cbcvebase.

Debian Qemu vulnerabilities

424 known vulnerabilities affecting debian/qemu.

Total CVEs
424
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH85MEDIUM226LOW102UNKNOWN1

Vulnerabilities

Page 18 of 22
CVE-2016-8909P4MEDIUMCVSS 6.0fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-8909 [MEDIUM] CVE-2016-8909: qemu - The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator)... The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via an entry with the same value for buffer length and pointer position. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-1) bullseye: resolved (fixed in 1:2.8+dfsg-1) forky: resolved
debian
CVE-2016-8578P4MEDIUMCVSS 6.0fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-8578 [MEDIUM] CVE-2016-8578: qemu - The v9fs_iov_vunmarshal function in fsdev/9p-iov-marshal.c in QEMU (aka Quick Em... The v9fs_iov_vunmarshal function in fsdev/9p-iov-marshal.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) by sending an empty string parameter to a 9P operation. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-1) bullseye: resolved (fixed in 1:2.8+dfsg-1) forky: resol
debian
CVE-2016-8667P4MEDIUMCVSS 6.0fixed in qemu 1:2.8+dfsg-4 (bookworm)2016
CVE-2016-8667 [MEDIUM] CVE-2016-8667: qemu - The rc4030_write function in hw/dma/rc4030.c in QEMU (aka Quick Emulator) allows... The rc4030_write function in hw/dma/rc4030.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via a large interval timer reload value. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-4) bullseye: resolved (fixed in 1:2.8+dfsg-4) forky: resolved (fixed in 1:2.8+dfsg-4) sid:
debian
CVE-2016-9105P4MEDIUMCVSS 6.0fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-9105 [MEDIUM] CVE-2016-9105: qemu - Memory leak in the v9fs_link function in hw/9pfs/9p.c in QEMU (aka Quick Emulato... Memory leak in the v9fs_link function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors involving a reference to the source fid object. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-1) bullseye: resolved (fixed in 1:2.8+dfsg-1) forky: resolved (fixed in 1:2.8+dfsg-1) si
debian
CVE-2015-7549P4MEDIUMCVSS 6.0fixed in qemu 1:2.5+dfsg-1 (bookworm)2015
CVE-2015-7549 [MEDIUM] CVE-2015-7549: qemu - The MSI-X MMIO support in hw/pci/msix.c in QEMU (aka Quick Emulator) allows loca... The MSI-X MMIO support in hw/pci/msix.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) by leveraging failure to define the .write method. Scope: local bookworm: resolved (fixed in 1:2.5+dfsg-1) bullseye: resolved (fixed in 1:2.5+dfsg-1) forky: resolved (fixed in 1:2.5+df
debian
CVE-2016-7422P4MEDIUMCVSS 6.0fixed in qemu 1:2.7+dfsg-1 (bookworm)2016
CVE-2016-7422 [MEDIUM] CVE-2016-7422: qemu - The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulato... The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via a large I/O descriptor buffer length value. Scope: local bookworm: resolved (fixed in 1:2.7+dfsg-1) bullseye: resolved (fixed in 1:2.7+dfsg-1) forky: resolved (fixed in
debian
CVE-2016-8669P4MEDIUMCVSS 6.0fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-8669 [MEDIUM] CVE-2016-8669: qemu - The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emu... The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via vectors involving a value of divider greater than baud base. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-1) bullseye: resolved (fixed in 1:2.8+dfsg-1) forky: r
debian
CVE-2018-18438P4MEDIUMCVSS 5.5fixed in qemu 1:3.1+dfsg-1 (bookworm)2018
CVE-2018-18438 [MEDIUM] CVE-2018-18438: qemu - Qemu has integer overflows because IOReadHandler and its associated functions us... Qemu has integer overflows because IOReadHandler and its associated functions use a signed integer data type for a size value. Scope: local bookworm: resolved (fixed in 1:3.1+dfsg-1) bullseye: resolved (fixed in 1:3.1+dfsg-1) forky: resolved (fixed in 1:3.1+dfsg-1) sid: resolved (fixed in 1:3.1+dfsg-1) trixie: resolved (fixed in 1:3.1+dfsg-1)
debian
CVE-2017-5987P4MEDIUMCVSS 5.5fixed in qemu 1:2.8+dfsg-3 (bookworm)2017
CVE-2017-5987 [MEDIUM] CVE-2017-5987: qemu - The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quic... The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local OS guest privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors involving the transfer mode register during multi block transfer. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-3) bullseye: resolved (fixed in 1:2.8+dfs
debian
CVE-2017-9503P4LOWCVSS 5.5fixed in qemu 1:2.10.0-1 (bookworm)2017
CVE-2017-9503 [MEDIUM] CVE-2017-9503: qemu - QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter... QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving megasas command processing. Scope: local bookworm: resolved (fixed in 1:2.10.0-1) bullseye: resolved (fixed in 1:2.10.0-1) forky: r
debian
