VYPR
Vendor

Spice Gtk

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2017-12194CriMar 14, 2018
    risk 0.64cvss 9.8epss 0.05

    A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions…

  • CVE-2020-14355MedOct 7, 2020
    risk 0.43cvss 6.6epss 0.03

    Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send…

  • CVE-2016-3066MedJun 6, 2017
    risk 0.42cvss 6.5epss 0.01

    The spice-gtk widget allows remote authenticated users to obtain information from the host clipboard.

  • CVE-2013-4324Oct 3, 2013
    risk 0.00cvss epss 0.00

    spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid…