Логотип exploitDog
bind:"CVE-2021-4206" OR bind:"CVE-2021-4207" OR bind:"CVE-2022-26353" OR bind:"CVE-2022-26354"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2021-4206" OR bind:"CVE-2021-4207" OR bind:"CVE-2022-26353" OR bind:"CVE-2022-26354"

Количество 50

Количество 50

oracle-oval логотип

ELSA-2022-9432

около 3 лет назад

ELSA-2022-9432: qemu security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2021-4207

около 3 лет назад

A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.

CVSS3: 8.2
EPSS: Низкий
redhat логотип

CVE-2021-4207

около 3 лет назад

A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2021-4207

около 3 лет назад

A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.

CVSS3: 8.2
EPSS: Низкий
msrc логотип

CVE-2021-4207

10 месяцев назад

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2021-4207

около 3 лет назад

A flaw was found in the QXL display device emulation in QEMU. A double ...

CVSS3: 8.2
EPSS: Низкий
oracle-oval логотип

ELSA-2022-9460

около 3 лет назад

ELSA-2022-9460: kvm_utils security update (IMPORTANT)

EPSS: Низкий
github логотип

GHSA-9p8r-v33g-4939

около 3 лет назад

A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2022-03597

около 3 лет назад

Уязвимость функции qxl_cursor() эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2022-26354

больше 3 лет назад

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 3.2
EPSS: Низкий
redhat логотип

CVE-2022-26354

больше 3 лет назад

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 2.5
EPSS: Низкий
nvd логотип

CVE-2022-26354

больше 3 лет назад

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 3.2
EPSS: Низкий
msrc логотип

CVE-2022-26354

11 месяцев назад

CVSS3: 3.2
EPSS: Низкий
debian логотип

CVE-2022-26354

больше 3 лет назад

A flaw was found in the vhost-vsock device of QEMU. In case of error, ...

CVSS3: 3.2
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3015-1

почти 2 года назад

Security update for qemu

EPSS: Низкий
ubuntu логотип

CVE-2022-26353

больше 3 лет назад

A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other unexpected results. Affected QEMU version: 6.2.0.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-26353

больше 3 лет назад

A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other unexpected results. Affected QEMU version: 6.2.0.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-26353

больше 3 лет назад

A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other unexpected results. Affected QEMU version: 6.2.0.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-26353

11 месяцев назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-26353

больше 3 лет назад

A flaw was found in the virtio-net device of QEMU. This flaw was inadv ...

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2022-9432

ELSA-2022-9432: qemu security update (IMPORTANT)

около 3 лет назад
ubuntu логотип
CVE-2021-4207

A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.

CVSS3: 8.2
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2021-4207

A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2021-4207

A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.

CVSS3: 8.2
0%
Низкий
около 3 лет назад
msrc логотип
CVSS3: 8.2
0%
Низкий
10 месяцев назад
debian логотип
CVE-2021-4207

A flaw was found in the QXL display device emulation in QEMU. A double ...

CVSS3: 8.2
0%
Низкий
около 3 лет назад
oracle-oval логотип
ELSA-2022-9460

ELSA-2022-9460: kvm_utils security update (IMPORTANT)

около 3 лет назад
github логотип
GHSA-9p8r-v33g-4939

A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2022-03597

Уязвимость функции qxl_cursor() эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-26354

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 3.2
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-26354

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 2.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-26354

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 3.2
0%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 3.2
0%
Низкий
11 месяцев назад
debian логотип
CVE-2022-26354

A flaw was found in the vhost-vsock device of QEMU. In case of error, ...

CVSS3: 3.2
0%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:3015-1

Security update for qemu

почти 2 года назад
ubuntu логотип
CVE-2022-26353

A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other unexpected results. Affected QEMU version: 6.2.0.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-26353

A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other unexpected results. Affected QEMU version: 6.2.0.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-26353

A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other unexpected results. Affected QEMU version: 6.2.0.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 7.5
0%
Низкий
11 месяцев назад
debian логотип
CVE-2022-26353

A flaw was found in the virtio-net device of QEMU. This flaw was inadv ...

CVSS3: 7.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу