pkg:Debian/qemu

共 517 筆 CVECRITICAL19HIGH103MEDIUM257LOW37

✅ 檢查你的版本

所有已知漏洞

  • CRITICAL10.0CVE-2022-36648The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier, allows remote attackers…
    from 0
  • CRITICAL10.0CVE-2017-16845hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access.
    from 0, < 1:2.12~rc3+dfsg-1
  • CRITICAL9.9CVE-2016-9603qemu-kvm - security update
    from 0, < 1:2.8+dfsg-4
  • CRITICAL9.9CVE-2017-2620Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue.
    from 0, < 1:2.8+dfsg-3
  • CRITICAL9.9CVE-2009-3616Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitra…
    from 0, < 0.11.0-1
  • CRITICAL9.8CVE-2019-12929The QMP guest_exec command in QEMU 4.0.0 and earlier is prone to OS command injection, which allows the attacker to achieve code execution,…
    from 0
  • CRITICAL9.8CVE-2019-12928The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote attacker to achiev…
    from 0
  • CRITICAL9.8CVE-2018-20815qemu - security update
    from 0, < 1:2.8+dfsg-6+deb9u8
  • CRITICAL9.8CVE-2018-20815qemu - security update
    from 0, < 1:3.1+dfsg-7
  • CRITICAL9.8CVE-2018-17963qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service…
    from 0, < 1:3.1+dfsg-1
  • CRITICAL9.8CVE-2017-15118A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an expo…
    from 0, < 1:2.11+dfsg-1
  • CRITICAL9.8CVE-2017-8380Buffer overflow in the "megasas_mmio_write" function in Qemu 2.9.0 allows remote attackers to have unspecified impact via unknown vectors.
    from 0, < 1:2.8+dfsg-5
  • CRITICAL9.8CVE-2016-7161qemu-kvm - security update
    from 0, < 1:2.7+dfsg-1
  • CRITICAL9.8CVE-2016-7161qemu-kvm - security update
    from 0, < 1.1.2+dfsg-6+deb7u16
  • CRITICAL9.8CVE-2016-4002Buffer overflow in the mipsnet_receive function in hw/net/mipsnet.c in QEMU, when the guest NIC is configured to accept large packets, allo…
    from 0, < 1:2.6+dfsg-2
  • CRITICAL9.1CVE-2017-2615qemu - security update
    from 0, < 1:2.8+dfsg-3
  • CRITICAL9.1CVE-2017-2615qemu - security update
    from 0, < 1.1.2+dfsg-6+deb7u20
  • CRITICAL9.0CVE-2017-7471Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System (9pfs) support, is vulnerable to an improper acc…
    from 0, < 1:2.8+dfsg-5
  • CRITICAL9.0CVE-2015-7512Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to caus…
    from 0, < 1:2.5+dfsg-1
  • HIGH8.8CVE-2024-24474QEMU before 8.2.0 has an integer underflow, and resultant buffer overflow, via a TI command when an expected non-DMA transfer length is les…
    from 0, < 1:7.2+dfsg-7+deb12u3
  • HIGH8.8CVE-2020-24165qemu - security update
    from 0, < 1:5.0-1
  • HIGH8.8CVE-2020-24165qemu - security update
    from 0, < 1:3.1+dfsg-8+deb10u11
  • HIGH8.8CVE-2022-35414softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or io_writex c…
    from 0
  • HIGH8.8CVE-2022-1050A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device.
    from 0, < 1:5.2+dfsg-11+deb11u3
  • HIGH8.8CVE-2013-4535The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted s…
    from 0, < 2.1+dfsg-1
  • HIGH8.8CVE-2019-14378ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the fir…
    from 0, < 1:4.1-1
  • HIGH8.8CVE-2017-2630A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2.9 built with the Network Block Device (NBD) client support.
    from 0, < 1:2.8+dfsg-3
  • HIGH8.8CVE-2016-9602qemu-kvm - security update
    from 0, < 1:2.8+dfsg-3
  • HIGH8.8CVE-2016-9602qemu-kvm - security update
    from 0, < 1.1.2+dfsg-6+deb7u22
  • HIGH8.8CVE-2018-7550qemu - security update
    from 0, < 1:2.12~rc3+dfsg-1
  • HIGH8.8CVE-2018-7550qemu - security update
    from 0, < 1.1.2+dfsg-6+deb7u25
  • HIGH8.8CVE-2015-7504Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of serv…
    from 0, < 1:2.5+dfsg-1
  • HIGH8.8CVE-2017-14167qemu - security update
    from 0, < 1:2.10.0-1
  • HIGH8.8CVE-2017-14167qemu - security update
    from 0, < 1.1.2+dfsg-6+deb7u24
  • HIGH8.8CVE-2017-5931Integer overflow in hw/virtio/virtio-crypto.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of serv…
    from 0, < 1:2.8+dfsg-3
  • HIGH8.8CVE-2016-3710qemu - security update
    from 0, < 1:2.6+dfsg-1
  • HIGH8.8CVE-2016-3710qemu - security update
    from 0, < 1:2.1+dfsg-12+deb8u6
  • HIGH8.8CVE-2016-3710qemu - security update
    from 0, < 1.1.2+dfsg-6a+deb7u13
  • HIGH8.8CVE-2016-1568Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial…
    from 0, < 1:2.5+dfsg-2
  • HIGH8.6CVE-2022-3872An off-by-one read/write issue was found in the SDHCI device of QEMU.
    from 0
  • HIGH8.6CVE-2014-0144QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions,…
    from 0, < 2.0.0+dfsg-1
  • HIGH8.6CVE-2017-15119The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue.
    from 0, < 1:2.11+dfsg-1
  • HIGH8.6CVE-2016-4001Buffer overflow in the stellaris_enet_receive function in hw/net/stellaris_enet.c in QEMU, when the Stellaris ethernet controller is config…
    from 0, < 1:2.6+dfsg-1
  • HIGH8.6CVE-2015-1779The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) w…
    from 0, < 1:2.3+dfsg-1
  • HIGH8.5CVE-2021-3682A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2.
    from 0, < 1:5.2+dfsg-11+deb11u1
  • HIGH8.4CVE-2016-2857The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap…
    from 0, < 1:2.6+dfsg-1
  • HIGH8.2CVE-2024-6519A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation.
    from 0
  • HIGH8.2CVE-2024-3446A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard…
    from 0
  • HIGH8.2CVE-2021-3929A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU.
    from 0
  • HIGH8.2CVE-2021-3750A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU.
    from 0
  • HIGH8.2CVE-2021-4207A flaw was found in the QXL display device emulation in QEMU.
    from 0, < 1:5.2+dfsg-11+deb11u2
  • HIGH8.2CVE-2021-4206qemu - security update
    from 0, < 1:5.2+dfsg-11+deb11u2
  • HIGH8.2CVE-2021-4206qemu - security update
    from 0, < 1:5.2+dfsg-11+deb11u2
  • HIGH8.2CVE-2021-3546An out-of-bounds write vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including…
    from 0, < 1:5.2+dfsg-11+deb11u1
  • HIGH8.2CVE-2020-35517A flaw was found in qemu.
    from 0, < 1:5.2+dfsg-5
  • HIGH8.2CVE-2018-11806qemu - security update
    from 0, < 1:2.8+dfsg-6+deb9u6
  • HIGH8.2CVE-2018-11806qemu - security update
    from 0, < 1:2.1+dfsg-12+deb8u11
  • HIGH8.2CVE-2018-11806qemu - security update
    from 0, < 1:3.1+dfsg-1
  • HIGH8.2CVE-2015-8550Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain…
    from 0, < 1:2.5+dfsg-2
  • HIGH8.1CVE-2016-1714The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration devi…
    from 0, < 1:2.5+dfsg-4
  • HIGH7.9CVE-2015-8666qemu - security update
    from 0, < 1:2.1+dfsg-12+deb8u7
  • HIGH7.9CVE-2015-8666qemu - security update
    from 0, < 1:2.5+dfsg-1
  • HIGH7.8CVE-2024-7730A heap buffer overflow was found in the virtio-snd device in QEMU.
    from 0
  • HIGH7.8CVE-2024-4467A flaw was found in the QEMU disk image utility (qemu-img) 'info' command.
    from 0
  • HIGH7.8CVE-2023-1386A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU.
    from 0
  • HIGH7.8CVE-2022-2962A DMA reentrancy issue was found in the Tulip device emulation in QEMU.
    from 0, < 1:7.1+dfsg-2
  • HIGH7.8CVE-2022-0358A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation.
    from 0, < 1:5.2+dfsg-11+deb11u2
  • HIGH7.8CVE-2013-4536An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process…
    from 0, < 2.1+dfsg-1
  • HIGH7.8CVE-2013-4532Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentially result in arbitrary code execution on the host with the p…
    from 0, < 2.1+dfsg-1
  • HIGH7.8CVE-2013-2016A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device.
    from 0, < 1.5.0+dfsg-1
  • HIGH7.8CVE-2019-13164qemu - security update
    from 0, < 1:3.1+dfsg-8+deb10u2
  • HIGH7.8CVE-2019-13164qemu - security update
    from 0, < 1:4.1-1
  • HIGH7.8CVE-2019-6778In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.
    from 0, < 1:3.1+dfsg-3
  • HIGH7.8CVE-2018-16867A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0.
    from 0, < 1:3.1+dfsg-1
  • HIGH7.8CVE-2018-16847An OOB heap buffer r/w access issue was found in the NVM Express Controller emulation in QEMU.
    from 0, < 1:3.1+dfsg-1
  • HIGH7.8CVE-2014-0145Multiple buffer overflows in QEMU before 1.7.2 and 2.x before 2.0.0, allow local users to cause a denial of service (crash) or possibly exe…
    from 0, < 2.0.0+dfsg-1
  • HIGH7.8CVE-2017-7980Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute…
    from 0, < 1:2.8+dfsg-4
  • HIGH7.8CVE-2017-7493Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable to an improper acce…
    from 0, < 1:2.8+dfsg-6
  • HIGH7.8CVE-2016-5338The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allow local guest OS administrators to cause a denial of serv…
    from 0, < 1:2.6+dfsg-2
  • HIGH7.8CVE-2016-5126qemu - security update
    from 0, < 1:2.1+dfsg-12+deb8u12
  • HIGH7.8CVE-2016-5126qemu - security update
    from 0, < 1:2.6+dfsg-2
  • HIGH7.7CVE-2015-8567Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption).
    from 0, < 1:2.5+dfsg-3
  • HIGH7.5CVE-2025-11234A flaw was found in QEMU.
    from 0
  • HIGH7.5CVE-2024-7409qemu - security update
    from 0, < 1:5.2+dfsg-11+deb11u5
  • HIGH7.5CVE-2024-7409qemu - security update
    from 0, < 1:5.2+dfsg-11+deb11u5
  • HIGH7.5CVE-2023-3354A flaw was found in the QEMU built-in VNC server.
    from 0, < 1:5.2+dfsg-11+deb11u3
  • HIGH7.5CVE-2021-3748A use-after-free vulnerability was found in the virtio-net device of QEMU.
    from 0, < 1:5.2+dfsg-11+deb11u1
  • HIGH7.5CVE-2022-26353A flaw was found in the virtio-net device of QEMU.
    from 0, < 1:5.2+dfsg-11+deb11u2
  • HIGH7.5CVE-2021-20181A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0.
    from 0, < 1:5.2+dfsg-4
  • HIGH7.5CVE-2019-20175An issue was discovered in ide_dma_cb() in hw/ide/core.c in QEMU 2.4.0 through 4.2.0.
    from 0, < 1:5.0-1
  • HIGH7.5CVE-2019-15890qemu - security update
    from 0, < 1:2.8+dfsg-6+deb9u9
  • HIGH7.5CVE-2019-15890qemu - security update
    from 0, < 1:4.1-2
  • HIGH7.5CVE-2019-12155interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference.
    from 0, < 1:3.1+dfsg-8
  • HIGH7.5CVE-2019-12247QEMU 3.0.0 has an Integer Overflow because the qga/commands*.c files do not check the length of the argument list or the number of environm…
    from 0
  • HIGH7.5CVE-2019-5008hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, which allows the attacker to cause a denial of service via a…
    from 0, < 1:3.1+dfsg-8
  • HIGH7.5CVE-2018-20191hw/rdma/vmw/pvrdma_main.c in QEMU does not implement a read operation (such as uar_read by analogy to uar_write), which allows attackers to…
    from 0, < 1:4.1-1
  • HIGH7.5CVE-2018-20216QEMU can have an infinite loop in hw/rdma/vmw/pvrdma_dev_ring.c because return values are not checked (and -1 is mishandled).
    from 0, < 1:4.1-1
  • HIGH7.5CVE-2018-20125hw/rdma/vmw/pvrdma_cmd.c in QEMU allows attackers to cause a denial of service (NULL pointer dereference or excessive memory allocation) in…
    from 0, < 1:4.1-1
  • HIGH7.5CVE-2018-17962Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used.
    from 0, < 1:3.1+dfsg-1
  • HIGH7.5CVE-2018-17958qemu - security update
    from 0, < 1:2.1+dfsg-12+deb8u9
  • HIGH7.5CVE-2018-17958qemu - security update
    from 0, < 1:3.1+dfsg-1
  • HIGH7.5CVE-2018-12617qemu - security update
    from 0, < 1:3.1+dfsg-1
  • HIGH7.5CVE-2018-12617qemu - security update
    from 0, < 1:2.1+dfsg-12+deb8u10
  • HIGH7.5CVE-2017-15124VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to be vulnerable to an unbounded memory allocation issue, as…
    from 0, < 1:2.12~rc3+dfsg-1
  • HIGH7.5CVE-2017-15268Qemu through 2.10.0 allows remote attackers to cause a memory leak by triggering slow data-channel read operations, related to io/channel-w…
    from 0, < 1:2.11+dfsg-1
  • HIGH7.5CVE-2017-13711Use-after-free vulnerability in the sofree function in slirp/socket.c in QEMU (aka Quick Emulator) allows attackers to cause a denial of se…
    from 0, < 1:2.10.0-1
  • HIGH7.5CVE-2017-10664qemu - security update
    from 0, < 1:2.8+dfsg-7
  • HIGH7.5CVE-2017-10664qemu - security update
    from 0, < 1.1.2+dfsg-6+deb7u23
  • HIGH7.5CVE-2017-10664qemu - security update
    from 0, < 1:2.8+dfsg-6+deb9u1
  • HIGH7.5CVE-2017-9524The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Server support, allows remote attackers to…
    from 0, < 1:2.8+dfsg-7
  • HIGH7.5CVE-2017-8309Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a denial of service (memory consumption) by…
    from 0, < 1:2.8+dfsg-5
  • HIGH7.5CVE-2015-8619The Human Monitor Interface support in QEMU allows remote attackers to cause a denial of service (out-of-bounds write and application crash…
    from 0, < 1:2.5+dfsg-5
  • HIGH7.5CVE-2017-6058Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmx…
    from 0, < 1:2.8+dfsg-3
  • HIGH7.5CVE-2015-6855hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of se…
    from 0, < 1:2.4+dfsg-2
  • HIGH7.4CVE-2021-3713An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0.
    from 0, < 1:5.2+dfsg-11+deb11u1
  • HIGH7.1CVE-2023-2861qemu - security update
    from 0, < 1:3.1+dfsg-8+deb10u12
  • HIGH7.1CVE-2023-2861qemu - security update
    from 0
  • HIGH7.1CVE-2015-8743QEMU (aka Quick Emulator) built with the NE2000 device emulation support is vulnerable to an OOB r/w access issue.
    from 0, < 1:2.5+dfsg-2
  • HIGH7.1CVE-2016-2538Multiple integer overflows in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 allow local guest OS administrators t…
    from 0, < 1:2.6+dfsg-1
  • HIGH7.0CVE-2023-5088A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potenti…
    from 0, < 1:5.2+dfsg-11+deb11u4
  • HIGH7.0CVE-2014-0143Multiple integer overflows in the block drivers in QEMU, possibly before 2.0.0, allow local users to cause a denial of service (crash) via…
    from 0, < 2.0.0+dfsg-1
  • HIGH7.0CVE-2017-8284The disas_insn function in target/i386/translate.c in QEMU before 2.9.0, when TCG mode without hardware acceleration is used, does not limi…
    from 0, < 1:2.10.0-1
  • MEDIUM6.8CVE-2024-6505A flaw was found in the virtio-net device in QEMU.
    from 0
  • MEDIUM6.7CVE-2020-35506A use-after-free vulnerability was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0 during the handli…
    from 0
  • MEDIUM6.7CVE-2020-13754hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation.
    from 0, < 1:5.0-6
  • MEDIUM6.7CVE-2016-6351The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows lo…
    from 0, < 1:2.6+dfsg-3.1
  • MEDIUM6.7CVE-2016-4439The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check command buffer…
    from 0, < 1:2.6+dfsg-2
  • MEDIUM6.5CVE-2026-0665An off-by-one error was found in QEMU's KVM Xen guest support.
