Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-9845

Опубликовано: 29 дек. 2016
Источник: nvd
CVSS3: 6.5
CVSS2: 2.1
EPSS Низкий

Описание

QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET_INFO' command. A guest user/process could use this flaw to leak contents of the host memory bytes.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*
Версия до 2.8.0 (исключая)
cpe:2.3:a:qemu:qemu:2.8.0:rc0:*:*:*:*:*:*
cpe:2.3:a:qemu:qemu:2.8.0:rc1:*:*:*:*:*:*
cpe:2.3:a:qemu:qemu:2.8.0:rc2:*:*:*:*:*:*

EPSS

Процентиль: 27%
0.00095
Низкий

6.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 9 лет назад

QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET_INFO' command. A guest user/process could use this flaw to leak contents of the host memory bytes.

CVSS3: 4.1
redhat
больше 9 лет назад

QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET_INFO' command. A guest user/process could use this flaw to leak contents of the host memory bytes.

CVSS3: 6.5
debian
около 9 лет назад

QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator su ...

CVSS3: 6.5
github
больше 3 лет назад

QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET_INFO' command. A guest user/process could use this flaw to leak contents of the host memory bytes.

fstec
около 9 лет назад

Уязвимость эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании или оказать иное воздействие на систему

EPSS

Процентиль: 27%
0.00095
Низкий

6.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-200