Vulnerabilities > Qemu > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-06-02 CVE-2020-27661 Divide By Zero vulnerability in Qemu
A divide-by-zero issue was found in dwc2_handle_packet in hw/usb/hcd-dwc2.c in the hcd-dwc2 USB host controller emulation of QEMU.
local
low complexity
qemu CWE-369
6.5
2021-06-02 CVE-2019-12067 NULL Pointer Dereference vulnerability in multiple products
The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null.
local
low complexity
qemu debian fedoraproject redhat CWE-476
6.5
2021-06-02 CVE-2020-35503 A NULL pointer dereference flaw was found in the megasas-gen2 SCSI host bus adapter emulation of QEMU in versions before and including 6.0.
local
low complexity
qemu fedoraproject
6.0
2021-06-02 CVE-2021-3544 Memory Leak vulnerability in multiple products
Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0.
local
low complexity
qemu debian CWE-401
6.5
2021-06-02 CVE-2021-3545 Use of Uninitialized Resource vulnerability in multiple products
An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0.
local
low complexity
qemu debian CWE-908
6.5
2021-05-28 CVE-2020-35504 NULL Pointer Dereference vulnerability in multiple products
A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0.
local
low complexity
qemu fedoraproject debian CWE-476
6.0
2021-05-28 CVE-2020-35505 NULL Pointer Dereference vulnerability in multiple products
A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0.
local
low complexity
qemu debian CWE-476
4.4
2021-05-28 CVE-2020-35506 Unspecified vulnerability in Qemu
A use-after-free vulnerability was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0 during the handling of the 'Information Transfer' command (CMD_TI).
local
low complexity
qemu
6.7
2021-05-26 CVE-2021-20196 A NULL pointer dereference flaw was found in the floppy disk emulator of QEMU.
local
low complexity
qemu debian
6.5
2021-05-26 CVE-2021-3527 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
A flaw was found in the USB redirector device (usb-redir) of QEMU.
local
low complexity
qemu redhat debian CWE-770
5.5