CRITICAL10.0CVE-2022-36648The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier, allows remote attackers… from 0
CRITICAL10.0CVE-2017-16845hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access. from 0, < 1:2.12~rc3+dfsg-1
CRITICAL9.9qemu-kvm - security update
from 0, < 1:2.8+dfsg-4
CRITICAL9.9Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue.
from 0, < 1:2.8+dfsg-3
CRITICAL9.9Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitra…
from 0, < 0.11.0-1
CRITICAL9.8The QMP guest_exec command in QEMU 4.0.0 and earlier is prone to OS command injection, which allows the attacker to achieve code execution,…
from 0
CRITICAL9.8The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote attacker to achiev…
from 0
CRITICAL9.8qemu - security update
from 0, < 1:2.8+dfsg-6+deb9u8
CRITICAL9.8qemu - security update
from 0, < 1:3.1+dfsg-7
CRITICAL9.8qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service…
from 0, < 1:3.1+dfsg-1
CRITICAL9.8A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an expo…
from 0, < 1:2.11+dfsg-1
CRITICAL9.8Buffer overflow in the "megasas_mmio_write" function in Qemu 2.9.0 allows remote attackers to have unspecified impact via unknown vectors.
from 0, < 1:2.8+dfsg-5
CRITICAL9.8qemu-kvm - security update
from 0, < 1.1.2+dfsg-6+deb7u16
CRITICAL9.8qemu-kvm - security update
from 0, < 1:2.7+dfsg-1
CRITICAL9.8Buffer overflow in the mipsnet_receive function in hw/net/mipsnet.c in QEMU, when the guest NIC is configured to accept large packets, allo…
from 0, < 1:2.6+dfsg-2
CRITICAL9.1qemu - security update
from 0, < 1.1.2+dfsg-6+deb7u20
CRITICAL9.1qemu - security update
from 0, < 1:2.8+dfsg-3
CRITICAL9.0Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System (9pfs) support, is vulnerable to an improper acc…
from 0, < 1:2.8+dfsg-5
CRITICAL9.0Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to caus…
from 0, < 1:2.5+dfsg-1
HIGH8.8QEMU before 8.2.0 has an integer underflow, and resultant buffer overflow, via a TI command when an expected non-DMA transfer length is les…
from 0, < 1:7.2+dfsg-7+deb12u3
HIGH8.8qemu - security update
from 0, < 1:3.1+dfsg-8+deb10u11
HIGH8.8qemu - security update
from 0, < 1:5.0-1
HIGH8.8softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or io_writex c…
from 0
HIGH8.8A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device.
from 0, < 1:5.2+dfsg-11+deb11u3
HIGH8.8The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted s…
from 0, < 2.1+dfsg-1
HIGH8.8ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the fir…
from 0, < 1:4.1-1
HIGH8.8A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2.9 built with the Network Block Device (NBD) client support.
from 0, < 1:2.8+dfsg-3
HIGH8.8qemu-kvm - security update
from 0, < 1.1.2+dfsg-6+deb7u22
HIGH8.8qemu-kvm - security update
from 0, < 1:2.8+dfsg-3
HIGH8.8qemu - security update
from 0, < 1.1.2+dfsg-6+deb7u25
HIGH8.8qemu - security update
from 0, < 1:2.12~rc3+dfsg-1
HIGH8.8Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of serv…
from 0, < 1:2.5+dfsg-1
HIGH8.8qemu - security update
from 0, < 1:2.10.0-1
HIGH8.8qemu - security update
from 0, < 1.1.2+dfsg-6+deb7u24
HIGH8.8Integer overflow in hw/virtio/virtio-crypto.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of serv…
from 0, < 1:2.8+dfsg-3
HIGH8.8qemu - security update
from 0, < 1.1.2+dfsg-6a+deb7u13
HIGH8.8qemu - security update
from 0, < 1:2.1+dfsg-12+deb8u6
HIGH8.8qemu - security update
from 0, < 1:2.6+dfsg-1
HIGH8.8Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial…
from 0, < 1:2.5+dfsg-2
HIGH8.6An off-by-one read/write issue was found in the SDHCI device of QEMU.
from 0
HIGH8.6QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions,…
from 0, < 2.0.0+dfsg-1
HIGH8.6The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue.
from 0, < 1:2.11+dfsg-1
HIGH8.6Buffer overflow in the stellaris_enet_receive function in hw/net/stellaris_enet.c in QEMU, when the Stellaris ethernet controller is config…
from 0, < 1:2.6+dfsg-1
HIGH8.6The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) w…
from 0, < 1:2.3+dfsg-1
HIGH8.5A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2.
from 0, < 1:5.2+dfsg-11+deb11u1
HIGH8.4The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap…
from 0, < 1:2.6+dfsg-1
HIGH8.2A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation.
from 0
HIGH8.2A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard…
from 0
HIGH8.2A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU.
from 0
HIGH8.2A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU.
from 0
HIGH8.2A flaw was found in the QXL display device emulation in QEMU.
from 0, < 1:5.2+dfsg-11+deb11u2
HIGH8.2qemu - security update
from 0, < 1:5.2+dfsg-11+deb11u2
HIGH8.2qemu - security update
from 0, < 1:5.2+dfsg-11+deb11u2
HIGH8.2An out-of-bounds write vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including…
from 0, < 1:5.2+dfsg-11+deb11u1
HIGH8.2A flaw was found in qemu.
from 0, < 1:5.2+dfsg-5
HIGH8.2qemu - security update
from 0, < 1:2.8+dfsg-6+deb9u6
HIGH8.2qemu - security update
from 0, < 1:2.1+dfsg-12+deb8u11
HIGH8.2qemu - security update
from 0, < 1:3.1+dfsg-1
HIGH8.2Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain…
from 0, < 1:2.5+dfsg-2
HIGH8.1The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration devi…
from 0, < 1:2.5+dfsg-4
HIGH7.9qemu - security update
from 0, < 1:2.5+dfsg-1
HIGH7.9qemu - security update
from 0, < 1:2.1+dfsg-12+deb8u7
HIGH7.8A heap buffer overflow was found in the virtio-snd device in QEMU.
from 0
HIGH7.8A flaw was found in the QEMU disk image utility (qemu-img) 'info' command.
from 0
HIGH7.8A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU.
from 0
HIGH7.8A DMA reentrancy issue was found in the Tulip device emulation in QEMU.
from 0, < 1:7.1+dfsg-2
HIGH7.8A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation.
from 0, < 1:5.2+dfsg-11+deb11u2
HIGH7.8An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process…
from 0, < 2.1+dfsg-1
HIGH7.8Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentially result in arbitrary code execution on the host with the p…
from 0, < 2.1+dfsg-1
HIGH7.8A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device.
from 0, < 1.5.0+dfsg-1
HIGH7.8qemu - security update
from 0, < 1:4.1-1
HIGH7.8qemu - security update
from 0, < 1:3.1+dfsg-8+deb10u2
HIGH7.8In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.
from 0, < 1:3.1+dfsg-3
HIGH7.8A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0.
from 0, < 1:3.1+dfsg-1
HIGH7.8An OOB heap buffer r/w access issue was found in the NVM Express Controller emulation in QEMU.
from 0, < 1:3.1+dfsg-1
HIGH7.8Multiple buffer overflows in QEMU before 1.7.2 and 2.x before 2.0.0, allow local users to cause a denial of service (crash) or possibly exe…
from 0, < 2.0.0+dfsg-1
HIGH7.8Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute…
from 0, < 1:2.8+dfsg-4
HIGH7.8Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable to an improper acce…
from 0, < 1:2.8+dfsg-6
HIGH7.8The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allow local guest OS administrators to cause a denial of serv…
from 0, < 1:2.6+dfsg-2
HIGH7.8qemu - security update
from 0, < 1:2.6+dfsg-2
HIGH7.8qemu - security update
from 0, < 1:2.1+dfsg-12+deb8u12
HIGH7.7Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption).
from 0, < 1:2.5+dfsg-3
HIGH7.5A flaw was found in QEMU.
from 0
HIGH7.5qemu - security update
from 0, < 1:5.2+dfsg-11+deb11u5
HIGH7.5qemu - security update
from 0, < 1:5.2+dfsg-11+deb11u5
HIGH7.5A flaw was found in the QEMU built-in VNC server.
from 0, < 1:5.2+dfsg-11+deb11u3
HIGH7.5A use-after-free vulnerability was found in the virtio-net device of QEMU.
from 0, < 1:5.2+dfsg-11+deb11u1
HIGH7.5A flaw was found in the virtio-net device of QEMU.
from 0, < 1:5.2+dfsg-11+deb11u2
HIGH7.5A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0.
from 0, < 1:5.2+dfsg-4
HIGH7.5An issue was discovered in ide_dma_cb() in hw/ide/core.c in QEMU 2.4.0 through 4.2.0.
from 0, < 1:5.0-1
HIGH7.5qemu - security update
from 0, < 1:4.1-2
HIGH7.5qemu - security update
from 0, < 1:2.8+dfsg-6+deb9u9
HIGH7.5interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference.
from 0, < 1:3.1+dfsg-8
HIGH7.5QEMU 3.0.0 has an Integer Overflow because the qga/commands*.c files do not check the length of the argument list or the number of environm…
from 0
HIGH7.5hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, which allows the attacker to cause a denial of service via a…
from 0, < 1:3.1+dfsg-8
HIGH7.5hw/rdma/vmw/pvrdma_main.c in QEMU does not implement a read operation (such as uar_read by analogy to uar_write), which allows attackers to…
from 0, < 1:4.1-1
HIGH7.5QEMU can have an infinite loop in hw/rdma/vmw/pvrdma_dev_ring.c because return values are not checked (and -1 is mishandled).
from 0, < 1:4.1-1
HIGH7.5hw/rdma/vmw/pvrdma_cmd.c in QEMU allows attackers to cause a denial of service (NULL pointer dereference or excessive memory allocation) in…
from 0, < 1:4.1-1
HIGH7.5Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used.
from 0, < 1:3.1+dfsg-1
HIGH7.5qemu - security update
from 0, < 1:2.1+dfsg-12+deb8u9
HIGH7.5qemu - security update
from 0, < 1:3.1+dfsg-1
HIGH7.5qemu - security update
from 0, < 1:3.1+dfsg-1
HIGH7.5qemu - security update
from 0, < 1:2.1+dfsg-12+deb8u10
HIGH7.5VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to be vulnerable to an unbounded memory allocation issue, as…
from 0, < 1:2.12~rc3+dfsg-1
HIGH7.5Qemu through 2.10.0 allows remote attackers to cause a memory leak by triggering slow data-channel read operations, related to io/channel-w…
from 0, < 1:2.11+dfsg-1
HIGH7.5Use-after-free vulnerability in the sofree function in slirp/socket.c in QEMU (aka Quick Emulator) allows attackers to cause a denial of se…
from 0, < 1:2.10.0-1
HIGH7.5qemu - security update
from 0, < 1.1.2+dfsg-6+deb7u23
HIGH7.5qemu - security update
from 0, < 1:2.8+dfsg-7
HIGH7.5qemu - security update
from 0, < 1:2.8+dfsg-6+deb9u1
HIGH7.5The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Server support, allows remote attackers to…
from 0, < 1:2.8+dfsg-7
HIGH7.5Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a denial of service (memory consumption) by…
from 0, < 1:2.8+dfsg-5
HIGH7.5The Human Monitor Interface support in QEMU allows remote attackers to cause a denial of service (out-of-bounds write and application crash…
from 0, < 1:2.5+dfsg-5
HIGH7.5Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmx…
from 0, < 1:2.8+dfsg-3
HIGH7.5hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of se…
from 0, < 1:2.4+dfsg-2
HIGH7.4An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0.
from 0, < 1:5.2+dfsg-11+deb11u1
HIGH7.1qemu - security update
from 0
HIGH7.1qemu - security update
from 0, < 1:3.1+dfsg-8+deb10u12
HIGH7.1QEMU (aka Quick Emulator) built with the NE2000 device emulation support is vulnerable to an OOB r/w access issue.
from 0, < 1:2.5+dfsg-2
HIGH7.1Multiple integer overflows in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 allow local guest OS administrators t…
from 0, < 1:2.6+dfsg-1
HIGH7.0A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potenti…
from 0, < 1:5.2+dfsg-11+deb11u4
HIGH7.0Multiple integer overflows in the block drivers in QEMU, possibly before 2.0.0, allow local users to cause a denial of service (crash) via…
from 0, < 2.0.0+dfsg-1
HIGH7.0The disas_insn function in target/i386/translate.c in QEMU before 2.9.0, when TCG mode without hardware acceleration is used, does not limi…
from 0, < 1:2.10.0-1
MEDIUM6.8A flaw was found in the virtio-net device in QEMU.
from 0
MEDIUM6.7A flaw was found in QEMU's virtio-blk device.
from 0
MEDIUM6.7A use-after-free vulnerability was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0 during the handli…
from 0
MEDIUM6.7hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation.
from 0, < 1:5.0-6
MEDIUM6.7The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows lo…
from 0, < 1:2.6+dfsg-3.1
MEDIUM6.7The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check command buffer…
from 0, < 1:2.6+dfsg-2
MEDIUM6.5An off-by-one error was found in QEMU's KVM Xen guest support.
from 0, < 1:10.0.8+ds-0+deb13u1
MEDIUM6.5A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages.
from 0, < 1:7.2+dfsg-7+deb12u4
MEDIUM6.5A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages.
from 0, < 1:7.2+dfsg-7+deb12u2
MEDIUM6.5A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU.
from 0, < 1:8.0.4+dfsg-2
MEDIUM6.5A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption requests in virtio_crypto_handle_sym_req.
from 0, < 1:5.2+dfsg-11+deb11u3
MEDIUM6.5A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU.
