VYPR

spice-gtk

by Spice Gtk

CVEs (3)

  • CVE-2017-12194CriMar 14, 2018
    risk 0.64cvss 9.8epss 0.06

    A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions…

  • CVE-2016-3066MedJun 6, 2017
    risk 0.42cvss 6.5epss 0.01

    The spice-gtk widget allows remote authenticated users to obtain information from the host clipboard.

  • CVE-2013-4324Oct 3, 2013
    risk 0.00cvss epss 0.00

    spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid…