Логотип exploitDog
bind:"CVE-2024-8354" OR bind:"CVE-2025-11234"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-8354" OR bind:"CVE-2025-11234"

Количество 27

Количество 27

oracle-oval логотип

ELSA-2026-50118

около 1 месяца назад

ELSA-2026-50118: virt:kvm_utils3 security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2024-8354

больше 1 года назад

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2024-8354

больше 1 года назад

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2024-8354

больше 1 года назад

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2024-8354

7 месяцев назад

Qemu-kvm: usb: assertion failure in usb_ep_get()

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2024-8354

больше 1 года назад

A flaw was found in QEMU. An assertion failure was present in the usb_ ...

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2025-11234

6 месяцев назад

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-11234

6 месяцев назад

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-11234

6 месяцев назад

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-11234

6 месяцев назад

Qemu-kvm: vnc websocket handshake use-after-free

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-11234

6 месяцев назад

A flaw was found in QEMU. If the QIOChannelWebsock object is freed whi ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx3p-5m4j-rhw8

больше 1 года назад

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.

CVSS3: 4.7
EPSS: Низкий
fstec логотип

BDU:2024-08773

больше 1 года назад

Уязвимость функции usb_ep_get() (hw/net/core.c) эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0436-1

около 2 месяцев назад

Security update for qemu

EPSS: Низкий
rocky логотип

RLSA-2026:1831

около 2 месяцев назад

Moderate: qemu-kvm security update

EPSS: Низкий
github логотип

GHSA-hm8v-8c3v-cxfq

6 месяцев назад

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2026-1831

около 2 месяцев назад

ELSA-2026-1831: qemu-kvm security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2025-16063

6 месяцев назад

Уязвимость эмулятора аппаратного обеспечения QEMU, связанная с использованием памяти после её освобождения, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20251105-12

5 месяцев назад

Уязвимость qemu

CVSS3: 5.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025:20171-1

3 месяца назад

Security update for qemu

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2026-50118

ELSA-2026-50118: virt:kvm_utils3 security update (MODERATE)

около 1 месяца назад
ubuntu логотип
CVE-2024-8354

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-8354

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-8354

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2024-8354

Qemu-kvm: usb: assertion failure in usb_ep_get()

CVSS3: 5.5
0%
Низкий
7 месяцев назад
debian логотип
CVE-2024-8354

A flaw was found in QEMU. An assertion failure was present in the usb_ ...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2025-11234

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2025-11234

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-11234

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
msrc логотип
CVE-2025-11234

Qemu-kvm: vnc websocket handshake use-after-free

CVSS3: 7.5
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-11234

A flaw was found in QEMU. If the QIOChannelWebsock object is freed whi ...

CVSS3: 7.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-xx3p-5m4j-rhw8

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.

CVSS3: 4.7
0%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-08773

Уязвимость функции usb_ep_get() (hw/net/core.c) эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.5
0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2026:0436-1

Security update for qemu

0%
Низкий
около 2 месяцев назад
rocky логотип
RLSA-2026:1831

Moderate: qemu-kvm security update

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-hm8v-8c3v-cxfq

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
oracle-oval логотип
ELSA-2026-1831

ELSA-2026-1831: qemu-kvm security update (MODERATE)

около 2 месяцев назад
fstec логотип
BDU:2025-16063

Уязвимость эмулятора аппаратного обеспечения QEMU, связанная с использованием памяти после её освобождения, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
6 месяцев назад
redos логотип
ROS-20251105-12

Уязвимость qemu

CVSS3: 5.5
0%
Низкий
5 месяцев назад
suse-cvrf логотип
openSUSE-SU-2025:20171-1

Security update for qemu

3 месяца назад

Уязвимостей на страницу