Show filters
27 Total Results
Displaying 1-10 of 27
Sort by:
Attacker Value
Unknown
CVE-2013-2016
Disclosure Date: December 30, 2019 (last updated November 27, 2024)
A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the matching host's qemu address space and thus increase their privileges on the host.
0
Attacker Value
Unknown
CVE-2014-9718
Disclosure Date: April 21, 2015 (last updated October 05, 2023)
The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have multiple interpretations of a function's return value, which allows guest OS users to cause a host OS denial of service (memory consumption or infinite loop, and system crash) via a PRDT with zero complete sectors, related to the bmdma_prepare_buf and ahci_dma_prepare_buf functions.
0
Attacker Value
Unknown
CVE-2013-4151
Disclosure Date: November 04, 2014 (last updated October 05, 2023)
The virtio_load function in virtio/virtio.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds write.
0
Attacker Value
Unknown
CVE-2013-4541
Disclosure Date: November 04, 2014 (last updated October 05, 2023)
The usb_device_post_load function in hw/usb/bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, related to a negative setup_len or setup_index value.
0
Attacker Value
Unknown
CVE-2013-4533
Disclosure Date: November 04, 2014 (last updated October 05, 2023)
Buffer overflow in the pxa2xx_ssp_load function in hw/arm/pxa2xx.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted s->rx_level value in a savevm image.
0
Attacker Value
Unknown
CVE-2013-4148
Disclosure Date: November 04, 2014 (last updated October 05, 2023)
Integer signedness error in the virtio_net_load function in hw/net/virtio-net.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, which triggers a buffer overflow.
0
Attacker Value
Unknown
CVE-2013-6399
Disclosure Date: November 04, 2014 (last updated October 05, 2023)
Array index error in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image.
0
Attacker Value
Unknown
CVE-2013-4542
Disclosure Date: November 04, 2014 (last updated October 05, 2023)
The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds array access.
0
Attacker Value
Unknown
CVE-2013-4538
Disclosure Date: November 04, 2014 (last updated October 05, 2023)
Multiple buffer overflows in the ssd0323_load function in hw/display/ssd0323.c in QEMU before 1.7.2 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted (1) cmd_len, (2) row, or (3) col values; (4) row_start and row_end values; or (5) col_star and col_end values in a savevm image.
0
Attacker Value
Unknown
CVE-2013-4527
Disclosure Date: November 04, 2014 (last updated October 05, 2023)
Buffer overflow in hw/timer/hpet.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via vectors related to the number of timers.
0