Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2017-7506

Disclosure Date: July 18, 2017 (last updated November 26, 2024)
spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.
0
Attacker Value
Unknown

CVE-2013-4282

Disclosure Date: November 02, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.
0
Attacker Value
Unknown

CVE-2013-4130

Disclosure Date: August 20, 2013 (last updated October 05, 2023)
The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE before 0.12.4 do not properly perform ring loops, which might allow remote attackers to cause a denial of service (reachable assertion and server exit) by triggering a network error.
0