cbcvebase.
CVE-2016-9577
published 2018-07-27

CVE-2016-9577: A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE…

PriorityP352high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
3.84%
89.0th percentile
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.

Affected

19 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianspice< spice 0.12.8-2.1 (bookworm)spice 0.12.8-2.1 (bookworm)
red_hatspice
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
spice_projectspice< 0.13.900.13.90
spice_projectspice>= 0 < 0.12.8-2.10.12.8-2.1
spice_projectspice>= 0 < 0.12.8-2.10.12.8-2.1
spice_projectspice>= 0 < 0.12.8-2.10.12.8-2.1
spice_projectspice>= 0 < 0.12.8-2.10.12.8-2.1

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.