Количество 43
Количество 43
RLSA-2024:6964
Moderate: virt:rhel and virt-devel:rhel security update
ELSA-2024-6964
ELSA-2024-6964: virt:ol and virt-devel:rhel security update (MODERATE)
RLSA-2024:9136
Moderate: qemu-kvm security update
ELSA-2024-9136
ELSA-2024-9136: qemu-kvm security update (MODERATE)
CVE-2024-3446
A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest user to crash the QEMU process on the host, resulting in a denial of service or allow arbitrary code execution within the context of the QEMU process on the host.
CVE-2024-3446
A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest user to crash the QEMU process on the host, resulting in a denial of service or allow arbitrary code execution within the context of the QEMU process on the host.
CVE-2024-3446
A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest user to crash the QEMU process on the host, resulting in a denial of service or allow arbitrary code execution within the context of the QEMU process on the host.
CVE-2024-3446
A double free vulnerability was found in QEMU virtio devices (virtio-g ...
GHSA-rgvf-j3x5-6277
A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest to crash the QEMU process on the host, resulting in a denial of service or allow arbitrary code execution within the context of the QEMU process on the host.
BDU:2024-03304
Уязвимость эмулятора аппаратного обеспечения QEMU, связанная с ошибкой повторного освобождения памяти, позволяющая нарушителю выполнить произвольный код
ROS-20240627-03
Уязвимость qemu
CVE-2024-7383
A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This issue allows a man-in-the-middle attack on NBD traffic.
CVE-2024-7383
A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This issue allows a man-in-the-middle attack on NBD traffic.
CVE-2024-7383
A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This issue allows a man-in-the-middle attack on NBD traffic.
CVE-2024-7383
CVE-2024-7383
A flaw was found in libnbd. The client did not always correctly verify ...
CVE-2024-7409
A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.
CVE-2024-7409
A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.
CVE-2024-7409
A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.
CVE-2024-7409
A flaw was found in the QEMU NBD Server. This vulnerability allows a d ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
RLSA-2024:6964 Moderate: virt:rhel and virt-devel:rhel security update | 9 месяцев назад | |||
ELSA-2024-6964 ELSA-2024-6964: virt:ol and virt-devel:rhel security update (MODERATE) | больше 1 года назад | |||
RLSA-2024:9136 Moderate: qemu-kvm security update | 11 месяцев назад | |||
ELSA-2024-9136 ELSA-2024-9136: qemu-kvm security update (MODERATE) | около 1 года назад | |||
CVE-2024-3446 A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest user to crash the QEMU process on the host, resulting in a denial of service or allow arbitrary code execution within the context of the QEMU process on the host. | CVSS3: 8.2 | 0% Низкий | почти 2 года назад | |
CVE-2024-3446 A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest user to crash the QEMU process on the host, resulting in a denial of service or allow arbitrary code execution within the context of the QEMU process on the host. | CVSS3: 8.2 | 0% Низкий | почти 2 года назад | |
CVE-2024-3446 A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest user to crash the QEMU process on the host, resulting in a denial of service or allow arbitrary code execution within the context of the QEMU process on the host. | CVSS3: 8.2 | 0% Низкий | почти 2 года назад | |
CVE-2024-3446 A double free vulnerability was found in QEMU virtio devices (virtio-g ... | CVSS3: 8.2 | 0% Низкий | почти 2 года назад | |
GHSA-rgvf-j3x5-6277 A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest to crash the QEMU process on the host, resulting in a denial of service or allow arbitrary code execution within the context of the QEMU process on the host. | CVSS3: 8.2 | 0% Низкий | почти 2 года назад | |
BDU:2024-03304 Уязвимость эмулятора аппаратного обеспечения QEMU, связанная с ошибкой повторного освобождения памяти, позволяющая нарушителю выполнить произвольный код | CVSS3: 8.2 | 0% Низкий | почти 2 года назад | |
ROS-20240627-03 Уязвимость qemu | CVSS3: 8.2 | 0% Низкий | больше 1 года назад | |
CVE-2024-7383 A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This issue allows a man-in-the-middle attack on NBD traffic. | CVSS3: 7.4 | 0% Низкий | больше 1 года назад | |
CVE-2024-7383 A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This issue allows a man-in-the-middle attack on NBD traffic. | CVSS3: 7.4 | 0% Низкий | больше 1 года назад | |
CVE-2024-7383 A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This issue allows a man-in-the-middle attack on NBD traffic. | CVSS3: 7.4 | 0% Низкий | больше 1 года назад | |
CVSS3: 7.4 | 0% Низкий | больше 1 года назад | ||
CVE-2024-7383 A flaw was found in libnbd. The client did not always correctly verify ... | CVSS3: 7.4 | 0% Низкий | больше 1 года назад | |
CVE-2024-7409 A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline. | CVSS3: 7.5 | 2% Низкий | больше 1 года назад | |
CVE-2024-7409 A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline. | CVSS3: 7.5 | 2% Низкий | больше 1 года назад | |
CVE-2024-7409 A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline. | CVSS3: 7.5 | 2% Низкий | больше 1 года назад | |
CVE-2024-7409 A flaw was found in the QEMU NBD Server. This vulnerability allows a d ... | CVSS3: 7.5 | 2% Низкий | больше 1 года назад |
Уязвимостей на страницу