Количество 47
Количество 47
GHSA-rxh4-5vqx-xjq8
A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.
GHSA-9p8r-v33g-4939
A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.
BDU:2022-04641
Уязвимость функции cursor_alloc() эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2022-03597
Уязвимость функции qxl_cursor() эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю выполнить произвольный код
SUSE-SU-2023:3015-1
Security update for qemu
ALT-PU-2021-2713
ALT-PU-2021-2713: package `qemu` update to version 6.1.0-alt1
ALT-PU-2021-3363
ALT-PU-2021-3363: package `qemu` update to version 6.1.0-alt2
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-rxh4-5vqx-xjq8 A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process. | CVSS3: 8.2 | 1% Низкий | больше 4 лет назад | |
GHSA-9p8r-v33g-4939 A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process. | CVSS3: 8.8 | 0% Низкий | больше 4 лет назад | |
BDU:2022-04641 Уязвимость функции cursor_alloc() эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код | CVSS3: 8.2 | 1% Низкий | больше 4 лет назад | |
BDU:2022-03597 Уязвимость функции qxl_cursor() эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю выполнить произвольный код | CVSS3: 8.8 | 0% Низкий | больше 4 лет назад | |
SUSE-SU-2023:3015-1 Security update for qemu | около 3 лет назад | |||
ALT-PU-2021-2713 ALT-PU-2021-2713: package `qemu` update to version 6.1.0-alt1 | CVSS3: 8.5 | около 5 лет назад | ||
ALT-PU-2021-3363 ALT-PU-2021-3363: package `qemu` update to version 6.1.0-alt2 | CVSS3: 8.5 | почти 5 лет назад |
Уязвимостей на страницу