cbcvebase.
CVE-2010-0430
published 2013-12-27

CVE-2010-0430: libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 and possibly other products…

PriorityP430high7.4CVSS 2.0
AVAACMAuSCCICAC
EPSS
0.49%
38.5th percentile
libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 and possibly other products, allows guest OS users to read from or write to arbitrary QEMU memory by modifying the address that is used by Cairo for memory mappings.

Affected

2 ranges
VendorProductVersion rangeFixed in
debianspice
redhatenterprise_virtualization_hypervisor<= 5.4-2.1

CVSS provenance

nvdv2.07.4HIGHAV:A/AC:M/Au:S/C:C/I:C/A:C
vendor_debian7.4LOW
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.