    from 0, < 1:10.0.8+ds-0+deb13u1
  • MEDIUM6.5CVE-2023-6683A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages.
    from 0, < 1:7.2+dfsg-7+deb12u4
  • MEDIUM6.5CVE-2023-3255A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages.
    from 0, < 1:7.2+dfsg-7+deb12u2
  • MEDIUM6.5CVE-2023-4135A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU.
    from 0, < 1:8.0.4+dfsg-2
  • MEDIUM6.5CVE-2023-3180A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption requests in virtio_crypto_handle_sym_req.
    from 0, < 1:5.2+dfsg-11+deb11u3
  • MEDIUM6.5CVE-2023-3019A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU.
    from 0, < 1:5.2+dfsg-11+deb11u4
  • MEDIUM6.5CVE-2022-4172An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_er…
    from 0, < 1:7.2+dfsg-1
  • MEDIUM6.5CVE-2022-4144An out-of-bounds read flaw was found in the QXL display device emulation in QEMU.
    from 0
  • MEDIUM6.5CVE-2022-3165An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format.
    from 0, < 1:7.2+dfsg-1
  • MEDIUM6.5CVE-2021-3611A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU.
    from 0
  • MEDIUM6.5CVE-2021-3582A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device.
    from 0, < 1:5.2+dfsg-11
  • MEDIUM6.5CVE-2021-20257An infinite loop flaw was found in the e1000 NIC emulator of the QEMU.
    from 0, < 1:5.2+dfsg-9
  • MEDIUM6.5CVE-2021-3638An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU.
    from 0, < 1:5.2+dfsg-11+deb11u1
  • MEDIUM6.5CVE-2021-3930An off-by-one error was found in the SCSI device emulation in QEMU.
    from 0, < 1:5.2+dfsg-11+deb11u3
  • MEDIUM6.5CVE-2021-4145A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0.
    from 0, < 1:6.2+dfsg-1
  • MEDIUM6.5CVE-2020-27661A divide-by-zero issue was found in dwc2_handle_packet in hw/usb/hcd-dwc2.c in the hcd-dwc2 USB host controller emulation of QEMU.
    from 0, < 1:5.2+dfsg-1
  • MEDIUM6.5CVE-2019-12067The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header…
    from 0
  • MEDIUM6.5CVE-2021-3545An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and includ…
    from 0, < 1:5.2+dfsg-11+deb11u1
  • MEDIUM6.5CVE-2021-3544qemu - security update
    from 0, < 1:5.2+dfsg-11+deb11u1
  • MEDIUM6.5CVE-2021-3544qemu - security update
    from 0, < 1:5.2+dfsg-11+deb11u1
  • MEDIUM6.5CVE-2021-20196qemu - security update
    from 0, < 1:5.2+dfsg-11+deb11u3
  • MEDIUM6.5CVE-2021-20196qemu - security update
    from 0, < 1:2.8+dfsg-6+deb9u17
  • MEDIUM6.5CVE-2019-20808In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation.
    from 0, < 1:4.2-1
  • MEDIUM6.5CVE-2020-27617eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure.
    from 0, < 1:5.2+dfsg-1
  • MEDIUM6.5CVE-2020-27616ati_2d_blt in hw/display/ati_2d.c in QEMU 4.2.1 can encounter an outside-limits situation in a calculation.
    from 0, < 1:5.2+dfsg-1
  • MEDIUM6.5CVE-2020-10756qemu - security update
    from 0, < 1:3.1+dfsg-8+deb10u6
  • MEDIUM6.5CVE-2020-10756qemu - security update
    from 0, < 1:4.1-2
  • MEDIUM6.5CVE-2020-10717A potential DoS flaw was found in the virtio-fs shared file system daemon (virtiofsd) implementation of the QEMU version >= v5.0.
    from 0, < 1:5.0-5
  • MEDIUM6.5CVE-2020-1983A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of…
    from 0, < 1:4.1-2
  • MEDIUM6.5CVE-2015-5745Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial o…
    from 0, < 1:2.4+dfsg-1a
  • MEDIUM6.5CVE-2015-5278qemu - security update
    from 0, < 1.1.2+dfsg-6a+deb7u11
  • MEDIUM6.5CVE-2015-5278qemu - security update
    from 0, < 1:2.4+dfsg-3
  • MEDIUM6.5CVE-2015-5239qemu-kvm - security update
    from 0, < 1.1.2+dfsg-6+deb7u14
  • MEDIUM6.5CVE-2015-5239qemu-kvm - security update
    from 0, < 2.1+dfsg-1
  • MEDIUM6.5CVE-2018-10839qemu - security update
    from 0, < 1:2.8+dfsg-6+deb9u5
  • MEDIUM6.5CVE-2018-10839qemu - security update
    from 0, < 1:3.1+dfsg-1
  • MEDIUM6.5CVE-2017-2633An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver.
    from 0, < 2.1+dfsg-1
  • MEDIUM6.5CVE-2017-17381The Virtio Vring implementation in QEMU allows local OS guest users to cause a denial of service (divide-by-zero error and QEMU process cra…
    from 0, < 1:2.11+dfsg-1
  • MEDIUM6.5CVE-2017-13673The vga display update in mis-calculated the region for the dirty bitmap snapshot in case split screen mode is used causing a denial of ser…
    from 0, < 1:2.10.0+dfsg-2
  • MEDIUM6.5CVE-2017-12809qemu - security update
    from 0, < 1:2.10.0-1
  • MEDIUM6.5CVE-2017-12809qemu - security update
    from 0, < 1:2.8+dfsg-6+deb9u3
  • MEDIUM6.5CVE-2017-10911The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensiti…
    from 0, < 1:2.8+dfsg-7
  • MEDIUM6.5CVE-2017-8379Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a den…
    from 0, < 1:2.8+dfsg-5
  • MEDIUM6.5CVE-2017-8112hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and CP…
    from 0, < 1:2.8+dfsg-5
  • MEDIUM6.5CVE-2017-8086Memory leak in the v9fs_list_xattr function in hw/9pfs/9p-xattr.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to ca…
    from 0, < 1:2.8+dfsg-5
  • MEDIUM6.5CVE-2015-8345The eepro100 emulator in QEMU qemu-kvm blank allows local guest users to cause a denial of service (application crash and infinite loop) vi…
    from 0, < 1:2.5+dfsg-1
  • MEDIUM6.5CVE-2015-8613Stack-based buffer overflow in the megasas_ctrl_get_info function in QEMU, when built with SCSI MegaRAID SAS HBA emulation support, allows…
    from 0, < 1:2.5+dfsg-3
  • MEDIUM6.5CVE-2015-8568Memory leak in QEMU, when built with a VMWARE VMXNET3 paravirtual NIC emulator support, allows local guest users to cause a denial of servi…
    from 0, < 1:2.5+dfsg-3
  • MEDIUM6.5CVE-2015-8504Qemu, when built with VNC display driver support, allows remote attackers to cause a denial of service (arithmetic exception and applicatio…
    from 0, < 1:2.5+dfsg-1
  • MEDIUM6.5CVE-2017-5857Memory leak in the virgl_cmd_resource_unref function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS users…
    from 0, < 1:2.8+dfsg-3
  • MEDIUM6.5CVE-2017-5856Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to…
    from 0, < 1:2.8+dfsg-3
  • MEDIUM6.5CVE-2017-5667The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause…
    from 0, < 1:2.8+dfsg-3
  • MEDIUM6.5CVE-2017-5579Memory leak in the serial_exit_core function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cau…
    from 0, < 1:2.8+dfsg-3
  • MEDIUM6.5CVE-2017-5578Memory leak in the virtio_gpu_resource_attach_backing function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest O…
    from 0, < 1:2.10.0-1
  • MEDIUM6.5CVE-2017-5552Memory leak in the virgl_resource_attach_backing function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS…
    from 0, < 1:2.10.0-1
  • MEDIUM6.5CVE-2017-5526Memory leak in hw/audio/es1370.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host mem…
    from 0, < 1:2.8+dfsg-2
  • MEDIUM6.5CVE-2017-5525Memory leak in hw/audio/ac97.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memor…
    from 0, < 1:2.8+dfsg-2
  • MEDIUM6.5CVE-2017-6505The ohci_service_ed_list function in hw/usb/hcd-ohci.c in QEMU (aka Quick Emulator) before 2.9.0 allows local guest OS users to cause a den…
    from 0, < 1:2.8+dfsg-4
  • MEDIUM6.5CVE-2016-9916Memory leak in hw/9pfs/9p-proxy.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host me…
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.5CVE-2016-9915Memory leak in hw/9pfs/9p-handle.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host m…
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.5CVE-2016-9914Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory c…
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.5CVE-2016-9913Memory leak in the v9fs_device_unrealize_common function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS user…
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.5CVE-2016-9846QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to a memory leakage issue.