from 0, < 1:5.2+dfsg-11+deb11u4
MEDIUM6.5An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_er…
from 0, < 1:7.2+dfsg-1
MEDIUM6.5An out-of-bounds read flaw was found in the QXL display device emulation in QEMU.
from 0
MEDIUM6.5An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format.
from 0, < 1:7.2+dfsg-1
MEDIUM6.5A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU.
from 0
MEDIUM6.5A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device.
from 0, < 1:5.2+dfsg-11
MEDIUM6.5An infinite loop flaw was found in the e1000 NIC emulator of the QEMU.
from 0, < 1:5.2+dfsg-9
MEDIUM6.5An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU.
from 0, < 1:5.2+dfsg-11+deb11u1
MEDIUM6.5An off-by-one error was found in the SCSI device emulation in QEMU.
from 0, < 1:5.2+dfsg-11+deb11u3
MEDIUM6.5A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0.
from 0, < 1:6.2+dfsg-1
MEDIUM6.5A divide-by-zero issue was found in dwc2_handle_packet in hw/usb/hcd-dwc2.c in the hcd-dwc2 USB host controller emulation of QEMU.
from 0, < 1:5.2+dfsg-1
MEDIUM6.5The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header…
from 0
MEDIUM6.5An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and includ…
from 0, < 1:5.2+dfsg-11+deb11u1
MEDIUM6.5qemu - security update
from 0, < 1:5.2+dfsg-11+deb11u1
MEDIUM6.5qemu - security update
from 0, < 1:5.2+dfsg-11+deb11u1
MEDIUM6.5qemu - security update
from 0, < 1:5.2+dfsg-11+deb11u3
MEDIUM6.5qemu - security update
from 0, < 1:2.8+dfsg-6+deb9u17
MEDIUM6.5In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation.
from 0, < 1:4.2-1
MEDIUM6.5eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure.
from 0, < 1:5.2+dfsg-1
MEDIUM6.5ati_2d_blt in hw/display/ati_2d.c in QEMU 4.2.1 can encounter an outside-limits situation in a calculation.
from 0, < 1:5.2+dfsg-1
MEDIUM6.5qemu - security update
from 0, < 1:3.1+dfsg-8+deb10u6
MEDIUM6.5qemu - security update
from 0, < 1:4.1-2
MEDIUM6.5A potential DoS flaw was found in the virtio-fs shared file system daemon (virtiofsd) implementation of the QEMU version >= v5.0.
from 0, < 1:5.0-5
MEDIUM6.5A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of…
from 0, < 1:4.1-2
MEDIUM6.5Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial o…
from 0, < 1:2.4+dfsg-1a
MEDIUM6.5qemu-kvm - security update
from 0, < 1:2.4+dfsg-3
MEDIUM6.5qemu-kvm - security update
from 0, < 1.1.2+dfsg-6a+deb7u11
MEDIUM6.5qemu-kvm - security update
from 0, < 1.1.2+dfsg-6+deb7u14
MEDIUM6.5qemu-kvm - security update
from 0, < 2.1+dfsg-1
MEDIUM6.5qemu - security update
from 0, < 1:3.1+dfsg-1
MEDIUM6.5qemu - security update
from 0, < 1:2.8+dfsg-6+deb9u5
MEDIUM6.5An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver.
from 0, < 2.1+dfsg-1
MEDIUM6.5The Virtio Vring implementation in QEMU allows local OS guest users to cause a denial of service (divide-by-zero error and QEMU process cra…
from 0, < 1:2.11+dfsg-1
MEDIUM6.5The vga display update in mis-calculated the region for the dirty bitmap snapshot in case split screen mode is used causing a denial of ser…
from 0, < 1:2.10.0+dfsg-2
MEDIUM6.5qemu - security update
from 0, < 1:2.8+dfsg-6+deb9u3
MEDIUM6.5qemu - security update
from 0, < 1:2.10.0-1
MEDIUM6.5The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensiti…
from 0, < 1:2.8+dfsg-7
MEDIUM6.5Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a den…
from 0, < 1:2.8+dfsg-5
MEDIUM6.5hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and CP…
from 0, < 1:2.8+dfsg-5
MEDIUM6.5Memory leak in the v9fs_list_xattr function in hw/9pfs/9p-xattr.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to ca…
from 0, < 1:2.8+dfsg-5
MEDIUM6.5The eepro100 emulator in QEMU qemu-kvm blank allows local guest users to cause a denial of service (application crash and infinite loop) vi…
from 0, < 1:2.5+dfsg-1
MEDIUM6.5Stack-based buffer overflow in the megasas_ctrl_get_info function in QEMU, when built with SCSI MegaRAID SAS HBA emulation support, allows…
from 0, < 1:2.5+dfsg-3
MEDIUM6.5Memory leak in QEMU, when built with a VMWARE VMXNET3 paravirtual NIC emulator support, allows local guest users to cause a denial of servi…
from 0, < 1:2.5+dfsg-3
MEDIUM6.5Qemu, when built with VNC display driver support, allows remote attackers to cause a denial of service (arithmetic exception and applicatio…
from 0, < 1:2.5+dfsg-1
MEDIUM6.5Memory leak in the virgl_cmd_resource_unref function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS users…
from 0, < 1:2.8+dfsg-3
MEDIUM6.5Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to…
from 0, < 1:2.8+dfsg-3
MEDIUM6.5The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause…
from 0, < 1:2.8+dfsg-3
MEDIUM6.5Memory leak in the serial_exit_core function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cau…
from 0, < 1:2.8+dfsg-3
MEDIUM6.5Memory leak in the virtio_gpu_resource_attach_backing function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest O…
from 0, < 1:2.10.0-1
MEDIUM6.5Memory leak in the virgl_resource_attach_backing function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS…
from 0, < 1:2.10.0-1
MEDIUM6.5Memory leak in hw/audio/es1370.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host mem…
from 0, < 1:2.8+dfsg-2
MEDIUM6.5Memory leak in hw/audio/ac97.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memor…
from 0, < 1:2.8+dfsg-2
MEDIUM6.5The ohci_service_ed_list function in hw/usb/hcd-ohci.c in QEMU (aka Quick Emulator) before 2.9.0 allows local guest OS users to cause a den…
from 0, < 1:2.8+dfsg-4
MEDIUM6.5Memory leak in hw/9pfs/9p-proxy.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host me…
from 0, < 1:2.8+dfsg-1
MEDIUM6.5Memory leak in hw/9pfs/9p-handle.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host m…
from 0, < 1:2.8+dfsg-1
MEDIUM6.5Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory c…
from 0, < 1:2.8+dfsg-1
MEDIUM6.5Memory leak in the v9fs_device_unrealize_common function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS user…
from 0, < 1:2.8+dfsg-1
MEDIUM6.5QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to a memory leakage issue.
from 0, < 1:2.8+dfsg-1
MEDIUM6.5QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue.
from 0, < 1:2.8+dfsg-1
MEDIUM6.5QEMU (aka Quick Emulator) built with the Rocker switch emulation support is vulnerable to an off-by-one error.
from 0, < 1:2.5+dfsg-3
MEDIUM6.5Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide by zero issue.
from 0, < 1:2.8+dfsg-1
MEDIUM6.5Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to a memory leakage issue.
from 0, < 1:2.8+dfsg-1
MEDIUM6.5qemu-kvm - security update
from 0, < 1:2.8+dfsg-1
MEDIUM6.5qemu-kvm - security update
from 0, < 1.1.2+dfsg-6+deb7u19
MEDIUM6.5Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw.
from 0, < 1:2.8+dfsg-1
MEDIUM6.5The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configurati…
from 0, < 1:2.6+dfsg-1
MEDIUM6.5The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administra…
from 0, < 1:2.6+dfsg-2
MEDIUM6.5QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service…
from 0, < 1:2.6+dfsg-1
MEDIUM6.3qemu - security update
from 0, < 1:5.2+dfsg-11+deb11u4
MEDIUM6.3qemu - security update
from 0, < 1:5.2+dfsg-11+deb11u4
MEDIUM6.3qemu - security update
from 0, < 1:2.8+dfsg-6+deb9u14
MEDIUM6.3qemu - security update
from 0, < 1:5.2+dfsg-10
MEDIUM6.2A stack-based buffer overflow was found in the QEMU e1000 network device.
from 0, < 1:10.0.7+ds-0+deb13u1
MEDIUM6.2Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possi…
from 0, < 2.0.0+dfsg-1
MEDIUM6.1A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including).
from 0, < 1:5.2+dfsg-11+deb11u3
MEDIUM6.0A heap-based buffer overflow was found in the SDHCI device emulation of QEMU.
from 0, < 1:5.2+dfsg-11+deb11u4
MEDIUM6.0An issue was discovered in QEMU 7.1.0 through 8.2.1.
from 0, < 1:7.2+dfsg-7+deb12u6
MEDIUM6.0A vulnerability in the lsi53c895a device affects the latest version of qemu.
from 0, < 1:5.2+dfsg-11+deb11u3
MEDIUM6.0A NULL pointer dereference issue was found in the ACPI code of QEMU.
from 0, < 1:6.2+dfsg-2
MEDIUM6.0A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0.
from 0, < 1:5.2+dfsg-11
MEDIUM6.0An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0.
from 0, < 1:5.2+dfsg-11
MEDIUM6.0A NULL pointer dereference flaw was found in the megasas-gen2 SCSI host bus adapter emulation of QEMU in versions before and including 6.0.
from 0
MEDIUM6.0A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0.
from 0
MEDIUM6.0An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and including qemu 4.2.0…
from 0, < 1:5.2+dfsg-4
MEDIUM6.0A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0.
from 0, < 1:5.2+dfsg-9
MEDIUM6.0A flaw was found in the memory management API of QEMU during the initialization of a memory region cache.
from 0, < 1:5.2+dfsg-3
MEDIUM6.0ati-vga in hw/display/ati.c in QEMU 4.2.0 allows guest OS users to trigger infinite recursion via a crafted mm_index value during an ati_mm…
from 0, < 1:5.0-6
MEDIUM6.0qemu - security update
from 0, < 1:4.2-2
MEDIUM6.0qemu - security update
from 0, < 1:2.1+dfsg-12+deb8u14
MEDIUM6.0The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process…
from 0, < 1:2.12~rc3+dfsg-1
MEDIUM6.0The MSI-X MMIO support in hw/pci/msix.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (N…
from 0, < 1:2.5+dfsg-1
MEDIUM6.0The mode4and5 write functions in hw/display/cirrus_vga.c in Qemu allow local OS guest privileged users to cause a denial of service (out-of…
from 0, < 1:2.11+dfsg-1
MEDIUM6.0The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to ca…
from 0, < 1:2.8+dfsg-4
MEDIUM6.0Memory leak in hw/watchdog/wdt_i6300esb.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service…
from 0, < 1:2.8+dfsg-2
MEDIUM6.0Memory leak in the ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to caus…
from 0, < 1:2.8+dfsg-1
MEDIUM6.0Memory leak in the virtio_gpu_resource_create_2d function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS adm…
from 0, < 1:2.8+dfsg-1
MEDIUM6.0Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator), when the xhci uses msix, allows local guest OS…
from 0, < 1:2.7+dfsg-1
MEDIUM6.0The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial o…
from 0, < 1:2.7+dfsg-1
MEDIUM6.0qemu-kvm - security update
from 0, < 1.1.2+dfsg-6+deb7u15
MEDIUM6.0qemu-kvm - security update
from 0, < 1:2.6+dfsg-3.1
MEDIUM6.0The vmxnet3_complete_packet function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensit…
from 0, < 1:2.6+dfsg-3.1
MEDIUM6.0The vmxnet_tx_pkt_parse_headers function in hw/net/vmxnet_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cau…
from 0, < 1:2.6+dfsg-3.1
MEDIUM6.0The mptsas_fetch_requests function in hw/scsi/mptsas.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial…
from 0, < 1:2.6+dfsg-2
MEDIUM6.0Memory leak in the v9fs_write function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial…
from 0, < 1:2.8+dfsg-1
MEDIUM6.0Memory leak in the v9fs_link function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial o…
from 0, < 1:2.8+dfsg-1
MEDIUM6.0The v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host he…
from 0, < 1:2.8+dfsg-1
MEDIUM6.0Memory leak in the v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a d…
from 0, < 1:2.8+dfsg-1
MEDIUM6.0Memory leak in hw/net/eepro100.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory con…
from 0, < 1:2.8+dfsg-1
MEDIUM6.0The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial…
from 0, < 1:2.8+dfsg-1
MEDIUM6.0The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of…
from 0, < 1:2.8+dfsg-1
MEDIUM6.0The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a deni…
from 0, < 1:2.8+dfsg-1
MEDIUM6.0The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial…
from 0, < 1:2.8+dfsg-1
MEDIUM6.0The rc4030_write function in hw/dma/rc4030.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service…
from 0, < 1:2.8+dfsg-4
MEDIUM6.0The v9fs_iov_vunmarshal function in fsdev/9p-iov-marshal.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a den…
from 0, < 1:2.8+dfsg-1
MEDIUM6.0Memory leak in the v9fs_read function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial o…
from 0, < 1:2.8+dfsg-1
MEDIUM6.0qemu-kvm - security update
from 0, < 1.1.2+dfsg-6+deb7u17
MEDIUM6.0qemu-kvm - security update
from 0, < 1:2.8+dfsg-1
MEDIUM6.0The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS a…
from 0, < 1:2.6+dfsg-2
MEDIUM6.0The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation supp…
from 0, < 1:2.6+dfsg-2
MEDIUM6.0QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus emulation support, allows local guest OS administrators to ca…
from 0, < 1:2.6+dfsg-2
MEDIUM6.0The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators…
from 0, < 1:2.6+dfsg-1
MEDIUM6.0The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to obtain sensitive host memory i…
from 0, < 1:2.6+dfsg-3
MEDIUM6.0The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite lo…
from 0, < 1:2.6+dfsg-1
MEDIUM6.0The get_cmd function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check DMA length, which all…
from 0, < 1:2.6+dfsg-2
MEDIUM5.8hw/display/bochs-display.c in QEMU 4.0.0 does not ensure a sufficient PCI config space allocation, leading to a buffer overflow involving t…
from 0, < 1:4.1-1
MEDIUM5.7The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access…
from 0, < 1:5.2+dfsg-10
MEDIUM5.7The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption.
from 0, < 1:3.1+dfsg-2
MEDIUM5.6A flaw was found in QEMU.
from 0, < 1:5.2+dfsg-11+deb11u3
MEDIUM5.6rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which allows attackers to tr…
from 0, < 1:4.2-1
MEDIUM5.6hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not validated against the…
from 0, < 1:4.2-4
MEDIUM5.6qemu - security update
from 0, < 1:3.1+dfsg-8+deb10u7
MEDIUM5.6qemu - security update
from 0, < 1:4.1-2
MEDIUM5.6slirp - security update
from 0, < 1:4.1-2
MEDIUM5.6slirp - security update
from 0, < 1:2.1+dfsg-12+deb8u13
MEDIUM5.6xen - security update
from 0, < 1:2.12~rc3+dfsg-1
MEDIUM5.6qemu - security update
from 0, < 1:2.8+dfsg-6+deb9u4
MEDIUM5.6qemu - security update
from 0, < 1:2.10.0+dfsg-2
MEDIUM5.6QEMU (aka Quick Emulator) before 2.9.0, when built with the USB OHCI Emulation support, allows local guest OS users to cause a denial of se…
from 0, < 1:2.8+dfsg-7
MEDIUM5.6QEMU (aka Quick Emulator), when built with the e1000e NIC emulation support, allows local guest OS privileged users to cause a denial of se…
from 0, < 1:2.8+dfsg-7
MEDIUM5.5A flaw was found in the virtio-crypto device of QEMU.
from 0
MEDIUM5.5A flaw was found in QEMU.
from 0
MEDIUM5.5A flaw was found in the QEMU Virtio PCI Bindings (hw/virtio/virtio-pci.c).
from 0, < 1:8.2.3+ds-1
MEDIUM5.5A flaw was found in QEMU.
from 0, < 1:8.2.3+ds-1
MEDIUM5.5QEMU through 8.0.0 could trigger a division by zero in scsi_disk_reset in hw/scsi/scsi-disk.c because scsi_disk_emulate_mode_select does no…
from 0, < 1:7.2+dfsg-7+deb12u3
MEDIUM5.5QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/ctrl.c because there is no check for whether an endurance g…
from 0, < 1:8.0.4+dfsg-2
MEDIUM5.5Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entrie…
from 0, < 2.0.0+dfsg-1
MEDIUM5.5A stack-buffer-overflow was found in QEMU in the NVME component.
from 0, < 1:6.2+dfsg-1
MEDIUM5.5qemu - security update
from 0, < 1:5.2+dfsg-11
MEDIUM5.5qemu - security update
from 0, < 1:2.8+dfsg-6+deb9u15
MEDIUM5.5A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU.
from 0
MEDIUM5.5hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.
from 0, < 1:5.2+dfsg-1
MEDIUM5.5An issue was discovered in QEMU through 5.1.0.
from 0, < 1:5.2+dfsg-1
MEDIUM5.5A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in…
from 0, < 1:4.2-5
MEDIUM5.5hw/pci/pci.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access by providing an address near the end of the PCI configu…
from 0, < 1:5.0-6
MEDIUM5.5qemu - security update
from 0, < 1:5.0-8
MEDIUM5.5qemu - security update
from 0, < 1:2.8+dfsg-6+deb9u11
MEDIUM5.5qemu - security update
from 0, < 1:3.1+dfsg-8+deb10u9
MEDIUM5.5tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information di…
from 0, < 1:3.1+dfsg-6
MEDIUM5.5In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations.
from 0, < 1:3.1+dfsg-3
MEDIUM5.5In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value.
from 0, < 1:3.1+dfsg-1
MEDIUM5.5QEMU, through version 2.10 and through version 3.1.0, is vulnerable to an out-of-bounds read of up to 128 bytes in the hw/i2c/i2c-ddc.c:i2c…
from 0, < 1:3.1+dfsg-5
MEDIUM5.5hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqWqe ring element with a large num_sge va…
from 0, < 1:4.1-1
MEDIUM5.5hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled.
from 0, < 1:4.1-1
MEDIUM5.5pvrdma_realize in hw/rdma/vmw/pvrdma_main.c in QEMU has a Memory leak after an initialisation error.
from 0, < 1:4.1-1
MEDIUM5.5hw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is being accessed by a second thread, leading to (for example) a…
from 0, < 1:3.1+dfsg-1
MEDIUM5.5The pnv_lpc_do_eccb function in hw/ppc/pnv_lpc.c in Qemu before 3.1 allows out-of-bounds write or read access to PowerNV memory.
from 0, < 1:3.1+dfsg-1
MEDIUM5.5Qemu has integer overflows because IOReadHandler and its associated functions use a signed integer data type for a size value.
from 0, < 1:3.1+dfsg-1
MEDIUM5.5qemu-seccomp.c in QEMU might allow local OS guest users to cause a denial of service (guest crash) by leveraging mishandling of the seccomp…
from 0, < 1:3.1+dfsg-1
MEDIUM5.5Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a den…
from 0, < 1:2.12~rc3+dfsg-1
MEDIUM5.5Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash).
