VYPR

Qemu

by QEMU

Source repositories

CVEs (449)

  • CVE-2020-25723LowDec 2, 2020
    risk 0.21cvss 3.2epss 0.00

    A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged user within the guest may abuse this flaw to send bogus USB requests and crash the…

  • CVE-2020-25743LowOct 6, 2020
    risk 0.21cvss 3.2epss 0.00

    hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.

  • CVE-2020-25742LowOct 6, 2020
    risk 0.21cvss 3.2epss 0.00

    pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not return a valid pointer.

  • CVE-2020-25741LowOct 2, 2020
    risk 0.21cvss 3.2epss 0.00

    fdctrl_write_data in hw/block/fdc.c in QEMU 5.0.0 has a NULL pointer dereference via a NULL block pointer for the current drive.

  • CVE-2020-25084LowSep 25, 2020
    risk 0.21cvss 3.2epss 0.00

    QEMU 5.0.0 has a use-after-free in hw/usb/hcd-xhci.c because the usb_packet_map return value is not checked.

  • CVE-2020-14415LowAug 27, 2020
    risk 0.21cvss 3.3epss 0.00

    oss_write in audio/ossaudio.c in QEMU before 5.0.0 mishandles a buffer position.

  • CVE-2020-15859LowJul 21, 2020
    risk 0.21cvss 3.3epss 0.00

    QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the data's address set to the e1000e's MMIO address.

  • CVE-2020-13362LowMay 28, 2020
    risk 0.21cvss 3.2epss 0.00

    In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue_head field from a guest OS user.

  • CVE-2020-10717LowMay 4, 2020
    risk 0.21cvss 3.3epss 0.00

    A potential DoS flaw was found in the virtio-fs shared file system daemon (virtiofsd) implementation of the QEMU version >= v5.0. Virtio-fs is meant to share a host file system directory with a guest via virtio-fs device. If the guest opens the maximum number of file descriptors…

  • CVE-2020-11869LowApr 27, 2020
    risk 0.21cvss 3.3epss 0.00

    An integer overflow was found in QEMU 4.0.1 through 4.2.0 in the way it implemented ATI VGA emulation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati-2d.c while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this…

  • CVE-2019-8934LowMar 21, 2019
    risk 0.21cvss 3.3epss 0.01

    hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/system-id and /proc/device-tree/model system attributes with a guest.

  • CVE-2016-9908LowDec 23, 2016
    risk 0.21cvss 3.3epss 0.00

    Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET' command. A guest user/process could use this flaw to leak contents of the host memory bytes.

  • CVE-2024-8612LowSep 20, 2024
    risk 0.18cvss 3.8epss 0.00

    A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complete / virito_crypto_req_complete could be larger than the true size of the data which has been sent to guest.…

  • CVE-2020-13659LowJun 2, 2020
    risk 0.16cvss 2.5epss 0.00

    address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.

  • CVE-2020-15469LowJul 2, 2020
    risk 0.15cvss 2.3epss 0.00

    In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback methods, leading to a NULL pointer dereference.

  • CVE-2021-20263LowMar 9, 2021
    risk 0.14cvss 3.3epss 0.00

    A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new 'xattrmap' option may cause the 'security.capability' xattr in the guest to not drop on file write, potentially leading to a modified, privileged executable in the guest. In rare…

  • CVE-2021-20203LowFeb 25, 2021
    risk 0.14cvss 3.2epss 0.01

    An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to crash the QEMU process on the…

  • CVE-2015-3456May 13, 2015
    risk 0.04cvss —epss 0.15

    The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND,…

  • CVE-2008-2382Dec 24, 2008
    risk 0.04cvss —epss 0.07

    The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote attackers to cause a denial of service (infinite loop) via a certain message.

  • CVE-2007-6227Dec 4, 2007
    risk 0.03cvss —epss 0.01

    QEMU 0.9.0 allows local users of a Windows XP SP2 guest operating system to overwrite the TranslationBlock (code_gen_buffer) buffer, and probably have unspecified other impacts related to an "overflow," via certain Windows executable programs, as demonstrated by qemu-dos.com.

Page 18 of 23