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.5CVE-2016-9845QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue.
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.5CVE-2015-8701QEMU (aka Quick Emulator) built with the Rocker switch emulation support is vulnerable to an off-by-one error.
    from 0, < 1:2.5+dfsg-3
  • MEDIUM6.5CVE-2016-9921Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide by zero issue.
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.5CVE-2016-9912Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to a memory leakage issue.
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.5CVE-2016-9911qemu - security update
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.5CVE-2016-9911qemu - security update
    from 0, < 1.1.2+dfsg-6+deb7u19
  • MEDIUM6.5CVE-2016-9907Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw.
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.5CVE-2016-2392The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configurati…
    from 0, < 1:2.6+dfsg-1
  • MEDIUM6.5CVE-2016-4020The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administra…
    from 0, < 1:2.6+dfsg-2
  • MEDIUM6.5CVE-2016-2858QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service…
    from 0, < 1:2.6+dfsg-1
  • MEDIUM6.3CVE-2023-1544qemu - security update
    from 0, < 1:5.2+dfsg-11+deb11u4
  • MEDIUM6.3CVE-2023-1544qemu - security update
    from 0, < 1:5.2+dfsg-11+deb11u4
  • MEDIUM6.3CVE-2020-17380qemu - security update
    from 0, < 1:5.2+dfsg-10
  • MEDIUM6.3CVE-2020-17380qemu - security update
    from 0, < 1:2.8+dfsg-6+deb9u14
  • MEDIUM6.2CVE-2025-12464A stack-based buffer overflow was found in the QEMU e1000 network device.
    from 0, < 1:10.0.7+ds-0+deb13u1
  • MEDIUM6.2CVE-2014-0147Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possi…
    from 0, < 2.0.0+dfsg-1
  • MEDIUM6.1CVE-2021-3507A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including).
    from 0, < 1:5.2+dfsg-11+deb11u3
  • MEDIUM6.0CVE-2024-3447A heap-based buffer overflow was found in the SDHCI device emulation of QEMU.
    from 0, < 1:5.2+dfsg-11+deb11u4
  • MEDIUM6.0CVE-2024-26328An issue was discovered in QEMU 7.1.0 through 8.2.1.
    from 0, < 1:7.2+dfsg-7+deb12u6
  • MEDIUM6.0CVE-2023-0330A vulnerability in the lsi53c895a device affects the latest version of qemu.
    from 0, < 1:5.2+dfsg-11+deb11u3
  • MEDIUM6.0CVE-2021-4158A NULL pointer dereference issue was found in the ACPI code of QEMU.
    from 0, < 1:6.2+dfsg-2
  • MEDIUM6.0CVE-2021-3608A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0.
    from 0, < 1:5.2+dfsg-11
  • MEDIUM6.0CVE-2021-3607An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0.
    from 0, < 1:5.2+dfsg-11
  • MEDIUM6.0CVE-2020-35503A NULL pointer dereference flaw was found in the megasas-gen2 SCSI host bus adapter emulation of QEMU in versions before and including 6.0.
    from 0
  • MEDIUM6.0CVE-2020-35504A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0.
    from 0
  • MEDIUM6.0CVE-2021-20221An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and including qemu 4.2.0…
    from 0, < 1:5.2+dfsg-4
  • MEDIUM6.0CVE-2021-3416A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0.
    from 0, < 1:5.2+dfsg-9
  • MEDIUM6.0CVE-2020-27821A flaw was found in the memory management API of QEMU during the initialization of a memory region cache.
    from 0, < 1:5.2+dfsg-3
  • MEDIUM6.0CVE-2020-13800ati-vga in hw/display/ati.c in QEMU 4.2.0 allows guest OS users to trigger infinite recursion via a crafted mm_index value during an ati_mm…
    from 0, < 1:5.0-6
  • MEDIUM6.0CVE-2020-1711qemu - security update
    from 0, < 1:4.2-2
  • MEDIUM6.0CVE-2020-1711qemu - security update
    from 0, < 1:2.1+dfsg-12+deb8u14
  • MEDIUM6.0CVE-2018-5683The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process…
    from 0, < 1:2.12~rc3+dfsg-1
  • MEDIUM6.0CVE-2015-7549The MSI-X MMIO support in hw/pci/msix.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (N…
    from 0, < 1:2.5+dfsg-1
  • MEDIUM6.0CVE-2017-15289The mode4and5 write functions in hw/display/cirrus_vga.c in Qemu allow local OS guest privileged users to cause a denial of service (out-of…
    from 0, < 1:2.11+dfsg-1
  • MEDIUM6.0CVE-2017-7377The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to ca…
    from 0, < 1:2.8+dfsg-4
  • MEDIUM6.0CVE-2016-10155Memory leak in hw/watchdog/wdt_i6300esb.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service…
    from 0, < 1:2.8+dfsg-2
  • MEDIUM6.0CVE-2016-7995Memory leak in the ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to caus…
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.0CVE-2016-7994Memory leak in the virtio_gpu_resource_create_2d function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS adm…
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.0CVE-2016-7466Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator), when the xhci uses msix, allows local guest OS…
    from 0, < 1:2.7+dfsg-1
  • MEDIUM6.0CVE-2016-7422The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial o…
    from 0, < 1:2.7+dfsg-1
  • MEDIUM6.0CVE-2016-7116qemu-kvm - security update
    from 0, < 1:2.6+dfsg-3.1
  • MEDIUM6.0CVE-2016-7116qemu-kvm - security update
    from 0, < 1.1.2+dfsg-6+deb7u15
  • MEDIUM6.0CVE-2016-6836The vmxnet3_complete_packet function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensit…
    from 0, < 1:2.6+dfsg-3.1
  • MEDIUM6.0CVE-2016-6835The vmxnet_tx_pkt_parse_headers function in hw/net/vmxnet_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cau…
    from 0, < 1:2.6+dfsg-3.1
  • MEDIUM6.0CVE-2016-4964The mptsas_fetch_requests function in hw/scsi/mptsas.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial…
    from 0, < 1:2.6+dfsg-2
  • MEDIUM6.0CVE-2016-9106Memory leak in the v9fs_write function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial…
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.0CVE-2016-9105Memory leak in the v9fs_link function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial o…
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.0CVE-2016-9103The v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host he…
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.0CVE-2016-9102Memory leak in the v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a d…
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.0CVE-2016-9101Memory leak in hw/net/eepro100.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory con…
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.0CVE-2016-8910The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial…
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.0CVE-2016-8909The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of…
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.0CVE-2016-8669The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a deni…
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.0CVE-2016-8668The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial…
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.0CVE-2016-8667The rc4030_write function in hw/dma/rc4030.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service…
    from 0, < 1:2.8+dfsg-4
  • MEDIUM6.0CVE-2016-8578The v9fs_iov_vunmarshal function in fsdev/9p-iov-marshal.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a den…
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.0CVE-2016-8577Memory leak in the v9fs_read function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial o…
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.0CVE-2016-8576qemu-kvm - security update
    from 0, < 1:2.8+dfsg-1
  • MEDIUM6.0CVE-2016-8576qemu-kvm - security update
    from 0, < 1.1.2+dfsg-6+deb7u17
  • MEDIUM6.0CVE-2016-5107The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS a…
    from 0, < 1:2.6+dfsg-2
  • MEDIUM6.0CVE-2016-5106The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation supp…
    from 0, < 1:2.6+dfsg-2
  • MEDIUM6.0CVE-2016-4952QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus emulation support, allows local guest OS administrators to ca…
    from 0, < 1:2.6+dfsg-2
  • MEDIUM6.0CVE-2016-2841The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators…
    from 0, < 1:2.6+dfsg-1
  • MEDIUM6.0CVE-2016-4454The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to obtain sensitive host memory i…
    from 0, < 1:2.6+dfsg-3
  • MEDIUM6.0CVE-2016-4037The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite lo…
    from 0, < 1:2.6+dfsg-1
  • MEDIUM6.0CVE-2016-4441The get_cmd function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check DMA length, which all…
    from 0, < 1:2.6+dfsg-2
  • MEDIUM5.8CVE-2019-15034hw/display/bochs-display.c in QEMU 4.0.0 does not ensure a sufficient PCI config space allocation, leading to a buffer overflow involving t…
    from 0, < 1:4.1-1
  • MEDIUM5.7CVE-2021-3409The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access…
    from 0, < 1:5.2+dfsg-10
  • MEDIUM5.7CVE-2018-19665The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption.
