VYPR

vdagent

by Spice Project

CVEs (2)

  • CVE-2020-25651MedNov 26, 2020
    risk 0.42cvss 6.4epss 0.00

    A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of…

  • CVE-2017-15108HigJan 20, 2018
    risk 0.00cvss 7.8epss 0.00

    spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.