Логотип exploitDog
bind:"CVE-2020-25650" OR bind:"CVE-2020-25651" OR bind:"CVE-2020-25652" OR bind:"CVE-2020-25653"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2020-25650" OR bind:"CVE-2020-25651" OR bind:"CVE-2020-25652" OR bind:"CVE-2020-25653"

Количество 31

Количество 31

suse-cvrf логотип

openSUSE-SU-2021:2614-1

больше 4 лет назад

Security update for spice-vdagent

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2803-1

больше 4 лет назад

Security update for spice-vdagent

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2766-1

больше 4 лет назад

Security update for spice-vdagent

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2614-1

больше 4 лет назад

Security update for spice-vdagent

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:3268-1

около 5 лет назад

Security update for spice-vdagent

EPSS: Низкий
rocky логотип

RLSA-2021:1791

больше 4 лет назад

Moderate: spice-vdagent security and bug fix update

EPSS: Низкий
oracle-oval логотип

ELSA-2021-1791

больше 4 лет назад

ELSA-2021-1791: spice-vdagent security and bug fix update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2020-25650

около 5 лет назад

A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/spice-vdagent-sock` could use this flaw to perform a memory denial of service for spice-vdagentd or even other processes in the VM system. The highest threat from this vulnerability is to system availability. This flaw affects spice-vdagent versions 0.20 and previous versions.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-25650

больше 5 лет назад

A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/spice-vdagent-sock` could use this flaw to perform a memory denial of service for spice-vdagentd or even other processes in the VM system. The highest threat from this vulnerability is to system availability. This flaw affects spice-vdagent versions 0.20 and previous versions.

CVSS3: 3.3
EPSS: Низкий
nvd логотип

CVE-2020-25650

около 5 лет назад

A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/spice-vdagent-sock` could use this flaw to perform a memory denial of service for spice-vdagentd or even other processes in the VM system. The highest threat from this vulnerability is to system availability. This flaw affects spice-vdagent versions 0.20 and previous versions.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2020-25650

около 4 лет назад

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2020-25650

около 5 лет назад

A flaw was found in the way the spice-vdagentd daemon handled file tra ...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-f637-jpfq-3wv2

больше 3 лет назад

A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/spice-vdagent-sock` could use this flaw to perform a memory denial of service for spice-vdagentd or even other processes in the VM system. The highest threat from this vulnerability is to system availability. This flaw affects spice-vdagent versions 0.20 and previous versions.

EPSS: Низкий
ubuntu логотип

CVE-2020-25651

около 5 лет назад

A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of service. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior.

CVSS3: 6.4
EPSS: Низкий
redhat логотип

CVE-2020-25651

больше 5 лет назад

A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of service. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2020-25651

около 5 лет назад

A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of service. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior.

CVSS3: 6.4
EPSS: Низкий
msrc логотип

CVE-2020-25651

около 4 лет назад

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2020-25651

около 5 лет назад

A flaw was found in the SPICE file transfer protocol. File data from t ...

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-gjj5-vggp-jg8p

больше 3 лет назад

A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of service. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior.

EPSS: Низкий
ubuntu логотип

CVE-2020-25653

около 5 лет назад

A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw may allow an unprivileged local guest user to become the active agent for spice-vdagentd, possibly resulting in a denial of service or information leakage from the host. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior.

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
openSUSE-SU-2021:2614-1

Security update for spice-vdagent

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:2803-1

Security update for spice-vdagent

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:2766-1

Security update for spice-vdagent

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:2614-1

Security update for spice-vdagent

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2020:3268-1

Security update for spice-vdagent

около 5 лет назад
rocky логотип
RLSA-2021:1791

Moderate: spice-vdagent security and bug fix update

больше 4 лет назад
oracle-oval логотип
ELSA-2021-1791

ELSA-2021-1791: spice-vdagent security and bug fix update (MODERATE)

больше 4 лет назад
ubuntu логотип
CVE-2020-25650

A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/spice-vdagent-sock` could use this flaw to perform a memory denial of service for spice-vdagentd or even other processes in the VM system. The highest threat from this vulnerability is to system availability. This flaw affects spice-vdagent versions 0.20 and previous versions.

CVSS3: 5.5
0%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-25650

A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/spice-vdagent-sock` could use this flaw to perform a memory denial of service for spice-vdagentd or even other processes in the VM system. The highest threat from this vulnerability is to system availability. This flaw affects spice-vdagent versions 0.20 and previous versions.

CVSS3: 3.3
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-25650

A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/spice-vdagent-sock` could use this flaw to perform a memory denial of service for spice-vdagentd or even other processes in the VM system. The highest threat from this vulnerability is to system availability. This flaw affects spice-vdagent versions 0.20 and previous versions.

CVSS3: 5.5
0%
Низкий
около 5 лет назад
msrc логотип
CVSS3: 5.5
0%
Низкий
около 4 лет назад
debian логотип
CVE-2020-25650

A flaw was found in the way the spice-vdagentd daemon handled file tra ...

CVSS3: 5.5
0%
Низкий
около 5 лет назад
github логотип
GHSA-f637-jpfq-3wv2

A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/spice-vdagent-sock` could use this flaw to perform a memory denial of service for spice-vdagentd or even other processes in the VM system. The highest threat from this vulnerability is to system availability. This flaw affects spice-vdagent versions 0.20 and previous versions.

0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2020-25651

A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of service. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior.

CVSS3: 6.4
0%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-25651

A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of service. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior.

CVSS3: 6.4
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-25651

A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of service. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior.

CVSS3: 6.4
0%
Низкий
около 5 лет назад
msrc логотип
CVSS3: 6.4
0%
Низкий
около 4 лет назад
debian логотип
CVE-2020-25651

A flaw was found in the SPICE file transfer protocol. File data from t ...

CVSS3: 6.4
0%
Низкий
около 5 лет назад
github логотип
GHSA-gjj5-vggp-jg8p

A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of service. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior.

0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2020-25653

A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw may allow an unprivileged local guest user to become the active agent for spice-vdagentd, possibly resulting in a denial of service or information leakage from the host. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior.

CVSS3: 6.3
0%
Низкий
около 5 лет назад

Уязвимостей на страницу