    from 0, < 1:3.1+dfsg-2
  • MEDIUM5.6CVE-2023-3301A flaw was found in QEMU.
    from 0, < 1:5.2+dfsg-11+deb11u3
  • MEDIUM5.6CVE-2020-13765rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which allows attackers to tr…
    from 0, < 1:4.2-1
  • MEDIUM5.6CVE-2020-11102hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not validated against the…
    from 0, < 1:4.2-4
  • MEDIUM5.6CVE-2020-8608qemu - security update
    from 0, < 1:3.1+dfsg-8+deb10u7
  • MEDIUM5.6CVE-2020-8608qemu - security update
    from 0, < 1:4.1-2
  • MEDIUM5.6CVE-2020-7039slirp - security update
    from 0, < 1:2.1+dfsg-12+deb8u13
  • MEDIUM5.6CVE-2020-7039slirp - security update
    from 0, < 1:4.1-2
  • MEDIUM5.6CVE-2017-5715xen - security update
    from 0, < 1:2.12~rc3+dfsg-1
  • MEDIUM5.6CVE-2017-15038qemu - security update
    from 0, < 1:2.8+dfsg-6+deb9u4
  • MEDIUM5.6CVE-2017-15038qemu - security update
    from 0, < 1:2.10.0+dfsg-2
  • MEDIUM5.6CVE-2017-9330QEMU (aka Quick Emulator) before 2.9.0, when built with the USB OHCI Emulation support, allows local guest OS users to cause a denial of se…
    from 0, < 1:2.8+dfsg-7
  • MEDIUM5.6CVE-2017-9310QEMU (aka Quick Emulator), when built with the e1000e NIC emulation support, allows local guest OS privileged users to cause a denial of se…
    from 0, < 1:2.8+dfsg-7
  • MEDIUM5.5CVE-2025-14876A flaw was found in the virtio-crypto device of QEMU.
    from 0
  • MEDIUM5.5CVE-2024-8354A flaw was found in QEMU.
    from 0
  • MEDIUM5.5CVE-2024-4693A flaw was found in the QEMU Virtio PCI Bindings (hw/virtio/virtio-pci.c).
    from 0, < 1:8.2.3+ds-1
  • MEDIUM5.5CVE-2024-3567A flaw was found in QEMU.
    from 0, < 1:8.2.3+ds-1
  • MEDIUM5.5CVE-2023-42467QEMU through 8.0.0 could trigger a division by zero in scsi_disk_reset in hw/scsi/scsi-disk.c because scsi_disk_emulate_mode_select does no…
    from 0, < 1:7.2+dfsg-7+deb12u3
  • MEDIUM5.5CVE-2023-40360QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/ctrl.c because there is no check for whether an endurance g…
    from 0, < 1:8.0.4+dfsg-2
  • MEDIUM5.5CVE-2014-0148Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entrie…
    from 0, < 2.0.0+dfsg-1
  • MEDIUM5.5CVE-2021-3947A stack-buffer-overflow was found in QEMU in the NVME component.
    from 0, < 1:6.2+dfsg-1
  • MEDIUM5.5CVE-2021-3527qemu - security update
    from 0, < 1:2.8+dfsg-6+deb9u15
  • MEDIUM5.5CVE-2021-3527qemu - security update
    from 0, < 1:5.2+dfsg-11
  • MEDIUM5.5CVE-2021-20255A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU.
    from 0
  • MEDIUM5.5CVE-2020-28916hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.
    from 0, < 1:5.2+dfsg-1
  • MEDIUM5.5CVE-2020-24352An issue was discovered in QEMU through 5.1.0.
    from 0, < 1:5.2+dfsg-1
  • MEDIUM5.5CVE-2020-10702A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in…
    from 0, < 1:4.2-5
  • MEDIUM5.5CVE-2020-13791hw/pci/pci.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access by providing an address near the end of the PCI configu…
    from 0, < 1:5.0-6
  • MEDIUM5.5CVE-2020-13253qemu - security update
    from 0, < 1:3.1+dfsg-8+deb10u9
  • MEDIUM5.5CVE-2020-13253qemu - security update
    from 0, < 1:2.8+dfsg-6+deb9u11
  • MEDIUM5.5CVE-2020-13253qemu - security update
    from 0, < 1:5.0-8
  • MEDIUM5.5CVE-2019-9824tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information di…
    from 0, < 1:3.1+dfsg-6
  • MEDIUM5.5CVE-2019-6501In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations.
    from 0, < 1:3.1+dfsg-3
  • MEDIUM5.5CVE-2018-18849In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value.
    from 0, < 1:3.1+dfsg-1
  • MEDIUM5.5CVE-2019-3812QEMU, through version 2.10 and through version 3.1.0, is vulnerable to an out-of-bounds read of up to 128 bytes in the hw/i2c/i2c-ddc.c:i2c…
    from 0, < 1:3.1+dfsg-5
  • MEDIUM5.5CVE-2018-20124hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqWqe ring element with a large num_sge va…
    from 0, < 1:4.1-1
  • MEDIUM5.5CVE-2018-20126hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled.
    from 0, < 1:4.1-1
  • MEDIUM5.5CVE-2018-20123pvrdma_realize in hw/rdma/vmw/pvrdma_main.c in QEMU has a Memory leak after an initialisation error.
    from 0, < 1:4.1-1
  • MEDIUM5.5CVE-2018-19364hw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is being accessed by a second thread, leading to (for example) a…
    from 0, < 1:3.1+dfsg-1
  • MEDIUM5.5CVE-2018-18954The pnv_lpc_do_eccb function in hw/ppc/pnv_lpc.c in Qemu before 3.1 allows out-of-bounds write or read access to PowerNV memory.
    from 0, < 1:3.1+dfsg-1
  • MEDIUM5.5CVE-2018-18438Qemu has integer overflows because IOReadHandler and its associated functions use a signed integer data type for a size value.
    from 0, < 1:3.1+dfsg-1
  • MEDIUM5.5CVE-2018-15746qemu-seccomp.c in QEMU might allow local OS guest users to cause a denial of service (guest crash) by leveraging mishandling of the seccomp…
    from 0, < 1:3.1+dfsg-1
  • MEDIUM5.5CVE-2018-7858Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a den…
    from 0, < 1:2.12~rc3+dfsg-1
  • MEDIUM5.5CVE-2017-18043Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash).
    from 0, < 1:2.10.0+dfsg-2
  • MEDIUM5.5CVE-2014-3471Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU i…
    from 0, < 2.1+dfsg-1
  • MEDIUM5.5CVE-2017-13672QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of se…
    from 0, < 1:2.10.0-1
  • MEDIUM5.5CVE-2014-0146The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x before 2.0.0 allows local users to cause a denial of service (N…
    from 0, < 2.0.0+dfsg-1
  • MEDIUM5.5CVE-2014-0142qemu - security update
    from 0, < 2.0.0+dfsg-1
  • MEDIUM5.5CVE-2014-0142qemu - security update
    from 0, < 1.1.2+dfsg-6a+deb7u4
  • MEDIUM5.5CVE-2017-10806qemu - security update
    from 0, < 1:2.8+dfsg-7
  • MEDIUM5.5CVE-2017-10806qemu - security update
    from 0, < 1:2.8+dfsg-6+deb9u2
  • MEDIUM5.5CVE-2017-11434The dhcp_decode function in slirp/bootp.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (out-of-bou…
    from 0, < 1:2.8+dfsg-7
  • MEDIUM5.5CVE-2017-9503qemu - security update
    from 0, < 1:2.10.0-1
  • MEDIUM5.5CVE-2017-9503qemu - security update
    from 0, < 1:2.8+dfsg-6+deb9u10
  • MEDIUM5.5CVE-2017-9375QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest OS privileged users to cause a denial o…
    from 0, < 1:2.10.0-1
  • MEDIUM5.5CVE-2017-9374Memory leak in QEMU (aka Quick Emulator), when built with USB EHCI Emulation support, allows local guest OS privileged users to cause a den…
    from 0, < 1:2.8+dfsg-7
  • MEDIUM5.5CVE-2017-9373Memory leak in QEMU (aka Quick Emulator), when built with IDE AHCI Emulation support, allows local guest OS privileged users to cause a den…
    from 0, < 1:2.8+dfsg-7
  • MEDIUM5.5CVE-2017-9060Memory leak in the virtio_gpu_set_scanout function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS users to c…
    from 0, < 1:2.10.0-1
  • MEDIUM5.5CVE-2017-7718hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds…
    from 0, < 1:2.8+dfsg-4
  • MEDIUM5.5CVE-2017-5973The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of…
    from 0, < 1:2.8+dfsg-3
  • MEDIUM5.5CVE-2016-9922The cirrus_do_copy function in hw/display/cirrus_vga.c in QEMU (aka Quick Emulator), when cirrus graphics mode is VGA, allows local guest O…
    from 0, < 1:2.8+dfsg-1
  • MEDIUM5.5CVE-2017-5987The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local OS guest privileged users to cause…
    from 0, < 1:2.8+dfsg-3
  • MEDIUM5.5CVE-2017-5898Integer overflow in the emulated_apdu_from_guest function in usb/dev-smartcard-reader.c in Quick Emulator (Qemu), when built with the CCID…
    from 0, < 1:2.8+dfsg-3
  • MEDIUM5.5CVE-2016-10029The virtio_gpu_set_scanout function in QEMU (aka Quick Emulator) built with Virtio GPU Device emulator support allows local guest OS users…
    from 0, < 1:2.7+dfsg-1
  • MEDIUM5.5CVE-2016-10028The virgl_cmd_get_capset function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) built with Virtio GPU Device emulator support…
    from 0, < 1:2.10.0-1
  • MEDIUM5.5CVE-2016-9776QEMU (aka Quick Emulator) built with the ColdFire Fast Ethernet Controller emulator support is vulnerable to an infinite loop issue.
