Количество 64
Количество 64
CVE-2021-3975
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged client with a read-only connection could use this flaw to perform a denial of service attack by causing the libvirt daemon to crash.
CVE-2021-3975
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister( ...
CVE-2021-4207
A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.
CVE-2021-4207
A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.
CVE-2021-4207
A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.
CVE-2021-4207
CVE-2021-4207
A flaw was found in the QXL display device emulation in QEMU. A double ...
ALT-PU-2021-2713
ALT-PU-2021-2713: package `qemu` update to version 6.1.0-alt1
ALT-PU-2021-3363
ALT-PU-2021-3363: package `qemu` update to version 6.1.0-alt2
GHSA-pg89-46xq-98vv
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged client with a read-only connection could use this flaw to perform a denial of service attack by causing the libvirt daemon to crash.
ELSA-2022-9668
ELSA-2022-9668: libvirt libvirt-python security update (IMPORTANT)
ALT-PU-2021-1465
ALT-PU-2021-1465: package `libvirt` update to version 7.1.0-alt1
GHSA-9p8r-v33g-4939
A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.
BDU:2022-03597
Уязвимость функции qxl_cursor() эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю выполнить произвольный код
SUSE-SU-2022:0128-1
Security update for libvirt
SUSE-SU-2022:0045-2
Security update for libvirt
SUSE-SU-2022:0045-1
Security update for libvirt
SUSE-SU-2022:0042-1
Security update for libvirt
SUSE-SU-2022:0041-1
Security update for libvirt
SUSE-SU-2022:0032-1
Security update for libvirt
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-3975 A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged client with a read-only connection could use this flaw to perform a denial of service attack by causing the libvirt daemon to crash. | CVSS3: 6.5 | 2% Низкий | около 4 лет назад | |
CVE-2021-3975 A use-after-free flaw was found in libvirt. The qemuMonitorUnregister( ... | CVSS3: 6.5 | 2% Низкий | около 4 лет назад | |
CVE-2021-4207 A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process. | CVSS3: 8.2 | 0% Низкий | больше 4 лет назад | |
CVE-2021-4207 A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process. | CVSS3: 7.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-4207 A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process. | CVSS3: 8.2 | 0% Низкий | больше 4 лет назад | |
CVSS3: 8.2 | 0% Низкий | около 2 лет назад | ||
CVE-2021-4207 A flaw was found in the QXL display device emulation in QEMU. A double ... | CVSS3: 8.2 | 0% Низкий | больше 4 лет назад | |
ALT-PU-2021-2713 ALT-PU-2021-2713: package `qemu` update to version 6.1.0-alt1 | CVSS3: 8.5 | около 5 лет назад | ||
ALT-PU-2021-3363 ALT-PU-2021-3363: package `qemu` update to version 6.1.0-alt2 | CVSS3: 8.5 | почти 5 лет назад | ||
GHSA-pg89-46xq-98vv A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged client with a read-only connection could use this flaw to perform a denial of service attack by causing the libvirt daemon to crash. | CVSS3: 6.5 | 2% Низкий | около 4 лет назад | |
ELSA-2022-9668 ELSA-2022-9668: libvirt libvirt-python security update (IMPORTANT) | 2% Низкий | около 4 лет назад | ||
ALT-PU-2021-1465 ALT-PU-2021-1465: package `libvirt` update to version 7.1.0-alt1 | CVSS3: 6.5 | 2% Низкий | больше 5 лет назад | |
GHSA-9p8r-v33g-4939 A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process. | CVSS3: 8.8 | 0% Низкий | больше 4 лет назад | |
BDU:2022-03597 Уязвимость функции qxl_cursor() эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю выполнить произвольный код | CVSS3: 8.8 | 0% Низкий | больше 4 лет назад | |
SUSE-SU-2022:0128-1 Security update for libvirt | больше 4 лет назад | |||
SUSE-SU-2022:0045-2 Security update for libvirt | больше 4 лет назад | |||
SUSE-SU-2022:0045-1 Security update for libvirt | больше 4 лет назад | |||
SUSE-SU-2022:0042-1 Security update for libvirt | больше 4 лет назад | |||
SUSE-SU-2022:0041-1 Security update for libvirt | больше 4 лет назад | |||
SUSE-SU-2022:0032-1 Security update for libvirt | больше 4 лет назад |
Уязвимостей на страницу