from 0, < 1:2.10.0+dfsg-2
MEDIUM5.5Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU i…
from 0, < 2.1+dfsg-1
MEDIUM5.5QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of se…
from 0, < 1:2.10.0-1
MEDIUM5.5The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x before 2.0.0 allows local users to cause a denial of service (N…
from 0, < 2.0.0+dfsg-1
MEDIUM5.5qemu - security update
from 0, < 2.0.0+dfsg-1
MEDIUM5.5qemu - security update
from 0, < 1.1.2+dfsg-6a+deb7u4
MEDIUM5.5qemu - security update
from 0, < 1:2.8+dfsg-7
MEDIUM5.5qemu - security update
from 0, < 1:2.8+dfsg-6+deb9u2
MEDIUM5.5The dhcp_decode function in slirp/bootp.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (out-of-bou…
from 0, < 1:2.8+dfsg-7
MEDIUM5.5qemu - security update
from 0, < 1:2.10.0-1
MEDIUM5.5qemu - security update
from 0, < 1:2.8+dfsg-6+deb9u10
MEDIUM5.5QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest OS privileged users to cause a denial o…
from 0, < 1:2.10.0-1
MEDIUM5.5Memory leak in QEMU (aka Quick Emulator), when built with USB EHCI Emulation support, allows local guest OS privileged users to cause a den…
from 0, < 1:2.8+dfsg-7
MEDIUM5.5Memory leak in QEMU (aka Quick Emulator), when built with IDE AHCI Emulation support, allows local guest OS privileged users to cause a den…
from 0, < 1:2.8+dfsg-7
MEDIUM5.5Memory leak in the virtio_gpu_set_scanout function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS users to c…
from 0, < 1:2.10.0-1
MEDIUM5.5hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds…
from 0, < 1:2.8+dfsg-4
MEDIUM5.5The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of…
from 0, < 1:2.8+dfsg-3
MEDIUM5.5The cirrus_do_copy function in hw/display/cirrus_vga.c in QEMU (aka Quick Emulator), when cirrus graphics mode is VGA, allows local guest O…
from 0, < 1:2.8+dfsg-1
MEDIUM5.5The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local OS guest privileged users to cause…
from 0, < 1:2.8+dfsg-3
MEDIUM5.5Integer overflow in the emulated_apdu_from_guest function in usb/dev-smartcard-reader.c in Quick Emulator (Qemu), when built with the CCID…
from 0, < 1:2.8+dfsg-3
MEDIUM5.5The virtio_gpu_set_scanout function in QEMU (aka Quick Emulator) built with Virtio GPU Device emulator support allows local guest OS users…
from 0, < 1:2.7+dfsg-1
MEDIUM5.5The virgl_cmd_get_capset function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) built with Virtio GPU Device emulator support…
from 0, < 1:2.10.0-1
MEDIUM5.5QEMU (aka Quick Emulator) built with the ColdFire Fast Ethernet Controller emulator support is vulnerable to an infinite loop issue.
from 0, < 1:2.8+dfsg-1
MEDIUM5.5QEMU (aka Quick Emulator) built with the USB EHCI emulation support is vulnerable to a null pointer dereference flaw.
from 0, < 1:2.6+dfsg-1
MEDIUM5.5QEMU (aka Quick Emulator) built with an IDE AHCI emulation support is vulnerable to a null pointer dereference flaw.
from 0, < 1:2.6+dfsg-1
MEDIUM5.5QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerable to an infinite loop issue.
from 0, < 1:2.5+dfsg-5
MEDIUM5.5QEMU (aka Quick Emulator) built with the TPR optimization for 32-bit Windows guests support is vulnerable to a null pointer dereference fla…
from 0, < 1:2.5+dfsg-4
MEDIUM5.5The cpu_physical_memory_write_rom_internal function in exec.c in QEMU (aka Quick Emulator) does not properly skip MMIO regions, which allow…
from 0, < 1:2.4+dfsg-1a
MEDIUM5.5QEMU (aka Quick Emulator) built to use 'address_space_translate' to map an address to a MemoryRegionSection is vulnerable to an OOB r/w acc…
from 0, < 1:2.4+dfsg-1a
MEDIUM5.5QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue.
from 0, < 1:2.5+dfsg-1
MEDIUM5.5QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue.
from 0, < 1:2.5+dfsg-1
MEDIUM5.5Quick Emulator (Qemu) built with the 'chardev' backend support is vulnerable to a use after free issue.
from 0, < 1:2.8+dfsg-1
MEDIUM5.5The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumpt…
from 0, < 1:2.6+dfsg-3.1
MEDIUM5.5The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory inform…
from 0, < 1:2.6+dfsg-2
MEDIUM5.5The ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop…
from 0, < 1:2.5+dfsg-2
MEDIUM5.5Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process cr…
from 0, < 1:2.6+dfsg-1
MEDIUM5.5Stack-based buffer overflow in hw/scsi/scsi-bus.c in QEMU, when built with SCSI-device emulation support, allows guest OS users with CAP_SY…
from 0, < 1:2.4+dfsg-1a
MEDIUM5.4hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
from 0, < 1:10.0.2+ds-2+deb13u1
MEDIUM5.4hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.
from 0, < 1:10.0.2+ds-2+deb13u1
MEDIUM5.3An issue was discovered in QEMU 7.1.0 through 8.2.1.
from 0, < 1:7.2+dfsg-7+deb12u6
MEDIUM5.3A stack based buffer overflow was found in the virtio-net device of QEMU.
from 0, < 1:5.2+dfsg-11+deb11u4
MEDIUM5.3hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop.
from 0, < 1:5.2+dfsg-1
MEDIUM5.3hw/net/xgmac.c in the XGMAC Ethernet controller in QEMU before 07-20-2020 has a buffer overflow.
from 0, < 1:5.0-12
MEDIUM5.3A flaw was found in qemu Media Transfer Protocol (MTP).
from 0, < 1:3.1+dfsg-2
MEDIUM5.1A flaw was found in QEMU.
from 0
MEDIUM5.0hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values obtained from the host controller driver.
from 0, < 1:5.2+dfsg-1
MEDIUM5.0qemu - security update
from 0, < 1:5.2+dfsg-1
MEDIUM5.0qemu - security update
from 0, < 1:2.8+dfsg-6+deb9u12
MEDIUM5.0An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0.
from 0, < 1:5.1+dfsg-4
MEDIUM5.0An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1.
from 0, < 1:5.0-6
MEDIUM5.0qemu - security update
from 0, < 1:2.6+dfsg-1
MEDIUM5.0qemu - security update
from 0, < 1:2.1+dfsg-12+deb8u8
MEDIUM4.7v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) because of a race condition during file renam…
from 0, < 1:3.1+dfsg-1
MEDIUM4.4A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU.
from 0, < 1:5.2+dfsg-11+deb11u3
MEDIUM4.4A deadlock issue was found in the AHCI controller device of QEMU.
from 0
MEDIUM4.4A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0.
