VYPR

Vendor CVEs

QEMU

All CVEs

438 total · sorted by risk
  • CVE-2021-3608Feb 24, 2022
    risk 0.00cvss epss 0.00

    A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an…

  • CVE-2021-3607Feb 24, 2022
    risk 0.00cvss epss 0.00

    An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest due to improper input validation. This flaw allows a privileged guest user to make…

  • CVE-2021-3947Feb 18, 2022
    risk 0.00cvss epss 0.00

    A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a malicious guest controlling certain input can read out of bounds memory. A malicious user could use this flaw leading to disclosure of sensitive information.

  • CVE-2021-3930Feb 18, 2022
    risk 0.00cvss epss 0.00

    An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A malicious guest could use this flaw to potentially crash QEMU, resulting in a…

  • CVE-2021-4145Jan 25, 2022
    risk 0.00cvss epss 0.00

    A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it's not NULL. A malicious unprivileged user within the guest could use this flaw to…

  • CVE-2021-3713Aug 25, 2021
    risk 0.00cvss epss 0.01

    An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0. The device uses the guest supplied stream number unchecked, which can lead to out-of-bounds access to the UASDevice->data3 and UASDevice->status3 fields.…

  • CVE-2021-3682Aug 5, 2021
    risk 0.00cvss epss 0.03

    A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full. A malicious SPICE client could use this flaw to make QEMU call free()…

  • CVE-2021-3595Jun 15, 2021
    risk 0.00cvss epss 0.00

    An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the 'tftp_t' structure. This issue may lead to…

  • CVE-2021-3593Jun 15, 2021
    risk 0.00cvss epss 0.00

    An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp6_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to…

  • CVE-2021-3594Jun 15, 2021
    risk 0.00cvss epss 0.00

    An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to…

  • CVE-2021-3592Jun 15, 2021
    risk 0.00cvss epss 0.00

    An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the 'bootp_t' structure. A malicious guest could use…

  • CVE-2020-27661Jun 2, 2021
    risk 0.00cvss epss 0.00

    A divide-by-zero issue was found in dwc2_handle_packet in hw/usb/hcd-dwc2.c in the hcd-dwc2 USB host controller emulation of QEMU. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service.

  • CVE-2019-12067Jun 2, 2021
    risk 0.00cvss epss 0.00

    The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null.

  • CVE-2021-3546Jun 2, 2021
    risk 0.00cvss epss 0.00

    An out-of-bounds write vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw occurs while processing the 'VIRTIO_GPU_CMD_GET_CAPSET' command from the guest. It could allow a privileged guest user to…

  • CVE-2021-3545Jun 2, 2021
    risk 0.00cvss epss 0.00

    An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw exists in virgl_cmd_get_capset_info() in contrib/vhost-user-gpu/virgl.c and could occur due to the read of uninitialized…

  • CVE-2021-3544Jun 2, 2021
    risk 0.00cvss epss 0.00

    Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. They exist in contrib/vhost-user-gpu/vhost-user-gpu.c and contrib/vhost-user-gpu/virgl.c due to improper release of memory (i.e., free) after…

  • CVE-2020-35503Jun 2, 2021
    risk 0.00cvss epss 0.00

    A NULL pointer dereference flaw was found in the megasas-gen2 SCSI host bus adapter emulation of QEMU in versions before and including 6.0. This issue occurs in the megasas_command_cancelled() callback function while dropping a SCSI request. This flaw allows a privileged guest…

  • CVE-2013-4536May 28, 2021
    risk 0.00cvss epss 0.00

    An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU…

  • CVE-2020-35506May 28, 2021
    risk 0.00cvss epss 0.00

    A use-after-free vulnerability was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0 during the handling of the 'Information Transfer' command (CMD_TI). This flaw allows a privileged guest user to crash the QEMU process on the host, resulting…

  • CVE-2020-35505May 28, 2021
    risk 0.00cvss epss 0.00

    A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0. This issue occurs while handling the 'Information Transfer' command. This flaw allows a privileged guest user to crash the QEMU process on the host,…

  • CVE-2020-35504May 28, 2021
    risk 0.00cvss epss 0.00

    A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system…

  • CVE-2021-20196May 26, 2021
    risk 0.00cvss epss 0.00

    A NULL pointer dereference flaw was found in the floppy disk emulator of QEMU. This issue occurs while processing read/write ioport commands if the selected floppy drive is not initialized with a block device. This flaw allows a privileged guest user to crash the QEMU process on…

  • CVE-2021-3527May 26, 2021
    risk 0.00cvss epss 0.00

    A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined into a single, large transfer request, to reduce the overhead and improve performance. The combined size of the bulk transfer is used to dynamically allocate a variable length array…

