VYPR

Qemu

by QEMU

Source repositories

CVEs (448)

  • CVE-2020-7039MedJan 16, 2020
    risk 0.37cvss 5.6epss 0.04

    tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.

  • CVE-2018-19665MedDec 6, 2018
    risk 0.37cvss 5.7epss 0.01

    The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption.

  • CVE-2026-23215MedFeb 18, 2026
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: x86/vmware: Fix hypercall clobbers Fedora QA reported the following panic: BUG: unable to handle page fault for address: 0000000040003e54 #PF: supervisor write access in kernel mode #PF:…

  • CVE-2024-8354MedSep 19, 2024
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of…

  • CVE-2024-4693MedMay 14, 2024
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the QEMU Virtio PCI Bindings (hw/virtio/virtio-pci.c). An improper release and use of the irqfd for vector 0 during the boot process leads to a guest triggerable crash via vhost_net_stop(). This flaw allows a malicious guest to crash the QEMU process on the…

  • CVE-2023-3301MedSep 13, 2023
    risk 0.36cvss 5.6epss 0.00

    A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.

  • CVE-2014-0148MedSep 29, 2022
    risk 0.36cvss 5.5epss 0.00

    Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables. These are used to derive other fields like…

  • CVE-2021-3947MedFeb 18, 2022
    risk 0.36cvss 5.5epss 0.00

    A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a malicious guest controlling certain input can read out of bounds memory. A malicious user could use this flaw leading to disclosure of sensitive information.

  • CVE-2021-20255MedMar 9, 2021
    risk 0.36cvss 5.5epss 0.00

    A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a guest user or process to consume CPU cycles or crash the QEMU…

  • CVE-2020-28916MedDec 4, 2020
    risk 0.36cvss 5.5epss 0.01

    hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.

  • CVE-2020-24352MedOct 16, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in QEMU through 5.1.0. An out-of-bounds memory access was found in the ATI VGA device implementation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati_2d.c while handling MMIO write operations through the ati_mm_write() callback. A malicious…

  • CVE-2020-10702MedJun 4, 2020
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation process caused every PAuth-enforced pointer to be signed with the same…

  • CVE-2020-13791MedJun 4, 2020
    risk 0.36cvss 5.5epss 0.00

    hw/pci/pci.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access by providing an address near the end of the PCI configuration space.

  • CVE-2020-13253MedMay 27, 2020
    risk 0.36cvss 5.5epss 0.00

    sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_write() operations. A guest OS user can crash the QEMU process.

  • CVE-2015-5239MedJan 23, 2020
    risk 0.36cvss 6.5epss 0.04

    Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.

  • CVE-2019-9824MedJun 3, 2019
    risk 0.36cvss 5.5epss 0.00

    tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure.

  • CVE-2019-6501MedMar 21, 2019
    risk 0.36cvss 5.5epss 0.01

    In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations.

  • CVE-2018-18849MedMar 21, 2019
    risk 0.36cvss 5.5epss 0.01

    In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value.

  • CVE-2018-20124MedDec 20, 2018
    risk 0.36cvss 5.5epss 0.00

    hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqWqe ring element with a large num_sge value.

  • CVE-2018-20126MedDec 20, 2018
    risk 0.36cvss 5.5epss 0.00

    hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled.

Page 11 of 23