.9.2fixed 4.4.4_22-61.9.2

    The dhcp_decode function in slirp/bootp.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) via a crafted DHCP options string.

  • CVE-2017-7980HigJul 25, 2017
    affected < 4.4.4_18-57.1fixed 4.4.4_18-57.1

    Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC client updating its display after a VGA operation.

  • CVE-2017-9503MedJun 16, 2017
    affected < 4.4.4_20-60.3fixed 4.4.4_20-60.3

    QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving megasas command processing.

  • CVE-2017-9374MedJun 16, 2017
    affected < 4.4.4_20-60.3fixed 4.4.4_20-60.3

    Memory leak in QEMU (aka Quick Emulator), when built with USB EHCI Emulation support, allows local guest OS privileged users to cause a denial of service (memory consumption) by repeatedly hot-unplugging the device.

  • CVE-2017-9330MedJun 8, 2017
    affected < 4.4.4_20-60.3fixed 4.4.4_20-60.3

    QEMU (aka Quick Emulator) before 2.9.0, when built with the USB OHCI Emulation support, allows local guest OS users to cause a denial of service (infinite loop) by leveraging an incorrect return value, a different vulnerability than CVE-2017-6505.

  • CVE-2017-8309HigMay 23, 2017
    affected < 4.4.4_20-60.3fixed 4.4.4_20-60.3

    Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a denial of service (memory consumption) by repeatedly starting and stopping audio capture.

  • CVE-2017-8905HigMay 11, 2017
    affected < 4.4.4_20-60.3fixed 4.4.4_20-60.3

    Xen through 4.6.x on 64-bit platforms mishandles a failsafe callback, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-215.

  • CVE-2017-8112MedMay 2, 2017
    affected < 4.4.4_20-60.3fixed 4.4.4_20-60.3

    hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and CPU consumption) via the message ring page count.

  • CVE-2017-7718MedApr 20, 2017
    affected < 4.4.4_18-57.1fixed 4.4.4_18-57.1

    hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors related to copying VGA data via the cirrus_bitblt_rop_fwd_transp_ and cirrus_bitblt_rop_fwd_ functi

  • CVE-2015-8619HigApr 13, 2017
    affected < 4.4.4_02-32.1fixed 4.4.4_02-32.1

    The Human Monitor Interface support in QEMU allows remote attackers to cause a denial of service (out-of-bounds write and application crash).

  • CVE-2015-8567HigApr 13, 2017
    affected < 4.4.4_02-32.1fixed 4.4.4_02-32.1

    Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption).

  • CVE-2015-8345MedApr 13, 2017
    affected < 4.4.3_06-29.1fixed 4.4.3_06-29.1

    The eepro100 emulator in QEMU qemu-kvm blank allows local guest users to cause a denial of service (application crash and infinite loop) via vectors involving the command block list.

  • CVE-2015-8613MedApr 11, 2017
    affected < 4.4.4_02-32.1fixed 4.4.4_02-32.1

    Stack-based buffer overflow in the megasas_ctrl_get_info function in QEMU, when built with SCSI MegaRAID SAS HBA emulation support, allows local guest users to cause a denial of service (QEMU instance crash) via a crafted SCSI controller CTRL_GET_INFO command.

  • CVE-2015-8568MedApr 11, 2017
    affected < 4.4.4_02-32.1fixed 4.4.4_02-32.1

    Memory leak in QEMU, when built with a VMWARE VMXNET3 paravirtual NIC emulator support, allows local guest users to cause a denial of service (host memory consumption) by trying to activate the vmxnet3 device repeatedly.

  • CVE-2015-8504MedApr 11, 2017
    affected < 4.4.4_02-32.1fixed 4.4.4_02-32.1

    Qemu, when built with VNC display driver support, allows remote attackers to cause a denial of service (arithmetic exception and application crash) via crafted SetPixelFormat messages from a client.

  • CVE-2017-7228HigApr 4, 2017
    affected < 4.4.4_16-54.1fixed 4.4.4_16-54.1

    An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The earlier XSA-29 fix introduced an insufficient check on XENMEM_exchange input, allowing the caller to drive hypervisor memory accesses outside of the guest provid

  • CVE-2017-5973MedMar 27, 2017
    affected < 4.4.4_14-51.1fixed 4.4.4_14-51.1

    The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors related to control transfer descriptor sequence.

  • CVE-2016-9922MedMar 27, 2017
    affected < 4.4.4_14-51.1fixed 4.4.4_14-51.1

    The cirrus_do_copy function in hw/display/cirrus_vga.c in QEMU (aka Quick Emulator), when cirrus graphics mode is VGA, allows local guest OS privileged users to cause a denial of service (divide-by-zero error and QEMU process crash) via vectors involving blit pitch values.

Page 4 of 11