CVE-2016-9922P4MEDIUMCVSS 5.5fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-9922 [MEDIUM] CVE-2016-9922: qemu - The cirrus_do_copy function in hw/display/cirrus_vga.c in QEMU (aka Quick Emulat... The cirrus_do_copy function in hw/display/cirrus_vga.c in QEMU (aka Quick Emulator), when cirrus graphics mode is VGA, allows local guest OS privileged users to cause a denial of service (divide-by-zero error and QEMU process crash) via vectors involving blit pitch values. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-1) bullseye: resolved (fixed in 1:2.8+dfsg-1
debian
CVE-2017-5898P4MEDIUMCVSS 5.5fixed in qemu 1:2.8+dfsg-3 (bookworm)2017
CVE-2017-5898 [MEDIUM] CVE-2017-5898: qemu - Integer overflow in the emulated_apdu_from_guest function in usb/dev-smartcard-r... Integer overflow in the emulated_apdu_from_guest function in usb/dev-smartcard-reader.c in Quick Emulator (Qemu), when built with the CCID Card device emulator support, allows local users to cause a denial of service (application crash) via a large Application Protocol Data Units (APDU) unit. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-3) bullseye: resolved (f
debian
CVE-2020-25625P4MEDIUMCVSS 5.3fixed in qemu 1:5.2+dfsg-1 (bookworm)2020
CVE-2020-25625 [MEDIUM] CVE-2020-25625: qemu - hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop. hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop. Scope: local bookworm: resolved (fixed in 1:5.2+dfsg-1) bullseye: resolved (fixed in 1:5.2+dfsg-1) forky: resolved (fixed in 1:5.2+dfsg-1) sid: resolved (fixed in 1:5.2+dfsg-1) trixie: resolved (fixed in 1:5.2+dfsg-1)
debian
CVE-2008-2004P4MEDIUMCVSS 4.9fixed in qemu 0.9.1-5 (bookworm)2008
CVE-2008-2004 [MEDIUM] CVE-2008-2004: qemu - The drive_init function in QEMU 0.9.1 determines the format of a raw disk image ... The drive_init function in QEMU 0.9.1 determines the format of a raw disk image based on the header, which allows local guest users to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted. Scope: local bookworm: resolved (fixed in 0.9.1-5) bullseye: resolved (fixed in 0.9.1-5) forky: resolved
debian
CVE-2017-18043P4MEDIUMCVSS 5.5fixed in qemu 1:2.10.0+dfsg-2 (bookworm)2017
CVE-2017-18043 [MEDIUM] CVE-2017-18043: qemu - Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a ... Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash). Scope: local bookworm: resolved (fixed in 1:2.10.0+dfsg-2) bullseye: resolved (fixed in 1:2.10.0+dfsg-2) forky: resolved (fixed in 1:2.10.0+dfsg-2) sid: resolved (fixed in 1:2.10.0+dfsg-2) trixie: resolved (fixed in 1:2.10.0+dfsg-2)
debian
CVE-2014-0142P4MEDIUMCVSS 5.5fixed in qemu 2.0.0+dfsg-1 (bookworm)2014
CVE-2014-0142 [MEDIUM] CVE-2014-0142: qemu - QEMU, possibly before 2.0.0, allows local users to cause a denial of service (di... QEMU, possibly before 2.0.0, allows local users to cause a denial of service (divide-by-zero error and crash) via a zero value in the (1) tracks field to the seek_to_sector function in block/parallels.c or (2) extent_size field in the bochs function in block/bochs.c. Scope: local bookworm: resolved (fixed in 2.0.0+dfsg-1) bullseye: resolved (fixed in 2.0.0+dfsg-1) fork
debian
CVE-2015-4103P4MEDIUMCVSS 4.9fixed in qemu 1:2.3+dfsg-5 (bookworm)2015
CVE-2015-4103 [MEDIUM] CVE-2015-4103: qemu - Xen 3.3.x through 4.5.x does not properly restrict write access to the host MSI ... Xen 3.3.x through 4.5.x does not properly restrict write access to the host MSI message data field, which allows local x86 HVM guest administrators to cause a denial of service (host interrupt handling confusion) via vectors related to qemu and accessing spanning multiple fields. Scope: local bookworm: resolved (fixed in 1:2.3+dfsg-5) bullseye: resolved (fixed in 1:2.3
debian
CVE-2015-2756P4MEDIUMCVSS 4.9fixed in qemu 1:2.3+dfsg-3 (bookworm)2015
CVE-2015-2756 [MEDIUM] CVE-2015-2756: qemu - QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to P... QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response. Sco
debian
CVE-2014-9718P4LOWCVSS 4.9fixed in qemu 1:2.3+dfsg-1 (bookworm)2014
CVE-2014-9718 [MEDIUM] CVE-2014-9718: qemu - The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 t... The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have multiple interpretations of a function's return value, which allows guest OS users to cause a host OS denial of service (memory consumption or infinite loop, and system crash) via a PRDT with zero complete sectors, related to the bmdma_prepare_buf and ahci_dma_prepare_buf
debian
CVE-2015-4106P4MEDIUMCVSS 4.6fixed in qemu 1:2.3+dfsg-5 (bookworm)2015
CVE-2015-4106 [MEDIUM] CVE-2015-4106: qemu - QEMU does not properly restrict write access to the PCI config space for certain... QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact via unknown vectors. Scope: local bookworm: resolved (fixed in 1:2.3+dfsg-5) bullseye: resolv
debian
Debian Qemu vulnerabilities | cvebase