Show filters
414 Total Results
Displaying 91-100 of 414
Sort by:
Attacker Value
Unknown
CVE-2020-25742
Disclosure Date: October 06, 2020 (last updated February 22, 2025)
pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not return a valid pointer.
0
Attacker Value
Unknown
CVE-2020-25741
Disclosure Date: October 02, 2020 (last updated February 22, 2025)
fdctrl_write_data in hw/block/fdc.c in QEMU 5.0.0 has a NULL pointer dereference via a NULL block pointer for the current drive.
0
Attacker Value
Unknown
CVE-2020-25625
Disclosure Date: September 25, 2020 (last updated February 22, 2025)
hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop.
0
Attacker Value
Unknown
CVE-2020-25085
Disclosure Date: September 25, 2020 (last updated February 22, 2025)
QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZE case.
0
Attacker Value
Unknown
CVE-2020-25084
Disclosure Date: September 25, 2020 (last updated February 22, 2025)
QEMU 5.0.0 has a use-after-free in hw/usb/hcd-xhci.c because the usb_packet_map return value is not checked.
0
Attacker Value
Unknown
CVE-2020-14364
Disclosure Date: August 31, 2020 (last updated February 22, 2025)
An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[4096]' in the do_token_in, do_token_out routines. This flaw allows a guest user to crash the QEMU process, resulting in a denial of service, or the potential execution of arbitrary code with the privileges of the QEMU process on the host.
0
Attacker Value
Unknown
CVE-2020-12829
Disclosure Date: August 31, 2020 (last updated February 22, 2025)
In QEMU through 5.0.0, an integer overflow was found in the SM501 display driver implementation. This flaw occurs in the COPY_AREA macro while handling MMIO write operations through the sm501_2d_engine_write() callback. A local attacker could abuse this flaw to crash the QEMU process in sm501_2d_operation() in hw/display/sm501.c on the host, resulting in a denial of service.
0
Attacker Value
Unknown
CVE-2020-14415
Disclosure Date: August 27, 2020 (last updated February 22, 2025)
oss_write in audio/ossaudio.c in QEMU before 5.0.0 mishandles a buffer position.
0
Attacker Value
Unknown
CVE-2020-16092
Disclosure Date: August 11, 2020 (last updated February 21, 2025)
In QEMU through 5.0.0, an assertion failure can occur in the network packet processing. This issue affects the e1000e and vmxnet3 network devices. A malicious guest user/process could use this flaw to abort the QEMU process on the host, resulting in a denial of service condition in net_tx_pkt_add_raw_fragment in hw/net/net_tx_pkt.c.
0
Attacker Value
Unknown
CVE-2020-15863
Disclosure Date: July 28, 2020 (last updated February 21, 2025)
hw/net/xgmac.c in the XGMAC Ethernet controller in QEMU before 07-20-2020 has a buffer overflow. This occurs during packet transmission and affects the highbank and midway emulated machines. A guest user or process could use this flaw to crash the QEMU process on the host, resulting in a denial of service or potential privileged code execution. This was fixed in commit 5519724a13664b43e225ca05351c60b4468e4555.
0