    from 0, < 1:2.8+dfsg-1
  • MEDIUM5.5CVE-2016-2198QEMU (aka Quick Emulator) built with the USB EHCI emulation support is vulnerable to a null pointer dereference flaw.
    from 0, < 1:2.6+dfsg-1
  • MEDIUM5.5CVE-2016-2197QEMU (aka Quick Emulator) built with an IDE AHCI emulation support is vulnerable to a null pointer dereference flaw.
    from 0, < 1:2.6+dfsg-1
  • MEDIUM5.5CVE-2016-1981QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerable to an infinite loop issue.
    from 0, < 1:2.5+dfsg-5
  • MEDIUM5.5CVE-2016-1922QEMU (aka Quick Emulator) built with the TPR optimization for 32-bit Windows guests support is vulnerable to a null pointer dereference fla…
    from 0, < 1:2.5+dfsg-4
  • MEDIUM5.5CVE-2015-8818The cpu_physical_memory_write_rom_internal function in exec.c in QEMU (aka Quick Emulator) does not properly skip MMIO regions, which allow…
    from 0, < 1:2.4+dfsg-1a
  • MEDIUM5.5CVE-2015-8817QEMU (aka Quick Emulator) built to use 'address_space_translate' to map an address to a MemoryRegionSection is vulnerable to an OOB r/w acc…
    from 0, < 1:2.4+dfsg-1a
  • MEDIUM5.5CVE-2015-8745QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue.
    from 0, < 1:2.5+dfsg-1
  • MEDIUM5.5CVE-2015-8744QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue.
    from 0, < 1:2.5+dfsg-1
  • MEDIUM5.5CVE-2016-9923Quick Emulator (Qemu) built with the 'chardev' backend support is vulnerable to a use after free issue.
    from 0, < 1:2.8+dfsg-1
  • MEDIUM5.5CVE-2016-5403The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumpt…
    from 0, < 1:2.6+dfsg-3.1
  • MEDIUM5.5CVE-2016-5337The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory inform…
    from 0, < 1:2.6+dfsg-2
  • MEDIUM5.5CVE-2015-8558The ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop…
    from 0, < 1:2.5+dfsg-2
  • MEDIUM5.5CVE-2016-3712Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process cr…
    from 0, < 1:2.6+dfsg-1
  • MEDIUM5.5CVE-2015-5158Stack-based buffer overflow in hw/scsi/scsi-bus.c in QEMU, when built with SCSI-device emulation support, allows guest OS users with CAP_SY…
    from 0, < 1:2.4+dfsg-1a
  • MEDIUM5.4CVE-2025-54567hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
    from 0, < 1:10.0.2+ds-2+deb13u1
  • MEDIUM5.4CVE-2025-54566hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.
    from 0, < 1:10.0.2+ds-2+deb13u1
  • MEDIUM5.3CVE-2024-26327An issue was discovered in QEMU 7.1.0 through 8.2.1.
    from 0, < 1:7.2+dfsg-7+deb12u6
  • MEDIUM5.3CVE-2023-6693A stack based buffer overflow was found in the virtio-net device of QEMU.
    from 0, < 1:5.2+dfsg-11+deb11u4
  • MEDIUM5.3CVE-2020-25625hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop.
    from 0, < 1:5.2+dfsg-1
  • MEDIUM5.3CVE-2020-15863hw/net/xgmac.c in the XGMAC Ethernet controller in QEMU before 07-20-2020 has a buffer overflow.
    from 0, < 1:5.0-12
  • MEDIUM5.3CVE-2018-16872A flaw was found in qemu Media Transfer Protocol (MTP).
    from 0, < 1:3.1+dfsg-2
  • MEDIUM5.1CVE-2026-2243A flaw was found in QEMU.
    from 0
  • MEDIUM5.0CVE-2020-25624hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values obtained from the host controller driver.
    from 0, < 1:5.2+dfsg-1
  • MEDIUM5.0CVE-2020-25085qemu - security update
    from 0, < 1:2.8+dfsg-6+deb9u12
  • MEDIUM5.0CVE-2020-25085qemu - security update
    from 0, < 1:5.2+dfsg-1
  • MEDIUM5.0CVE-2020-14364An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0.
    from 0, < 1:5.1+dfsg-4
  • MEDIUM5.0CVE-2020-10761An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1.
    from 0, < 1:5.0-6
  • MEDIUM5.0CVE-2016-2391qemu - security update
    from 0, < 1:2.6+dfsg-1
  • MEDIUM5.0CVE-2016-2391qemu - security update
    from 0, < 1:2.1+dfsg-12+deb8u8
  • MEDIUM4.7CVE-2018-19489v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) because of a race condition during file renam…
    from 0, < 1:3.1+dfsg-1
  • MEDIUM4.4CVE-2022-0216A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU.
    from 0, < 1:5.2+dfsg-11+deb11u3
  • MEDIUM4.4CVE-2021-3735A deadlock issue was found in the AHCI controller device of QEMU.
    from 0
  • MEDIUM4.4CVE-2020-35505A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0.
    from 0
  • MEDIUM4.4CVE-2017-18030The cirrus_invalidate_region function in hw/display/cirrus_vga.c in Qemu allows local OS guest privileged users to cause a denial of servic…
    from 0, < 1:2.8+dfsg-4
  • MEDIUM4.4CVE-2017-11334The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial o…
    from 0, < 1:2.8+dfsg-7
  • MEDIUM4.4CVE-2016-7421The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a…
    from 0, < 1:2.7+dfsg-1
  • MEDIUM4.4CVE-2016-7170The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial…
    from 0, < 1:2.8+dfsg-1
  • MEDIUM4.4CVE-2016-7157The (1) mptsas_config_manufacturing_1 and (2) mptsas_config_ioc_0 functions in hw/scsi/mptconfig.c in QEMU (aka Quick Emulator) allow local…
    from 0, < 1:2.6+dfsg-3.1
  • MEDIUM4.4CVE-2016-7156The pvscsi_convert_sglist function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a den…
    from 0, < 1:2.6+dfsg-3.1
  • MEDIUM4.4CVE-2016-7155hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds access o…
    from 0, < 1:2.6+dfsg-3.1
  • MEDIUM4.4CVE-2016-6888Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators t…
    from 0, < 1:2.6+dfsg-3.1
  • MEDIUM4.4CVE-2016-6834The net_tx_pkt_do_sw_fragmentation function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cau…
    from 0, < 1:2.6+dfsg-3.1
  • MEDIUM4.4CVE-2016-6833Use-after-free vulnerability in the vmxnet3_io_bar0_write function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS a…
    from 0, < 1:2.6+dfsg-3.1
  • MEDIUM4.4CVE-2016-6490The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial o…
    from 0, < 1:2.6+dfsg-3.1
  • MEDIUM4.4CVE-2016-9104Multiple integer overflows in the (1) v9fs_xattr_read and (2) v9fs_xattr_write functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow…
    from 0, < 1:2.8+dfsg-1
  • MEDIUM4.4CVE-2016-7423The mptsas_process_scsi_io_request function in QEMU (aka Quick Emulator), when built with LSI SAS1068 Host Bus emulation support, allows lo…
    from 0, < 1:2.7+dfsg-1
  • MEDIUM4.4CVE-2016-7909qemu - security update
    from 0, < 1:2.8+dfsg-1
  • MEDIUM4.4CVE-2016-7909qemu - security update
    from 0, < 1.1.2+dfsg-6+deb7u18
  • MEDIUM4.4CVE-2016-7908The mcf_fec_do_tx function in hw/net/mcf_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transm…
    from 0, < 1:2.8+dfsg-1
  • MEDIUM4.4CVE-2016-7907The imx_fec_do_tx function in hw/net/imx_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transm…
    from 0, < 1:2.8+dfsg-3
  • MEDIUM4.4CVE-2016-5105The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, u…
    from 0, < 1:2.6+dfsg-2
  • MEDIUM4.4CVE-2016-5238The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a denial of service (out-of-bounds write a…
    from 0, < 1:2.6+dfsg-3
  • MEDIUM4.4CVE-2016-4453The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to cause a denial of service (infinite…
    from 0, < 1:2.6+dfsg-3
  • MEDIUM4.3CVE-2020-29130slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the…
    from 0, < 1:4.1-2
  • MEDIUM4.3CVE-2020-29129ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the t…
    from 0, < 1:4.1-2
  • LOW3.9CVE-2020-29443ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.
