Vulnerabilities > Qemu

DATE CVE VULNERABILITY TITLE RISK
2017-03-20 CVE-2017-6058 Classic Buffer Overflow vulnerability in Qemu
Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 device, allows remote attackers to cause a denial of service (out-of-bounds access and QEMU process crash) via vectors related to VLAN stripping.
network
low complexity
qemu CWE-120
7.5
2017-03-20 CVE-2017-5987 Infinite Loop vulnerability in multiple products
The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local OS guest privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors involving the transfer mode register during multi block transfer.
local
low complexity
qemu debian CWE-835
5.5
2017-03-16 CVE-2017-5857 Memory Leak vulnerability in Qemu
Memory leak in the virgl_cmd_resource_unref function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_UNREF commands sent without detaching the backing storage beforehand.
local
low complexity
qemu CWE-401
6.5
2017-03-16 CVE-2017-5856 Memory Leak vulnerability in multiple products
Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) via MegaRAID Firmware Interface (MFI) commands with the sglist size set to a value over 2 Gb.
local
low complexity
qemu debian CWE-401
6.5
2017-03-16 CVE-2017-5667 Out-of-bounds Read vulnerability in multiple products
The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds heap access and crash) or execute arbitrary code on the QEMU host via vectors involving the data transfer length.
local
low complexity
qemu debian CWE-125
6.5
2017-03-15 CVE-2017-5898 Integer Overflow or Wraparound vulnerability in multiple products
Integer overflow in the emulated_apdu_from_guest function in usb/dev-smartcard-reader.c in Quick Emulator (Qemu), when built with the CCID Card device emulator support, allows local users to cause a denial of service (application crash) via a large Application Protocol Data Units (APDU) unit.
local
low complexity
qemu suse CWE-190
5.5
2017-03-15 CVE-2017-5579 Memory Leak vulnerability in multiple products
Memory leak in the serial_exit_core function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
local
low complexity
qemu debian CWE-401
6.5
2017-03-15 CVE-2017-5578 Memory Leak vulnerability in Qemu
Memory leak in the virtio_gpu_resource_attach_backing function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_ATTACH_BACKING commands.
local
low complexity
qemu CWE-401
6.5
2017-03-15 CVE-2017-5552 Memory Leak vulnerability in Qemu
Memory leak in the virgl_resource_attach_backing function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_ATTACH_BACKING commands.
local
low complexity
qemu CWE-401
6.5
2017-03-15 CVE-2017-5526 Memory Leak vulnerability in multiple products
Memory leak in hw/audio/es1370.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
local
low complexity
qemu debian CWE-401
6.5