Show filters
26 Total Results
Displaying 1-10 of 26
Sort by:
Attacker Value
Unknown

CVE-2015-8817

Disclosure Date: December 29, 2016 (last updated November 25, 2024)
QEMU (aka Quick Emulator) built to use 'address_space_translate' to map an address to a MemoryRegionSection is vulnerable to an OOB r/w access issue. It could occur while doing pci_dma_read/write calls. Affects QEMU versions >= 1.6.0 and <= 2.3.1. A privileged user inside guest could use this flaw to crash the guest instance resulting in DoS.
0
Attacker Value
Unknown

CVE-2014-9718

Disclosure Date: April 21, 2015 (last updated October 05, 2023)
The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have multiple interpretations of a function's return value, which allows guest OS users to cause a host OS denial of service (memory consumption or infinite loop, and system crash) via a PRDT with zero complete sectors, related to the bmdma_prepare_buf and ahci_dma_prepare_buf functions.
0
Attacker Value
Unknown

CVE-2013-4151

Disclosure Date: November 04, 2014 (last updated October 05, 2023)
The virtio_load function in virtio/virtio.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds write.
0
Attacker Value
Unknown

CVE-2013-4541

Disclosure Date: November 04, 2014 (last updated October 05, 2023)
The usb_device_post_load function in hw/usb/bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, related to a negative setup_len or setup_index value.
0
Attacker Value
Unknown

CVE-2013-4533

Disclosure Date: November 04, 2014 (last updated October 05, 2023)
Buffer overflow in the pxa2xx_ssp_load function in hw/arm/pxa2xx.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted s->rx_level value in a savevm image.
0
Attacker Value
Unknown

CVE-2013-4148

Disclosure Date: November 04, 2014 (last updated October 05, 2023)
Integer signedness error in the virtio_net_load function in hw/net/virtio-net.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, which triggers a buffer overflow.
0
Attacker Value
Unknown

CVE-2013-6399

Disclosure Date: November 04, 2014 (last updated October 05, 2023)
Array index error in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image.
0
Attacker Value
Unknown

CVE-2013-4542

Disclosure Date: November 04, 2014 (last updated October 05, 2023)
The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds array access.
0
Attacker Value
Unknown

CVE-2013-4538

Disclosure Date: November 04, 2014 (last updated October 05, 2023)
Multiple buffer overflows in the ssd0323_load function in hw/display/ssd0323.c in QEMU before 1.7.2 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted (1) cmd_len, (2) row, or (3) col values; (4) row_start and row_end values; or (5) col_star and col_end values in a savevm image.
0
Attacker Value
Unknown

CVE-2013-4527

Disclosure Date: November 04, 2014 (last updated October 05, 2023)
Buffer overflow in hw/timer/hpet.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via vectors related to the number of timers.
0