Show filters
31 Total Results
Displaying 21-30 of 31
Sort by:
Attacker Value
Unknown

CVE-2011-2212

Disclosure Date: June 21, 2012 (last updated October 04, 2023)
Buffer overflow in the virtio subsystem in qemu-kvm 0.14.0 and earlier allows privileged guest users to cause a denial of service (guest crash) or gain privileges via a crafted indirect descriptor related to "virtqueue in and out requests."
0
Attacker Value
Unknown

CVE-2011-2527

Disclosure Date: June 21, 2012 (last updated October 04, 2023)
The change_process_uid function in os-posix.c in Qemu 0.14.0 and earlier does not properly drop group privileges when the -runas option is used, which allows local guest users to access restricted files on the host.
0
Attacker Value
Unknown

CVE-2010-0297

Disclosure Date: February 12, 2010 (last updated October 04, 2023)
Buffer overflow in the usb_host_handle_control function in the USB passthrough handling implementation in usb-linux.c in QEMU before 0.11.1 allows guest OS users to cause a denial of service (guest OS crash or hang) or possibly execute arbitrary code on the host OS via a crafted USB packet.
0
Attacker Value
Unknown

CVE-2008-2382

Disclosure Date: December 24, 2008 (last updated October 04, 2023)
The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote attackers to cause a denial of service (infinite loop) via a certain message.
0
Attacker Value
Unknown

CVE-2008-0928

Disclosure Date: March 03, 2008 (last updated October 04, 2023)
Qemu 0.9.1 and earlier does not perform range checks for block device read or write requests, which allows guest host users with root privileges to access arbitrary memory and escape the virtual machine.
0
Attacker Value
Unknown

CVE-2007-1321

Disclosure Date: October 30, 2007 (last updated October 04, 2023)
Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.
0
Attacker Value
Unknown

CVE-2007-5730

Disclosure Date: October 30, 2007 (last updated October 04, 2023)
Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to execute arbitrary code via crafted data in the "net socket listen" option, aka QEMU "net socket" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the correct identifier for the individual net socket listen vulnerability.
0
Attacker Value
Unknown

CVE-2007-5729

Disclosure Date: October 30, 2007 (last updated October 04, 2023)
The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_TCNT register, which triggers a heap-based buffer overflow in the slirp library, aka NE2000 "mtu" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the correct identifier for the mtu overflow vulnerability.
0
Attacker Value
Unknown

CVE-2007-1322

Disclosure Date: May 02, 2007 (last updated October 04, 2023)
QEMU 0.8.2 allows local users to halt a virtual machine by executing the icebp instruction.
0
Attacker Value
Unknown

CVE-2007-1320

Disclosure Date: May 02, 2007 (last updated October 04, 2023)
Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark non-existent regions as dirty," aka the "bitblt" heap overflow.
0