Search CVE reports


Toggle filters

441 – 450 of 476 results


CVE-2012-0029

Medium priority

Some fixes available 4 of 6

Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000.c) in qemu-kvm 0.12, and possibly other versions, allows guest OS users to cause a denial of service (QEMU crash) and possibly execute...

3 affected packages

kvm, qemu, qemu-kvm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kvm
qemu
qemu-kvm
Show less packages

CVE-2011-4111

Medium priority
Not affected

Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary...

1 affected package

qemu-kvm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu-kvm
Show less packages

CVE-2011-2527

Medium priority
Fixed

The change_process_uid function in os-posix.c in Qemu 0.14.0 and earlier does not properly drop group privileges when the -runas option is used, which allows local guest users to access restricted files on the host.

1 affected package

qemu-kvm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu-kvm
Show less packages

CVE-2011-2512

Medium priority
Fixed

The virtio_queue_notify in qemu-kvm 0.14.0 and earlier does not properly validate the virtqueue number, which allows guest users to cause a denial of service (guest crash) and possibly execute arbitrary code via a negative number...

1 affected package

qemu-kvm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu-kvm
Show less packages

CVE-2011-2212

Medium priority
Fixed

Buffer overflow in the virtio subsystem in qemu-kvm 0.14.0 and earlier allows privileged guest users to cause a denial of service (guest crash) or gain privileges via a crafted indirect descriptor related to "virtqueue in and out...

1 affected package

qemu-kvm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu-kvm
Show less packages

CVE-2011-1751

Medium priority
Fixed

The pciej_write function in hw/acpi_piix4.c in the PIIX4 Power Management emulation in qemu-kvm does not check if a device is hotpluggable before unplugging the PCI-ISA bridge, which allows privileged guest users to cause a denial...

1 affected package

qemu-kvm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu-kvm
Show less packages

CVE-2011-1750

Medium priority
Fixed

Multiple heap-based buffer overflows in the virtio-blk driver (hw/virtio-blk.c) in qemu-kvm 0.14.0 allow local guest users to cause a denial of service (guest crash) and possibly gain privileges via a (1) write request to the...

1 affected package

qemu-kvm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu-kvm
Show less packages

CVE-2011-0011

Medium priority
Fixed

qemu-kvm before 0.11.0 disables VNC authentication when the password is cleared, which allows remote attackers to bypass authentication and establish VNC sessions.

1 affected package

qemu-kvm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu-kvm
Show less packages

CVE-2010-2784

Negligible priority
Ignored

The subpage MMIO initialization functionality in the subpage_register function in exec.c in QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and KVM 83, does not properly...

2 affected packages

kvm, qemu-kvm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kvm
qemu-kvm
Show less packages

CVE-2010-0431

Medium priority
Not affected

QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and KVM 83, does not properly validate guest QXL driver pointers, which allows guest OS users to cause a denial of service...

2 affected packages

kvm, qemu-kvm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kvm
qemu-kvm
Show less packages