  • CVE-2021-20221May 13, 2021
    risk 0.00cvss epss 0.00

    An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and including qemu 4.2.0on aarch64 platform. The issue occurs because while writing an interrupt ID to the controller memory area, it is not masked to be 4 bits…

  • CVE-2021-20181May 13, 2021
    risk 0.00cvss epss 0.00

    A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a malicious 9p client to cause a use-after-free error, potentially escalating their privileges on the system. The highest threat from this vulnerability is to…

  • CVE-2021-3507May 6, 2021
    risk 0.00cvss epss 0.00

    A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileged guest user could use this…

  • CVE-2021-3409Mar 23, 2021
    risk 0.00cvss epss 0.00

    The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest to crash the QEMU process on…

  • CVE-2021-3392Mar 23, 2021
    risk 0.00cvss epss 0.00

    A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privileged guest…

  • CVE-2021-3416Mar 18, 2021
    risk 0.00cvss epss 0.00

    A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A guest user/process may use this flaw to consume CPU cycles…

  • CVE-2021-20255Mar 9, 2021
    risk 0.00cvss epss 0.00

    A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a guest user or process to consume CPU cycles or crash the QEMU…

  • CVE-2021-20263Mar 9, 2021
    risk 0.00cvss epss 0.00

    A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new 'xattrmap' option may cause the 'security.capability' xattr in the guest to not drop on file write, potentially leading to a modified, privileged executable in the guest. In rare…

  • CVE-2021-20203Feb 25, 2021
    risk 0.00cvss epss 0.01

    An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to crash the QEMU process on the…

  • CVE-2020-17380Jan 30, 2021
    risk 0.00cvss epss 0.00

    A heap-based buffer overflow was found in QEMU through 5.0.0 in the SDHCI device emulation support. It could occur while doing a multi block SDMA transfer via the sdhci_sdma_transfer_multi_blocks() routine in hw/sd/sdhci.c. A guest user or process could use this flaw to crash…

  • CVE-2020-35517Jan 28, 2021
    risk 0.00cvss epss 0.01

    A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices.

  • CVE-2020-29443Jan 22, 2021
    risk 0.00cvss epss 0.00

    ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.

  • CVE-2019-20808Dec 31, 2020
    risk 0.00cvss epss 0.00

    In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation. It occurs in the ati_cursor_define() routine while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting…

  • CVE-2020-11947Dec 31, 2020
    risk 0.00cvss epss 0.00

    iscsi_aio_ioctl_cb in block/iscsi.c in QEMU 4.1.0 has a heap-based buffer over-read that may disclose unrelated information from process memory to an attacker.

  • CVE-2020-27821Dec 8, 2020
    risk 0.00cvss epss 0.00

    A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A guest user may abuse this flaw to crash the QEMU process on the…

  • CVE-2020-28916Dec 4, 2020
    risk 0.00cvss epss 0.01

    hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.

  • CVE-2020-25723Dec 2, 2020
    risk 0.00cvss epss 0.00

    A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged user within the guest may abuse this flaw to send bogus USB requests and crash the…

  • CVE-2020-25624Nov 30, 2020
    risk 0.00cvss epss 0.01

    hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values obtained from the host controller driver.

  • CVE-2020-27617Nov 6, 2020
    risk 0.00cvss epss 0.03

    eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure. A guest can crash the QEMU process via packet data that lacks a valid Layer 3 protocol.

  • CVE-2020-27616Nov 6, 2020
    risk 0.00cvss epss 0.03

    ati_2d_blt in hw/display/ati_2d.c in QEMU 4.2.1 can encounter an outside-limits situation in a calculation. A guest can crash the QEMU process.

  • CVE-2020-24352Oct 16, 2020
    risk 0.00cvss epss 0.00

    An issue was discovered in QEMU through 5.1.0. An out-of-bounds memory access was found in the ATI VGA device implementation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati_2d.c while handling MMIO write operations through the ati_mm_write() callback. A malicious…

  • CVE-2020-25742Oct 6, 2020
    risk 0.00cvss epss 0.00

    pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not return a valid pointer.

  • CVE-2020-25743Oct 6, 2020
    risk 0.00cvss epss 0.00

    hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.

  • CVE-2020-25741Oct 2, 2020
    risk 0.00cvss epss 0.00

    fdctrl_write_data in hw/block/fdc.c in QEMU 5.0.0 has a NULL pointer dereference via a NULL block pointer for the current drive.

  • CVE-2020-25625Sep 25, 2020
    risk 0.00cvss epss 0.00

    hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop.

  • CVE-2020-25085Sep 25, 2020
    risk 0.00cvss epss 0.01

    QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZE case.

  • CVE-2020-25084Sep 25, 2020
    risk 0.00cvss epss 0.00

    QEMU 5.0.0 has a use-after-free in hw/usb/hcd-xhci.c because the usb_packet_map return value is not checked.

Page 6 of 9