Логотип exploitDog
bind:"CVE-2021-3750" OR bind:"CVE-2023-3301"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2021-3750" OR bind:"CVE-2023-3301"

Количество 32

Количество 32

oracle-oval логотип

ELSA-2023-6980

больше 1 года назад

ELSA-2023-6980: virt:ol and virt-devel:rhel security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
redos логотип

ROS-20240606-01

около 1 года назад

Множественные уязвимости qemu

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3444-1

почти 2 года назад

Security update for qemu

EPSS: Низкий
ubuntu логотип

CVE-2023-3301

почти 2 года назад

A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.

CVSS3: 5.6
EPSS: Низкий
redhat логотип

CVE-2023-3301

около 2 лет назад

A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.

CVSS3: 5.6
EPSS: Низкий
nvd логотип

CVE-2023-3301

почти 2 года назад

A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.

CVSS3: 5.6
EPSS: Низкий
msrc логотип

CVE-2023-3301

9 месяцев назад

CVSS3: 5.6
EPSS: Низкий
debian логотип

CVE-2023-3301

почти 2 года назад

A flaw was found in QEMU. The async nature of hot-unplug enables a rac ...

CVSS3: 5.6
EPSS: Низкий
ubuntu логотип

CVE-2021-3750

около 3 лет назад

A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.

CVSS3: 8.2
EPSS: Низкий
redhat логотип

CVE-2021-3750

почти 5 лет назад

A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2021-3750

около 3 лет назад

A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.

CVSS3: 8.2
EPSS: Низкий
msrc логотип

CVE-2021-3750

около 3 лет назад

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2021-3750

около 3 лет назад

A DMA reentrancy issue was found in the USB EHCI controller emulation ...

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-cp42-9j6q-v649

почти 2 года назад

A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.

CVSS3: 5.6
EPSS: Низкий
fstec логотип

BDU:2024-04418

почти 2 года назад

Уязвимость интерфейса virtio-net эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-2v3x-7c37-r5r2

около 3 лет назад

A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.

CVSS3: 8.2
EPSS: Низкий
fstec логотип

BDU:2024-04421

около 3 лет назад

Уязвимость эмулятора аппаратного обеспечения QEMU, связанная с ошибками при работе с памятью, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3234-1

почти 2 года назад

Security update for qemu

EPSS: Низкий
oracle-oval логотип

ELSA-2024-12152

больше 1 года назад

ELSA-2024-12152: virt:kvm_utils1 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-12835

больше 1 года назад

ELSA-2023-12835: qemu security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2023-6980

ELSA-2023-6980: virt:ol and virt-devel:rhel security, bug fix, and enhancement update (MODERATE)

больше 1 года назад
redos логотип
ROS-20240606-01

Множественные уязвимости qemu

CVSS3: 7.5
около 1 года назад
suse-cvrf логотип
SUSE-SU-2023:3444-1

Security update for qemu

почти 2 года назад
ubuntu логотип
CVE-2023-3301

A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.

CVSS3: 5.6
0%
Низкий
почти 2 года назад
redhat логотип
CVE-2023-3301

A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.

CVSS3: 5.6
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-3301

A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.

CVSS3: 5.6
0%
Низкий
почти 2 года назад
msrc логотип
CVSS3: 5.6
0%
Низкий
9 месяцев назад
debian логотип
CVE-2023-3301

A flaw was found in QEMU. The async nature of hot-unplug enables a rac ...

CVSS3: 5.6
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2021-3750

A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.

CVSS3: 8.2
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2021-3750

A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.

CVSS3: 7.5
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-3750

A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.

CVSS3: 8.2
0%
Низкий
около 3 лет назад
msrc логотип
CVSS3: 8.2
0%
Низкий
около 3 лет назад
debian логотип
CVE-2021-3750

A DMA reentrancy issue was found in the USB EHCI controller emulation ...

CVSS3: 8.2
0%
Низкий
около 3 лет назад
github логотип
GHSA-cp42-9j6q-v649

A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.

CVSS3: 5.6
0%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-04418

Уязвимость интерфейса virtio-net эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.6
0%
Низкий
почти 2 года назад
github логотип
GHSA-2v3x-7c37-r5r2

A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.

CVSS3: 8.2
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2024-04421

Уязвимость эмулятора аппаратного обеспечения QEMU, связанная с ошибками при работе с памятью, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:3234-1

Security update for qemu

почти 2 года назад
oracle-oval логотип
ELSA-2024-12152

ELSA-2024-12152: virt:kvm_utils1 security update (MODERATE)

больше 1 года назад
oracle-oval логотип
ELSA-2023-12835

ELSA-2023-12835: qemu security update (MODERATE)

больше 1 года назад

Уязвимостей на страницу