    from 0, < 1:5.2+dfsg-11
  • LOW3.9CVE-2020-13361qemu - security update
    from 0, < 1:5.0-6
  • LOW3.9CVE-2020-13361qemu - security update
    from 0, < 1:2.1+dfsg-12+deb8u15
  • LOW3.8CVE-2024-8612A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices.
    from 0
  • LOW3.8CVE-2021-3595An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU.
    from 0, < 1:4.1-2
  • LOW3.8CVE-2021-3594An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU.
    from 0, < 1:4.1-2
  • LOW3.8CVE-2021-3593An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU.
    from 0, < 1:4.1-2
  • LOW3.8CVE-2021-3592An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU.
    from 0, < 1:4.1-2
  • LOW3.8CVE-2020-11947iscsi_aio_ioctl_cb in block/iscsi.c in QEMU 4.1.0 has a heap-based buffer over-read that may disclose unrelated information from process me…
    from 0, < 1:4.2-7
  • LOW3.8CVE-2020-12829qemu - security update
    from 0, < 1:5.0-12
  • LOW3.8CVE-2020-12829qemu - security update
    from 0, < 1:3.1+dfsg-8+deb10u8
  • LOW3.8CVE-2020-16092In QEMU through 5.0.0, an assertion failure can occur in the network packet processing.
    from 0, < 1:5.1+dfsg-1
  • LOW3.8CVE-2019-12068qemu - security update
    from 0, < 1:3.1+dfsg-8+deb10u5
  • LOW3.8CVE-2019-12068qemu - security update
    from 0, < 1:4.1-2
  • LOW3.5CVE-2019-20382QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resultin…
    from 0, < 1:4.2-1
  • LOW3.5CVE-2015-6815The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a net…
    from 0, < 1:2.4+dfsg-2
  • LOW3.3CVE-2025-8860A flaw was found in QEMU in the uefi-vars virtual device.
    from 0, < 1:10.0.3+ds-4
  • LOW3.3CVE-2021-20263A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU.
    from 0, < 1:5.2+dfsg-9
  • LOW3.3CVE-2020-14415oss_write in audio/ossaudio.c in QEMU before 5.0.0 mishandles a buffer position.
    from 0, < 1:5.0-1
  • LOW3.3CVE-2020-15859QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the data's address set to…
    from 0, < 1:5.2+dfsg-1
  • LOW3.3CVE-2020-11869An integer overflow was found in QEMU 4.0.1 through 4.2.0 in the way it implemented ATI VGA emulation.
    from 0, < 1:5.0-1
  • LOW3.3CVE-2019-8934hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/system-id and /proc/de…
    from 0, < 1:4.1-1
  • LOW3.3CVE-2016-9908Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue.
    from 0, < 1:2.8+dfsg-1
  • LOW3.2CVE-2020-14394qemu - security update
    from 0, < 1:5.2+dfsg-11+deb11u3
  • LOW3.2CVE-2020-14394qemu - security update
    from 0, < 1:3.1+dfsg-8+deb10u10
  • LOW3.2CVE-2022-26354A flaw was found in the vhost-vsock device of QEMU.
    from 0, < 1:5.2+dfsg-11+deb11u2
  • LOW3.2CVE-2021-3392A use-after-free flaw was found in the MegaRAID emulator of QEMU.
    from 0, < 1:5.2+dfsg-10
  • LOW3.2CVE-2021-20203An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0.
    from 0, < 1:5.2+dfsg-11+deb11u3
  • LOW3.2CVE-2020-25723A reachable assertion issue was found in the USB EHCI emulation code of QEMU.
    from 0, < 1:5.2+dfsg-1
  • LOW3.2CVE-2020-25743hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync cal…
    from 0
  • LOW3.2CVE-2020-25742pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not return a valid poi…
    from 0
  • LOW3.2CVE-2020-25741fdctrl_write_data in hw/block/fdc.c in QEMU 5.0.0 has a NULL pointer dereference via a NULL block pointer for the current drive.
    from 0
  • LOW3.2CVE-2020-25084QEMU 5.0.0 has a use-after-free in hw/usb/hcd-xhci.c because the usb_packet_map return value is not checked.
    from 0, < 1:5.2+dfsg-1
  • LOW3.2CVE-2020-13362In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue_head field from a…
    from 0, < 1:5.0-6
  • LOW2.5CVE-2020-13659address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.
    from 0, < 1:5.0-6
  • LOW2.3CVE-2020-15469qemu - security update
    from 0, < 1:2.8+dfsg-6+deb9u13
  • LOW2.3CVE-2020-15469qemu - security update
    from 0
  • CVE-2026-41437(無摘要)
    from 0
  • CVE-2026-41439(無摘要)
    from 0
  • CVE-2026-8341(無摘要)
    from 0
  • CVE-2026-41440(無摘要)
    from 0
  • CVE-2026-41435(無摘要)
    from 0
  • CVE-2026-41436(無摘要)
    from 0
  • CVE-2026-41438(無摘要)
    from 0
  • CVE-2026-6502(無摘要)
    from 0
  • CVE-2026-3890(無摘要)
    from 0
  • CVE-2026-5761(無摘要)
    from 0
  • CVE-2026-5744(無摘要)
    from 0
  • CVE-2026-5763(無摘要)
    from 0
  • CVE-2015-7295qemu - security update
    from 0, < 1.1.2+dfsg-6a+deb7u12
  • CVE-2015-7295qemu - security update
    from 0, < 1:2.4+dfsg-4
  • CVE-2015-7295qemu - security update
    from 0, < 1:2.1+dfsg-12+deb8u5a
  • CVE-2015-5225Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a d…
    from 0, < 1:2.4+dfsg-1a
  • CVE-2015-5279Heap-based buffer overflow in the ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows guest OS users to cause a denial…
    from 0, < 1:2.4+dfsg-3
  • CVE-2015-3214qemu - security update
    from 0, < 1:2.4+dfsg-1a
  • CVE-2015-3214qemu - security update
    from 0, < 1:2.1+dfsg-12+deb8u2
  • CVE-2015-4037The slirp_smb function in net/slirp.c in QEMU 2.3.0 and earlier creates temporary files with predictable names, which allows local users to…
    from 0, < 1:2.3+dfsg-5
  • CVE-2015-5166Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completely unplug emulated block devices, which allows local HVM gue…
    from 0, < 1:2.4+dfsg-1a
  • CVE-2015-5165qemu-kvm - security update
    from 0, < 1:2.4+dfsg-1a
  • CVE-2015-5154Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, al…
    from 0, < 1:2.4+dfsg-1a
  • CVE-2015-3209xen - security update
    from 0, < 1:2.1+dfsg-12+deb8u1
  • CVE-2015-3209xen - security update
    from 0, < 1:2.3+dfsg-6
  • CVE-2015-4106QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM…
    from 0, < 1:2.3+dfsg-5
  • CVE-2015-4105Xen 3.3.x through 4.5.x enables logging for PCI MSI-X pass-through error messages, which allows local x86 HVM guests to cause a denial of s…
    from 0, < 1:2.3+dfsg-5
  • CVE-2015-4104Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, which allows local x86 HVM guest users to cause a denial of…
    from 0, < 1:2.3+dfsg-5
  • CVE-2015-4103Xen 3.3.x through 4.5.x does not properly restrict write access to the host MSI message data field, which allows local x86 HVM guest admini…
    from 0, < 1:2.3+dfsg-5
  • CVE-2015-3456virtualbox - security update
    from 0, < 1:2.3+dfsg-3
  • CVE-2015-3456virtualbox - security update
    from 0, < 0.12.5+dfsg-3squeeze5
  • CVE-2014-9718qemu - security update
    from 0, < 1:2.3+dfsg-1
  • CVE-2014-9718qemu - security update
    from 0, < 1:2.1+dfsg-12
  • CVE-2015-2756QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest use…
    from 0, < 1:2.3+dfsg-3
  • CVE-2014-7840The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrar…
    from 0, < 2.1+dfsg-8
  • CVE-2014-8106qemu - security update
    from 0, < 1.1.2+dfsg-6a+deb7u6
  • CVE-2014-8106qemu - security update
    from 0, < 2.1+dfsg-9
  • CVE-2014-5388Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain se…
    from 0, < 2.1+dfsg-5
  • CVE-2014-7815The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel…
    from 0, < 2.1+dfsg-7
  • CVE-2014-3689qemu-kvm - security update
