Логотип exploitDog
bind:"CVE-2021-3750" OR bind:"CVE-2021-3507" OR bind:"CVE-2021-3611" OR bind:"CVE-2021-4158"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2021-3750" OR bind:"CVE-2021-3507" OR bind:"CVE-2021-3611" OR bind:"CVE-2021-4158"

Количество 65

Количество 65

rocky логотип

RLSA-2022:7967

около 3 лет назад

Moderate: qemu-kvm security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2022-7967

около 3 лет назад

ELSA-2022-7967: qemu-kvm security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2021-3750

почти 4 года назад

A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.

CVSS3: 8.2
EPSS: Низкий
redhat логотип

CVE-2021-3750

больше 5 лет назад

A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2021-3750

почти 4 года назад

A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.

CVSS3: 8.2
EPSS: Низкий
msrc логотип

CVE-2021-3750

больше 3 лет назад

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2021-3750

почти 4 года назад

A DMA reentrancy issue was found in the USB EHCI controller emulation ...

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-2v3x-7c37-r5r2

почти 4 года назад

A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.

CVSS3: 8.2
EPSS: Низкий
fstec логотип

BDU:2024-04421

почти 4 года назад

Уязвимость эмулятора аппаратного обеспечения QEMU, связанная с ошибками при работе с памятью, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2023-6980

около 2 лет назад

ELSA-2023-6980: virt:ol and virt-devel:rhel security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2021-3507

почти 5 лет назад

A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileged guest user could use this flaw to crash the QEMU process on the host resulting in DoS scenario, or potential information leakage from the host memory.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2021-3507

почти 5 лет назад

A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileged guest user could use this flaw to crash the QEMU process on the host resulting in DoS scenario, or potential information leakage from the host memory.

CVSS3: 4.6
EPSS: Низкий
nvd логотип

CVE-2021-3507

почти 5 лет назад

A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileged guest user could use this flaw to crash the QEMU process on the host resulting in DoS scenario, or potential information leakage from the host memory.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2021-3507

4 месяца назад

A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileged guest user could use this flaw to crash the QEMU process on the host resulting in DoS scenario, or potential information leakage from the host memory.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2021-3507

почти 5 лет назад

A heap buffer overflow was found in the floppy disk emulator of QEMU u ...

CVSS3: 6.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1395-1

почти 2 года назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4056-1

больше 2 лет назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3444-1

больше 2 лет назад

Security update for qemu

EPSS: Низкий
github логотип

GHSA-m99h-7jcp-j7w9

больше 3 лет назад

A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileged guest user could use this flaw to crash the QEMU process on the host resulting in DoS scenario, or potential information leakage from the host memory.

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2023-01705

почти 5 лет назад

Уязвимость функции fdctrl_transfer_handler() компонента hw/block/fdc.c эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2022:7967

Moderate: qemu-kvm security, bug fix, and enhancement update

около 3 лет назад
oracle-oval логотип
ELSA-2022-7967

ELSA-2022-7967: qemu-kvm security, bug fix, and enhancement update (MODERATE)

около 3 лет назад
ubuntu логотип
CVE-2021-3750

A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.

CVSS3: 8.2
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2021-3750

A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.

CVSS3: 7.5
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2021-3750

A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.

CVSS3: 8.2
0%
Низкий
почти 4 года назад
msrc логотип
CVSS3: 8.2
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2021-3750

A DMA reentrancy issue was found in the USB EHCI controller emulation ...

CVSS3: 8.2
0%
Низкий
почти 4 года назад
github логотип
GHSA-2v3x-7c37-r5r2

A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.

CVSS3: 8.2
0%
Низкий
почти 4 года назад
fstec логотип
BDU:2024-04421

Уязвимость эмулятора аппаратного обеспечения QEMU, связанная с ошибками при работе с памятью, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
почти 4 года назад
oracle-oval логотип
ELSA-2023-6980

ELSA-2023-6980: virt:ol and virt-devel:rhel security, bug fix, and enhancement update (MODERATE)

около 2 лет назад
ubuntu логотип
CVE-2021-3507

A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileged guest user could use this flaw to crash the QEMU process on the host resulting in DoS scenario, or potential information leakage from the host memory.

CVSS3: 6.1
0%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-3507

A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileged guest user could use this flaw to crash the QEMU process on the host resulting in DoS scenario, or potential information leakage from the host memory.

CVSS3: 4.6
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-3507

A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileged guest user could use this flaw to crash the QEMU process on the host resulting in DoS scenario, or potential information leakage from the host memory.

CVSS3: 6.1
0%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-3507

A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileged guest user could use this flaw to crash the QEMU process on the host resulting in DoS scenario, or potential information leakage from the host memory.

CVSS3: 6.1
0%
Низкий
4 месяца назад
debian логотип
CVE-2021-3507

A heap buffer overflow was found in the floppy disk emulator of QEMU u ...

CVSS3: 6.1
0%
Низкий
почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2024:1395-1

Security update for qemu

почти 2 года назад
suse-cvrf логотип
SUSE-SU-2023:4056-1

Security update for qemu

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:3444-1

Security update for qemu

больше 2 лет назад
github логотип
GHSA-m99h-7jcp-j7w9

A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileged guest user could use this flaw to crash the QEMU process on the host resulting in DoS scenario, or potential information leakage from the host memory.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2023-01705

Уязвимость функции fdctrl_transfer_handler() компонента hw/block/fdc.c эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании

CVSS3: 6.1
0%
Низкий
почти 5 лет назад

Уязвимостей на страницу