Show filters
25 Total Results
Displaying 21-25 of 25
Sort by:
Attacker Value
Unknown
CVE-2011-2212
Disclosure Date: June 21, 2012 (last updated October 04, 2023)
Buffer overflow in the virtio subsystem in qemu-kvm 0.14.0 and earlier allows privileged guest users to cause a denial of service (guest crash) or gain privileges via a crafted indirect descriptor related to "virtqueue in and out requests."
0
Attacker Value
Unknown
CVE-2011-2527
Disclosure Date: June 21, 2012 (last updated October 04, 2023)
The change_process_uid function in os-posix.c in Qemu 0.14.0 and earlier does not properly drop group privileges when the -runas option is used, which allows local guest users to access restricted files on the host.
0
Attacker Value
Unknown
CVE-2010-0297
Disclosure Date: February 12, 2010 (last updated October 04, 2023)
Buffer overflow in the usb_host_handle_control function in the USB passthrough handling implementation in usb-linux.c in QEMU before 0.11.1 allows guest OS users to cause a denial of service (guest OS crash or hang) or possibly execute arbitrary code on the host OS via a crafted USB packet.
0
Attacker Value
Unknown
CVE-2008-2382
Disclosure Date: December 24, 2008 (last updated October 04, 2023)
The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote attackers to cause a denial of service (infinite loop) via a certain message.
0
Attacker Value
Unknown
CVE-2008-0928
Disclosure Date: March 03, 2008 (last updated October 04, 2023)
Qemu 0.9.1 and earlier does not perform range checks for block device read or write requests, which allows guest host users with root privileges to access arbitrary memory and escape the virtual machine.
0