Vulnerabilities > Qemu > Qemu > 7.1.0

DATE CVE VULNERABILITY TITLE RISK
2023-03-23 CVE-2023-1544 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device.
local
low complexity
qemu fedoraproject CWE-770
6.3
2022-11-29 CVE-2022-4144 Out-of-bounds Read vulnerability in multiple products
An out-of-bounds read flaw was found in the QXL display device emulation in QEMU.
local
low complexity
qemu fedoraproject redhat CWE-125
6.5
2022-11-07 CVE-2022-3872 Off-by-one Error vulnerability in Qemu
An off-by-one read/write issue was found in the SDHCI device of QEMU.
network
low complexity
qemu CWE-193
8.6
2022-10-17 CVE-2022-3165 Integer Underflow (Wrap or Wraparound) vulnerability in multiple products
An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format.
network
low complexity
qemu fedoraproject CWE-191
6.5
2022-09-13 CVE-2022-2962 Improper Synchronization vulnerability in Qemu
A DMA reentrancy issue was found in the Tulip device emulation in QEMU.
local
low complexity
qemu CWE-662
7.8
2022-08-26 CVE-2022-0216 Use After Free vulnerability in multiple products
A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU.
local
low complexity
qemu fedoraproject CWE-416
4.4
2021-06-02 CVE-2021-3544 Memory Leak vulnerability in multiple products
Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0.
local
low complexity
qemu debian CWE-401
6.5
2021-06-02 CVE-2021-3545 Use of Uninitialized Resource vulnerability in multiple products
An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0.
local
low complexity
qemu debian CWE-908
6.5
2021-06-02 CVE-2021-3546 Out-of-bounds Write vulnerability in multiple products
An out-of-bounds write vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0.
local
low complexity
qemu debian CWE-787
8.2
2021-05-28 CVE-2020-35504 NULL Pointer Dereference vulnerability in multiple products
A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0.
local
low complexity
qemu fedoraproject debian CWE-476
2.1