Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2020-24165

Disclosure Date: August 28, 2023 (last updated May 15, 2024)
An issue was discovered in TCG Accelerator in QEMU 4.2.0, allows local attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS). Note: This is disputed as a bug and not a valid security issue by multiple third parties.
Attacker Value
Unknown

CVE-2020-15859

Disclosure Date: July 21, 2020 (last updated February 21, 2025)
QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the data's address set to the e1000e's MMIO address.
Attacker Value
Unknown

CVE-2020-13800

Disclosure Date: June 04, 2020 (last updated February 21, 2025)
ati-vga in hw/display/ati.c in QEMU 4.2.0 allows guest OS users to trigger infinite recursion via a crafted mm_index value during an ati_mm_read or ati_mm_write call.
Attacker Value
Unknown

CVE-2020-13659

Disclosure Date: June 02, 2020 (last updated February 21, 2025)
address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.
Attacker Value
Unknown

CVE-2020-11102

Disclosure Date: April 06, 2020 (last updated February 21, 2025)
hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not validated against the r/w data length.
Attacker Value
Unknown

CVE-2020-7211

Disclosure Date: January 21, 2020 (last updated February 21, 2025)
tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows.
Attacker Value
Unknown

CVE-2020-7039

Disclosure Date: January 16, 2020 (last updated February 21, 2025)
tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.
Attacker Value
Unknown

CVE-2013-4375

Disclosure Date: January 19, 2014 (last updated October 05, 2023)
The qdisk PV disk backend in qemu-xen in Xen 4.2.x and 4.3.x before 4.3.1, and qemu 1.1 and other versions, allows local HVM guests to cause a denial of service (domain grant reference consumption) via unspecified vectors.
0