Vulnerabilities > Qemu
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-12-08 | CVE-2020-27821 | Out-of-bounds Write vulnerability in multiple products A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. | 6.0 |
2020-12-04 | CVE-2020-28916 | Infinite Loop vulnerability in multiple products hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address. | 5.5 |
2020-12-02 | CVE-2020-25723 | A reachable assertion issue was found in the USB EHCI emulation code of QEMU. | 3.2 |
2020-11-30 | CVE-2020-25624 | Out-of-bounds Read vulnerability in multiple products hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values obtained from the host controller driver. | 5.0 |
2020-11-06 | CVE-2020-27617 | Reachable Assertion vulnerability in multiple products eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure. | 6.5 |
2020-11-06 | CVE-2020-27616 | Incorrect Calculation vulnerability in Qemu 4.2.1 ati_2d_blt in hw/display/ati_2d.c in QEMU 4.2.1 can encounter an outside-limits situation in a calculation. | 6.5 |
2020-10-16 | CVE-2020-24352 | Out-of-bounds Write vulnerability in Qemu An issue was discovered in QEMU through 5.1.0. | 5.5 |
2020-10-06 | CVE-2020-25743 | NULL Pointer Dereference vulnerability in multiple products hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call. | 3.2 |
2020-10-06 | CVE-2020-25742 | NULL Pointer Dereference vulnerability in Qemu pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not return a valid pointer. | 3.2 |
2020-10-02 | CVE-2020-25741 | NULL Pointer Dereference vulnerability in Qemu 5.0.0 fdctrl_write_data in hw/block/fdc.c in QEMU 5.0.0 has a NULL pointer dereference via a NULL block pointer for the current drive. | 3.2 |