Show filters
27 Total Results
Displaying 21-27 of 27
Sort by:
Attacker Value
Unknown

CVE-2011-2212

Disclosure Date: June 21, 2012 (last updated October 04, 2023)
Buffer overflow in the virtio subsystem in qemu-kvm 0.14.0 and earlier allows privileged guest users to cause a denial of service (guest crash) or gain privileges via a crafted indirect descriptor related to "virtqueue in and out requests."
0
Attacker Value
Unknown

CVE-2011-2527

Disclosure Date: June 21, 2012 (last updated October 04, 2023)
The change_process_uid function in os-posix.c in Qemu 0.14.0 and earlier does not properly drop group privileges when the -runas option is used, which allows local guest users to access restricted files on the host.
0
Attacker Value
Unknown

CVE-2010-0297

Disclosure Date: February 12, 2010 (last updated October 04, 2023)
Buffer overflow in the usb_host_handle_control function in the USB passthrough handling implementation in usb-linux.c in QEMU before 0.11.1 allows guest OS users to cause a denial of service (guest OS crash or hang) or possibly execute arbitrary code on the host OS via a crafted USB packet.
0
Attacker Value
Unknown

CVE-2008-5714

Disclosure Date: December 24, 2008 (last updated October 04, 2023)
Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote attackers to guess the VNC password, which is limited to seven characters where eight was intended.
0
Attacker Value
Unknown

CVE-2008-4553

Disclosure Date: October 15, 2008 (last updated October 04, 2023)
qemu-make-debian-root in qemu 0.9.1-5 on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on temporary files and directories.
0
Attacker Value
Unknown

CVE-2008-2004

Disclosure Date: May 12, 2008 (last updated October 04, 2023)
The drive_init function in QEMU 0.9.1 determines the format of a raw disk image based on the header, which allows local guest users to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted.
0
Attacker Value
Unknown

CVE-2008-0928

Disclosure Date: March 03, 2008 (last updated October 04, 2023)
Qemu 0.9.1 and earlier does not perform range checks for block device read or write requests, which allows guest host users with root privileges to access arbitrary memory and escape the virtual machine.
0