    from 0, < 1.1.2+dfsg-6a+deb7u5
  • CVE-2014-3689qemu-kvm - security update
    from 0, < 2.1+dfsg-6
  • CVE-2014-3640The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sen…
    from 0, < 2.1+dfsg-5
  • CVE-2014-3461hw/usb/bus.c in QEMU 1.6.2 allows remote attackers to execute arbitrary code via crafted savevm data, which triggers a heap-based buffer ov…
    from 0, < 2.1+dfsg-1
  • CVE-2014-0223Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of service (crash) and…
    from 0, < 2.0.0+dfsg-6
  • CVE-2014-0222Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service (crash…
    from 0, < 2.0.0+dfsg-6
  • CVE-2014-0182Heap-based buffer overflow in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 might allow remote attackers to execute a…
    from 0, < 2.1+dfsg-1
  • CVE-2013-6399Array index error in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code…
    from 0, < 2.1+dfsg-1
  • CVE-2013-4542The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via…
    from 0, < 2.1+dfsg-1
  • CVE-2013-4541The usb_device_post_load function in hw/usb/bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted…
    from 0, < 2.1+dfsg-1
  • CVE-2013-4540Buffer overflow in scoop_gpio_handler_update in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a large (1) pr…
    from 0, < 2.1+dfsg-1
  • CVE-2013-4539Multiple buffer overflows in the tsc210x_load function in hw/input/tsc210x.c in QEMU before 1.7.2 might allow remote attackers to execute a…
    from 0, < 2.1+dfsg-1
  • CVE-2013-4538Multiple buffer overflows in the ssd0323_load function in hw/display/ssd0323.c in QEMU before 1.7.2 allow remote attackers to cause a denia…
    from 0, < 2.1+dfsg-1
  • CVE-2013-4537The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen…
    from 0, < 2.1+dfsg-1
  • CVE-2013-4534Buffer overflow in hw/intc/openpic.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrar…
    from 0, < 2.1+dfsg-1
  • CVE-2013-4533Buffer overflow in the pxa2xx_ssp_load function in hw/arm/pxa2xx.c in QEMU before 1.7.2 allows remote attackers to cause a denial of servic…
    from 0, < 2.1+dfsg-1
  • CVE-2013-4531Buffer overflow in target-arm/machine.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbi…
    from 0, < 2.1+dfsg-1
  • CVE-2013-4530Buffer overflow in hw/ssi/pl022.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary c…
    from 0, < 2.1+dfsg-1
  • CVE-2013-4529Buffer overflow in hw/pci/pcie_aer.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitra…
    from 0, < 2.1+dfsg-1
  • CVE-2013-4527Buffer overflow in hw/timer/hpet.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via vectors related to the n…
    from 0, < 2.1+dfsg-1
  • CVE-2013-4526Buffer overflow in hw/ide/ahci.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary c…
    from 0, < 2.1+dfsg-1
  • CVE-2013-4151The virtio_load function in virtio/virtio.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm…
    from 0, < 2.1+dfsg-1
  • CVE-2013-4150The virtio_net_load function in hw/net/virtio-net.c in QEMU 1.5.0 through 1.7.x before 1.7.2 allows remote attackers to cause a denial of s…
    from 0, < 2.1+dfsg-1
  • CVE-2013-4149Buffer overflow in virtio_net_load function in net/virtio-net.c in QEMU 1.3.0 through 1.7.x before 1.7.2 might allow remote attackers to ex…
    from 0, < 2.1+dfsg-1
  • CVE-2013-4148Integer signedness error in the virtio_net_load function in hw/net/virtio-net.c in QEMU 1.x before 1.7.2 allows remote attackers to execute…
    from 0, < 2.1+dfsg-1
  • CVE-2014-3615The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
    from 0, < 2.1+dfsg-5
  • CVE-2014-5263vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the list with the VMSTATE_END_OF_LIST macro, which allows attacker…
    from 0, < 2.1+dfsg-1
  • CVE-2013-4544hw/net/vmxnet3.c in QEMU 2.0.0-rc0, 1.7.1, and earlier allows local guest users to cause a denial of service or possibly execute arbitrary…
    from 0, < 2.0.0+dfsg-1
  • CVE-2014-2894Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecifie…
    from 0, < 2.0.0+dfsg-1
  • CVE-2014-0150qemu-kvm - security update
    from 0, < 0.12.5+dfsg-3squeeze4
  • CVE-2014-0150qemu-kvm - security update
    from 0, < 1.7.0+dfsg-8
  • CVE-2011-4111Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 all…
    from 0, < 0.15.1+dfsg-2
  • CVE-2013-4375The qdisk PV disk backend in qemu-xen in Xen 4.2.x and 4.3.x before 4.3.1, and qemu 1.1 and other versions, allows local HVM guests to caus…
    from 0, < 1.7.0+dfsg-1
  • CVE-2013-4377Use-after-free vulnerability in the virtio-pci implementation in Qemu 1.4.0 through 1.6.0 allows local users to cause a denial of service (…
    from 0, < 1.7.0+dfsg-4
  • CVE-2013-4344qemu-kvm - security update
    from 0, < 1.6.0+dfsg-2
  • CVE-2013-4344qemu-kvm - security update
    from 0, < 1.1.2+dfsg-6a+deb7u3
  • CVE-2013-1922qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk image based on the header, which allows local guest OS administ…
    from 0, < 1.5.0+dfsg-1
  • CVE-2012-6075xen-qemu-dm-4.0 - buffer overflow
    from 0, < 0.12.5+dfsg-3squeeze3
  • CVE-2012-6075xen-qemu-dm-4.0 - buffer overflow
    from 0, < 1.1.2+dfsg-4
  • CVE-2012-3515xen-qemu-dm-4.0 - multiple
    from 0, < 1.1.2+dfsg-1
  • CVE-2012-2652qemu - multiple
    from 0, < 1.1.0+dfsg-1
  • CVE-2012-2652qemu - multiple
    from 0, < 0.12.5+dfsg-3squeeze2
  • CVE-2008-4539Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allo…
    from 0, < 0.9.1+svn20081101-1
  • CVE-2008-5714kvm - several vulnerabilities
    from 0, < 0.9.1-10
  • CVE-2008-2382The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote atta…
    from 0, < 0.9.1-9
  • CVE-2008-4553qemu - denial of service
    from 0, < 0.9.1-6
  • CVE-2008-4553qemu - denial of service
    from 0, < 0.8.2-4etch2
  • CVE-2008-1945QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using…
    from 0, < 0.9.1-5
  • CVE-2008-2004The drive_init function in QEMU 0.9.1 determines the format of a raw disk image based on the header, which allows local guest users to read…
    from 0, < 0.9.1-5
  • CVE-2008-0928qemu - several vulnerabilities
    from 0, < 0.9.1+svn20081207-1
  • CVE-2008-0928qemu - several vulnerabilities
    from 0, < 0.8.2-4etch3
  • CVE-2007-5729The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU t…
    from 0, < 0.9.0-2
  • CVE-2007-1321Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a…
    from 0, < 0.9.0-2
  • CVE-2007-5730Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to execute arbitrary code via craf…
    from 0, < 0.9.0-2
  • CVE-2007-1320qemu - several vulnerabilities
    from 0, < 0.6.1+20050407-1sarge1
  • CVE-2007-1366QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand to the aam instruction, as demonstrated by "aam 0x0," whic…
    from 0, < 0.9.0-2
  • CVE-2007-1322QEMU 0.8.2 allows local users to halt a virtual machine by executing the icebp instruction.
    from 0, < 0.9.0-2
  • CVE-2007-1320qemu - several vulnerabilities
    from 0, < 0.8.2-5lenny1
  • CVE-2007-1320qemu - several vulnerabilities
    from 0, < 0.9.0-2
  • CVE-2026-3195(無摘要)
    from 0
  • CVE-2026-3196(無摘要)
    from 0
  • CVE-2026-3842(無摘要)
    from 0