Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown
CVE-2021-20201
Disclosure Date: May 28, 2021 (last updated November 28, 2024)
A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection.
0
Attacker Value
Unknown
CVE-2020-14355
Disclosure Date: October 07, 2020 (last updated February 22, 2025)
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.
0
Attacker Value
Unknown
CVE-2019-3813
Disclosure Date: February 04, 2019 (last updated November 27, 2024)
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.
0
Attacker Value
Unknown
CVE-2018-10893
Disclosure Date: September 11, 2018 (last updated November 27, 2024)
Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.
0
Attacker Value
Unknown
CVE-2018-10873
Disclosure Date: August 17, 2018 (last updated November 27, 2024)
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.
0
Attacker Value
Unknown
CVE-2016-9578
Disclosure Date: July 27, 2018 (last updated November 08, 2023)
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.
0
Attacker Value
Unknown
CVE-2016-9577
Disclosure Date: July 27, 2018 (last updated November 08, 2023)
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.
0
Attacker Value
Unknown
CVE-2017-12194
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.
0
Attacker Value
Unknown
CVE-2017-7506
Disclosure Date: July 18, 2017 (last updated November 26, 2024)
spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.
0
Attacker Value
Unknown
CVE-2016-3066
Disclosure Date: June 06, 2017 (last updated November 26, 2024)
The spice-gtk widget allows remote authenticated users to obtain information from the host clipboard.
0