cbcvebase.
CVE-2007-1321
published 2007-10-30

CVE-2007-1321: Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer…

PriorityP425high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.46%
37.3th percentile
Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianqemu< qemu 0.9.0-2 (bookworm)qemu 0.9.0-2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora_core
opensuseopensuse
opensuseopensuse
qemuqemu
qemuqemu>= 0 < 0.9.0-20.9.0-2
qemuqemu>= 0 < 0.9.0-20.9.0-2
qemuqemu>= 0 < 0.9.0-20.9.0-2
qemuqemu>= 0 < 0.9.0-20.9.0-2

CVSS provenance

nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.