cbcvebase.
CVE-2015-8743
published 2016-12-29

CVE-2015-8743: QEMU (aka Quick Emulator) built with the NE2000 device emulation support is vulnerable to an OOB r/w access issue. It could occur while performing 'ioport' r/w…

PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHIHAN
EPSS
0.45%
36.3th percentile
QEMU (aka Quick Emulator) built with the NE2000 device emulation support is vulnerable to an OOB r/w access issue. It could occur while performing 'ioport' r/w operations. A privileged (CAP_SYS_RAWIO) user/process could use this flaw to leak or corrupt QEMU memory bytes.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianqemu< qemu 1:2.5+dfsg-2 (bookworm)qemu 1:2.5+dfsg-2 (bookworm)
qemuqemu<= 2.5.1
qemuqemu>= 0 < 1:2.5+dfsg-21:2.5+dfsg-2
qemuqemu>= 0 < 1:2.5+dfsg-21:2.5+dfsg-2
qemuqemu>= 0 < 1:2.5+dfsg-21:2.5+dfsg-2
qemuqemu>= 0 < 1:2.5+dfsg-21:2.5+dfsg-2
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.222.0.0+dfsg-2ubuntu1.22

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu6.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.