Show filters
22 Total Results
Displaying 11-20 of 22
Sort by:
Attacker Value
Unknown

CVE-2013-4539

Disclosure Date: November 04, 2014 (last updated October 05, 2023)
Multiple buffer overflows in the tsc210x_load function in hw/input/tsc210x.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted (1) precision, (2) nextprecision, (3) function, or (4) nextfunction value in a savevm image.
0
Attacker Value
Unknown

CVE-2013-4529

Disclosure Date: November 04, 2014 (last updated October 05, 2023)
Buffer overflow in hw/pci/pcie_aer.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large log_num value in a savevm image.
0
Attacker Value
Unknown

CVE-2013-4534

Disclosure Date: November 04, 2014 (last updated October 05, 2023)
Buffer overflow in hw/intc/openpic.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via vectors related to IRQDest elements.
0
Attacker Value
Unknown

CVE-2013-4537

Disclosure Date: November 04, 2014 (last updated October 05, 2023)
The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a savevm image.
0
Attacker Value
Unknown

CVE-2013-4540

Disclosure Date: November 04, 2014 (last updated October 05, 2023)
Buffer overflow in scoop_gpio_handler_update in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a large (1) prev_level, (2) gpio_level, or (3) gpio_dir value in a savevm image.
0
Attacker Value
Unknown

CVE-2013-4526

Disclosure Date: November 04, 2014 (last updated October 05, 2023)
Buffer overflow in hw/ide/ahci.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via vectors related to migrating ports.
0
Attacker Value
Unknown

CVE-2013-4531

Disclosure Date: November 04, 2014 (last updated October 05, 2023)
Buffer overflow in target-arm/machine.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a negative value in cpreg_vmstate_array_len in a savevm image.
0
Attacker Value
Unknown

CVE-2014-2894

Disclosure Date: April 23, 2014 (last updated October 05, 2023)
Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact via a SMART EXECUTE OFFLINE command that triggers a buffer underflow and memory corruption.
0
Attacker Value
Unknown

CVE-2014-0150

Disclosure Date: April 18, 2014 (last updated October 05, 2023)
Integer overflow in the virtio_net_handle_mac function in hw/net/virtio-net.c in QEMU 2.0 and earlier allows local guest users to execute arbitrary code via a MAC addresses table update request, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2011-1751

Disclosure Date: June 21, 2012 (last updated October 04, 2023)
The pciej_write function in hw/acpi_piix4.c in the PIIX4 Power Management emulation in qemu-kvm does not check if a device is hotpluggable before unplugging the PCI-ISA bridge, which allows privileged guest users to cause a denial of service (guest crash) and possibly execute arbitrary code by sending a crafted value to the 0xae08 (PCI_EJ_BASE) I/O port, which leads to a use-after-free related to "active qemu timers."
0