Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2016-2150

Disclosure Date: June 09, 2016 (last updated November 25, 2024)
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
0
Attacker Value
Unknown

CVE-2016-0749

Disclosure Date: June 09, 2016 (last updated November 25, 2024)
The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecting to a guest VM, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2015-5261

Disclosure Date: June 07, 2016 (last updated November 25, 2024)
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.
0
Attacker Value
Unknown

CVE-2015-5260

Disclosure Date: June 07, 2016 (last updated November 25, 2024)
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter.
0
Attacker Value
Unknown

CVE-2015-3247

Disclosure Date: September 08, 2015 (last updated October 05, 2023)
Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-4282

Disclosure Date: November 02, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.
0
Attacker Value
Unknown

CVE-2013-4324

Disclosure Date: October 03, 2013 (last updated October 05, 2023)
spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
0
Attacker Value
Unknown

CVE-2013-4130

Disclosure Date: August 20, 2013 (last updated October 05, 2023)
The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE before 0.12.4 do not properly perform ring loops, which might allow remote attackers to cause a denial of service (reachable assertion and server exit) by triggering a network error.
0