from 0
MEDIUM4.4The cirrus_invalidate_region function in hw/display/cirrus_vga.c in Qemu allows local OS guest privileged users to cause a denial of servic…
from 0, < 1:2.8+dfsg-4
MEDIUM4.4The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial o…
from 0, < 1:2.8+dfsg-7
MEDIUM4.4The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a…
from 0, < 1:2.7+dfsg-1
MEDIUM4.4The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial…
from 0, < 1:2.8+dfsg-1
MEDIUM4.4The (1) mptsas_config_manufacturing_1 and (2) mptsas_config_ioc_0 functions in hw/scsi/mptconfig.c in QEMU (aka Quick Emulator) allow local…
from 0, < 1:2.6+dfsg-3.1
MEDIUM4.4The pvscsi_convert_sglist function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a den…
from 0, < 1:2.6+dfsg-3.1
MEDIUM4.4hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds access o…
from 0, < 1:2.6+dfsg-3.1
MEDIUM4.4Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators t…
from 0, < 1:2.6+dfsg-3.1
MEDIUM4.4The net_tx_pkt_do_sw_fragmentation function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cau…
from 0, < 1:2.6+dfsg-3.1
MEDIUM4.4Use-after-free vulnerability in the vmxnet3_io_bar0_write function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS a…
from 0, < 1:2.6+dfsg-3.1
MEDIUM4.4The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial o…
from 0, < 1:2.6+dfsg-3.1
MEDIUM4.4Multiple integer overflows in the (1) v9fs_xattr_read and (2) v9fs_xattr_write functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow…
from 0, < 1:2.8+dfsg-1
MEDIUM4.4The mptsas_process_scsi_io_request function in QEMU (aka Quick Emulator), when built with LSI SAS1068 Host Bus emulation support, allows lo…
from 0, < 1:2.7+dfsg-1
MEDIUM4.4qemu - security update
from 0, < 1:2.8+dfsg-1
MEDIUM4.4qemu - security update
from 0, < 1.1.2+dfsg-6+deb7u18
MEDIUM4.4The mcf_fec_do_tx function in hw/net/mcf_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transm…
from 0, < 1:2.8+dfsg-1
MEDIUM4.4The imx_fec_do_tx function in hw/net/imx_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transm…
from 0, < 1:2.8+dfsg-3
MEDIUM4.4The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, u…
from 0, < 1:2.6+dfsg-2
MEDIUM4.4The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a denial of service (out-of-bounds write a…
from 0, < 1:2.6+dfsg-3
MEDIUM4.4The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to cause a denial of service (infinite…
from 0, < 1:2.6+dfsg-3
MEDIUM4.3slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the…
from 0, < 1:4.1-2
MEDIUM4.3ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the t…
from 0, < 1:4.1-2
LOW3.9ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.
from 0, < 1:5.2+dfsg-11
LOW3.9qemu - security update
from 0, < 1:5.0-6
LOW3.9qemu - security update
from 0, < 1:2.1+dfsg-12+deb8u15
LOW3.8A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices.
from 0
LOW3.8An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU.
from 0, < 1:4.1-2
LOW3.8An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU.
from 0, < 1:4.1-2
LOW3.8An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU.
from 0, < 1:4.1-2
LOW3.8An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU.
from 0, < 1:4.1-2
LOW3.8iscsi_aio_ioctl_cb in block/iscsi.c in QEMU 4.1.0 has a heap-based buffer over-read that may disclose unrelated information from process me…
from 0, < 1:4.2-7
LOW3.8qemu - security update
from 0, < 1:3.1+dfsg-8+deb10u8
LOW3.8qemu - security update
from 0, < 1:5.0-12
LOW3.8In QEMU through 5.0.0, an assertion failure can occur in the network packet processing.
from 0, < 1:5.1+dfsg-1
LOW3.8qemu - security update
from 0, < 1:4.1-2
LOW3.8qemu - security update
from 0, < 1:3.1+dfsg-8+deb10u5
LOW3.5QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resultin…
from 0, < 1:4.2-1
LOW3.5The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a net…
from 0, < 1:2.4+dfsg-2
LOW3.3A flaw was found in QEMU in the uefi-vars virtual device.
from 0, < 1:10.0.3+ds-4
LOW3.3A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU.
from 0, < 1:5.2+dfsg-9
LOW3.3oss_write in audio/ossaudio.c in QEMU before 5.0.0 mishandles a buffer position.
from 0, < 1:5.0-1
LOW3.3QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the data's address set to…
from 0, < 1:5.2+dfsg-1
LOW3.3An integer overflow was found in QEMU 4.0.1 through 4.2.0 in the way it implemented ATI VGA emulation.
from 0, < 1:5.0-1
LOW3.3hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/system-id and /proc/de…
from 0, < 1:4.1-1
LOW3.3Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue.
from 0, < 1:2.8+dfsg-1
LOW3.2qemu - security update
from 0, < 1:3.1+dfsg-8+deb10u10
LOW3.2qemu - security update
from 0, < 1:5.2+dfsg-11+deb11u3
LOW3.2A flaw was found in the vhost-vsock device of QEMU.
from 0, < 1:5.2+dfsg-11+deb11u2
LOW3.2A use-after-free flaw was found in the MegaRAID emulator of QEMU.
from 0, < 1:5.2+dfsg-10
LOW3.2An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0.
from 0, < 1:5.2+dfsg-11+deb11u3
LOW3.2A reachable assertion issue was found in the USB EHCI emulation code of QEMU.
from 0, < 1:5.2+dfsg-1
LOW3.2hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync cal…
from 0
LOW3.2pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not return a valid poi…
from 0
LOW3.2fdctrl_write_data in hw/block/fdc.c in QEMU 5.0.0 has a NULL pointer dereference via a NULL block pointer for the current drive.
from 0
LOW3.2QEMU 5.0.0 has a use-after-free in hw/usb/hcd-xhci.c because the usb_packet_map return value is not checked.
from 0, < 1:5.2+dfsg-1
LOW3.2In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue_head field from a…
from 0, < 1:5.0-6
LOW2.5address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.
from 0, < 1:5.0-6
LOW2.3qemu - security update
from 0
LOW2.3qemu - security update
from 0, < 1:2.8+dfsg-6+deb9u13
—(no summary)
from 0
—(no summary)
from 0
—(no summary)
from 0
—(no summary)
from 0
—(no summary)
from 0
—(no summary)
from 0
—(no summary)
from 0
—(no summary)
from 0
—(no summary)
from 0
—(no summary)
from 0
—(no summary)
from 0
—(no summary)
from 0
—qemu - security update
from 0, < 1:2.4+dfsg-4
—qemu - security update
from 0, < 1:2.1+dfsg-12+deb8u5a
—qemu - security update
from 0, < 1.1.2+dfsg-6a+deb7u12
—Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a d…
from 0, < 1:2.4+dfsg-1a
—Heap-based buffer overflow in the ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows guest OS users to cause a denial…
from 0, < 1:2.4+dfsg-3
—qemu - security update
from 0, < 1:2.1+dfsg-12+deb8u2
—qemu - security update
from 0, < 1:2.4+dfsg-1a
—The slirp_smb function in net/slirp.c in QEMU 2.3.0 and earlier creates temporary files with predictable names, which allows local users to…
from 0, < 1:2.3+dfsg-5
—Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completely unplug emulated block devices, which allows local HVM gue…
from 0, < 1:2.4+dfsg-1a
—qemu-kvm - security update
from 0, < 1:2.4+dfsg-1a
—Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, al…
from 0, < 1:2.4+dfsg-1a
—xen - security update
from 0, < 1:2.3+dfsg-6
—xen - security update
from 0, < 1:2.1+dfsg-12+deb8u1
—QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM…
from 0, < 1:2.3+dfsg-5
—Xen 3.3.x through 4.5.x enables logging for PCI MSI-X pass-through error messages, which allows local x86 HVM guests to cause a denial of s…
from 0, < 1:2.3+dfsg-5
—Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, which allows local x86 HVM guest users to cause a denial of…
from 0, < 1:2.3+dfsg-5
—Xen 3.3.x through 4.5.x does not properly restrict write access to the host MSI message data field, which allows local x86 HVM guest admini…
from 0, < 1:2.3+dfsg-5
—virtualbox - security update
from 0, < 0.12.5+dfsg-3squeeze5
—virtualbox - security update
from 0, < 1:2.3+dfsg-3
—qemu - security update
from 0, < 1:2.3+dfsg-1
—qemu - security update
from 0, < 1:2.1+dfsg-12
—QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest use…
from 0, < 1:2.3+dfsg-3
—The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrar…
from 0, < 2.1+dfsg-8
—qemu-kvm - security update
from 0, < 2.1+dfsg-9
—qemu-kvm - security update
from 0, < 1.1.2+dfsg-6a+deb7u6
—Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain se…
from 0, < 2.1+dfsg-5
—The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel…
from 0, < 2.1+dfsg-7
—qemu-kvm - security update
from 0, < 1.1.2+dfsg-6a+deb7u5
—qemu-kvm - security update
from 0, < 2.1+dfsg-6
—The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sen…
from 0, < 2.1+dfsg-5
—hw/usb/bus.c in QEMU 1.6.2 allows remote attackers to execute arbitrary code via crafted savevm data, which triggers a heap-based buffer ov…
from 0, < 2.1+dfsg-1
—Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of service (crash) and…
from 0, < 2.0.0+dfsg-6
—Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service (crash…
from 0, < 2.0.0+dfsg-6
—Heap-based buffer overflow in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 might allow remote attackers to execute a…
from 0, < 2.1+dfsg-1
—Array index error in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code…
from 0, < 2.1+dfsg-1
—The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via…
from 0, < 2.1+dfsg-1
—The usb_device_post_load function in hw/usb/bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted…
from 0, < 2.1+dfsg-1
—Buffer overflow in scoop_gpio_handler_update in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a large (1) pr…
from 0, < 2.1+dfsg-1
—Multiple buffer overflows in the tsc210x_load function in hw/input/tsc210x.c in QEMU before 1.7.2 might allow remote attackers to execute a…
from 0, < 2.1+dfsg-1
—Multiple buffer overflows in the ssd0323_load function in hw/display/ssd0323.c in QEMU before 1.7.2 allow remote attackers to cause a denia…
from 0, < 2.1+dfsg-1
—The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen…
from 0, < 2.1+dfsg-1
—Buffer overflow in hw/intc/openpic.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrar…
from 0, < 2.1+dfsg-1
—Buffer overflow in the pxa2xx_ssp_load function in hw/arm/pxa2xx.c in QEMU before 1.7.2 allows remote attackers to cause a denial of servic…
from 0, < 2.1+dfsg-1
—Buffer overflow in target-arm/machine.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbi…
from 0, < 2.1+dfsg-1
—Buffer overflow in hw/ssi/pl022.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary c…
from 0, < 2.1+dfsg-1
—Buffer overflow in hw/pci/pcie_aer.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitra…
from 0, < 2.1+dfsg-1
—Buffer overflow in hw/timer/hpet.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via vectors related to the n…
from 0, < 2.1+dfsg-1
—Buffer overflow in hw/ide/ahci.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary c…
from 0, < 2.1+dfsg-1
—The virtio_load function in virtio/virtio.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm…
from 0, < 2.1+dfsg-1
—The virtio_net_load function in hw/net/virtio-net.c in QEMU 1.5.0 through 1.7.x before 1.7.2 allows remote attackers to cause a denial of s…
from 0, < 2.1+dfsg-1
—Buffer overflow in virtio_net_load function in net/virtio-net.c in QEMU 1.3.0 through 1.7.x before 1.7.2 might allow remote attackers to ex…
from 0, < 2.1+dfsg-1
—Integer signedness error in the virtio_net_load function in hw/net/virtio-net.c in QEMU 1.x before 1.7.2 allows remote attackers to execute…
from 0, < 2.1+dfsg-1
—The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
from 0, < 2.1+dfsg-5
—vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the list with the VMSTATE_END_OF_LIST macro, which allows attacker…
from 0, < 2.1+dfsg-1
—hw/net/vmxnet3.c in QEMU 2.0.0-rc0, 1.7.1, and earlier allows local guest users to cause a denial of service or possibly execute arbitrary…
from 0, < 2.0.0+dfsg-1
—Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecifie…
from 0, < 2.0.0+dfsg-1
—qemu-kvm - security update
from 0, < 1.7.0+dfsg-8
—qemu-kvm - security update
from 0, < 0.12.5+dfsg-3squeeze4
—Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 all…
from 0, < 0.15.1+dfsg-2
—The qdisk PV disk backend in qemu-xen in Xen 4.2.x and 4.3.x before 4.3.1, and qemu 1.1 and other versions, allows local HVM guests to caus…
from 0, < 1.7.0+dfsg-1
—Use-after-free vulnerability in the virtio-pci implementation in Qemu 1.4.0 through 1.6.0 allows local users to cause a denial of service (…
from 0, < 1.7.0+dfsg-4
—qemu-kvm - security update
from 0, < 1.1.2+dfsg-6a+deb7u3
—qemu-kvm - security update
from 0, < 1.6.0+dfsg-2
—qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk image based on the header, which allows local guest OS administ…
from 0, < 1.5.0+dfsg-1
—xen-qemu-dm-4.0 - buffer overflow
from 0, < 1.1.2+dfsg-4
—xen-qemu-dm-4.0 - buffer overflow
from 0, < 0.12.5+dfsg-3squeeze3
—xen-qemu-dm-4.0 - multiple
from 0, < 1.1.2+dfsg-1
—qemu - multiple
from 0, < 0.12.5+dfsg-3squeeze2
—qemu - multiple
from 0, < 1.1.0+dfsg-1
—Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allo…
from 0, < 0.9.1+svn20081101-1
—kvm - several vulnerabilities
from 0, < 0.9.1-10
—The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote atta…
from 0, < 0.9.1-9
—qemu - denial of service
from 0, < 0.8.2-4etch2
—qemu - denial of service
from 0, < 0.9.1-6
—QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using…
from 0, < 0.9.1-5
—The drive_init function in QEMU 0.9.1 determines the format of a raw disk image based on the header, which allows local guest users to read…
from 0, < 0.9.1-5
—qemu - several vulnerabilities
from 0, < 0.8.2-4etch3
—qemu - several vulnerabilities
from 0, < 0.9.1+svn20081207-1
—Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a…
from 0, < 0.9.0-2
—The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU t…
from 0, < 0.9.0-2
—Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to execute arbitrary code via craf…
from 0, < 0.9.0-2
—qemu - several vulnerabilities
from 0, < 0.9.0-2
—QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand to the aam instruction, as demonstrated by "aam 0x0," whic…
from 0, < 0.9.0-2
—QEMU 0.8.2 allows local users to halt a virtual machine by executing the icebp instruction.
from 0, < 0.9.0-2
—qemu - several vulnerabilities
from 0, < 0.6.1+20050407-1sarge1
—qemu - several vulnerabilities
from 0, < 0.8.2-5lenny1
—(no summary)
from 0
—(no summary)
from 0
—(no summary)
from 0