Show filters
27 Total Results
Displaying 21-27 of 27
Sort by:
Attacker Value
Unknown

CVE-2011-2212

Disclosure Date: June 21, 2012 (last updated October 04, 2023)
Buffer overflow in the virtio subsystem in qemu-kvm 0.14.0 and earlier allows privileged guest users to cause a denial of service (guest crash) or gain privileges via a crafted indirect descriptor related to "virtqueue in and out requests."
0
Attacker Value
Unknown

CVE-2011-2527

Disclosure Date: June 21, 2012 (last updated October 04, 2023)
The change_process_uid function in os-posix.c in Qemu 0.14.0 and earlier does not properly drop group privileges when the -runas option is used, which allows local guest users to access restricted files on the host.
0
Attacker Value
Unknown

CVE-2010-0297

Disclosure Date: February 12, 2010 (last updated October 04, 2023)
Buffer overflow in the usb_host_handle_control function in the USB passthrough handling implementation in usb-linux.c in QEMU before 0.11.1 allows guest OS users to cause a denial of service (guest OS crash or hang) or possibly execute arbitrary code on the host OS via a crafted USB packet.
0
Attacker Value
Unknown

CVE-2008-2382

Disclosure Date: December 24, 2008 (last updated October 04, 2023)
The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote attackers to cause a denial of service (infinite loop) via a certain message.
0
Attacker Value
Unknown

CVE-2008-1945

Disclosure Date: August 08, 2008 (last updated October 04, 2023)
QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different format, a related issue to CVE-2008-2004.
0
Attacker Value
Unknown

CVE-2008-0928

Disclosure Date: March 03, 2008 (last updated October 04, 2023)
Qemu 0.9.1 and earlier does not perform range checks for block device read or write requests, which allows guest host users with root privileges to access arbitrary memory and escape the virtual machine.
0
Attacker Value
Unknown

CVE-2007-6227

Disclosure Date: December 04, 2007 (last updated October 04, 2023)
QEMU 0.9.0 allows local users of a Windows XP SP2 guest operating system to overwrite the TranslationBlock (code_gen_buffer) buffer, and probably have unspecified other impacts related to an "overflow," via certain Windows executable programs, as demonstrated by qemu-dos.com.
0