cbcvebase.
CVE-2016-9578
published 2018-07-27

CVE-2016-9578: A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted…

PriorityP339high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
2.49%
82.9th percentile
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.

Affected

19 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianspice< spice 0.12.8-2.1 (bookworm)spice 0.12.8-2.1 (bookworm)
red_hatspice
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
spice_projectspice< 0.13.900.13.90
spice_projectspice>= 0 < 0.12.8-2.10.12.8-2.1
spice_projectspice>= 0 < 0.12.8-2.10.12.8-2.1
spice_projectspice>= 0 < 0.12.8-2.10.12.8-2.1
spice_projectspice>= 0 < 0.12.8-2.10.12.8-2.1

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.