Vendor
Spice Gtk
Products
1
CVEs
3
Across products
3
Status
Private
Products
1- 3 CVEs
Recent CVEs
3| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-12194 | Cri | 0.64 | 9.8 | 0.06 | Mar 14, 2018 | A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions… | ||
| CVE-2016-3066 | Med | 0.42 | 6.5 | 0.01 | Jun 6, 2017 | The spice-gtk widget allows remote authenticated users to obtain information from the host clipboard. | ||
| CVE-2013-4324 | 0.00 | — | 0.00 | Oct 3, 2013 | spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid… |
- risk 0.64cvss 9.8epss 0.06
A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions…
- risk 0.42cvss 6.5epss 0.01
The spice-gtk widget allows remote authenticated users to obtain information from the host clipboard.
- CVE-2013-4324Oct 3, 2013risk 0.00cvss —epss 0.00
spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid…