cbcvebase.

Debian Qemu vulnerabilities

424 known vulnerabilities affecting debian/qemu.

Total CVEs
424
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH85MEDIUM226LOW102UNKNOWN1

Vulnerabilities

Page 7 of 22
CVE-2016-9637P4LOWCVSS 7.5fixed in xen 4.4.0-1 (bookworm)2016
CVE-2016-9637 [HIGH] CVE-2016-9637: qemu - The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as ... The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS administrators to gain qemu process privileges via vectors involving an out-of-range ioport access. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2015-5279P3HIGHCVSS 7.2fixed in qemu 1:2.4+dfsg-3 (bookworm)2015
CVE-2015-5279 [HIGH] CVE-2015-5279: qemu - Heap-based buffer overflow in the ne2000_receive function in hw/net/ne2000.c in ... Heap-based buffer overflow in the ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via vectors related to receiving packets. Scope: local bookworm: resolved (fixed in 1:2.4+dfsg-3) bullseye: resolved (fixed in 1:2.4+dfsg-3) forky: resolved (fixed in 1:2
debian
CVE-2020-27617P4MEDIUMCVSS 6.5fixed in qemu 1:5.2+dfsg-1 (bookworm)2020
CVE-2020-27617 [MEDIUM] CVE-2020-27617: qemu - eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an ... eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure. A guest can crash the QEMU process via packet data that lacks a valid Layer 3 protocol. Scope: local bookworm: resolved (fixed in 1:5.2+dfsg-1) bullseye: resolved (fixed in 1:5.2+dfsg-1) forky: resolved (fixed in 1:5.2+dfsg-1) sid: resolved (fixed in 1:5.2+dfsg-1) trixi
debian
CVE-2015-5154P4HIGHCVSS 7.2fixed in qemu 1:2.4+dfsg-1a (bookworm)2015
CVE-2015-5154 [HIGH] CVE-2015-5154: qemu - Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x an... Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, allows local guest users to execute arbitrary code on the host via unspecified ATAPI commands. Scope: local bookworm: resolved (fixed in 1:2.4+dfsg-1a) bullseye: resolved (fixed in 1:2.4+dfsg-1a) forky: resolved (fixed in 1:2.4+dfsg-1a)
debian
CVE-2024-6505P4MEDIUMCVSS 6.8fixed in qemu 1:7.2+dfsg-7+deb12u8 (bookworm)2024
CVE-2024-6505 [MEDIUM] CVE-2024-6505: qemu - A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature... A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within RSS becomes controllable. Setting excessively large values may cause an index out-of-bounds issue, potentially resulting in heap overflow access. This flaw allows a privileged user in the guest to crash the QEMU process on
debian
CVE-2018-20191P4LOWCVSS 7.5fixed in qemu 1:4.1-1 (bookworm)2018
CVE-2018-20191 [HIGH] CVE-2018-20191: qemu - hw/rdma/vmw/pvrdma_main.c in QEMU does not implement a read operation (such as u... hw/rdma/vmw/pvrdma_main.c in QEMU does not implement a read operation (such as uar_read by analogy to uar_write), which allows attackers to cause a denial of service (NULL pointer dereference). Scope: local bookworm: resolved (fixed in 1:4.1-1) bullseye: resolved (fixed in 1:4.1-1) forky: resolved (fixed in 1:4.1-1) sid: resolved (fixed in 1:4.1-1) trixie: resolved (fi
debian
CVE-2020-17380P4MEDIUMCVSS 6.3fixed in qemu 1:5.2+dfsg-10 (bookworm)2020
CVE-2020-17380 [MEDIUM] CVE-2020-17380: qemu - A heap-based buffer overflow was found in QEMU through 5.0.0 in the SDHCI device... A heap-based buffer overflow was found in QEMU through 5.0.0 in the SDHCI device emulation support. It could occur while doing a multi block SDMA transfer via the sdhci_sdma_transfer_multi_blocks() routine in hw/sd/sdhci.c. A guest user or process could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially exe
debian
CVE-2016-2857P4HIGHCVSS 8.4fixed in qemu 1:2.6+dfsg-1 (bookworm)2016
CVE-2016-2857 [HIGH] CVE-2016-2857: qemu - The net_checksum_calculate function in net/checksum.c in QEMU allows local guest... The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and crash) via the payload length in a crafted packet. Scope: local bookworm: resolved (fixed in 1:2.6+dfsg-1) bullseye: resolved (fixed in 1:2.6+dfsg-1) forky: resolved (fixed in 1:2.6+dfsg-1) sid: resolved (fixed in 1:2.6+dfsg-
debian
CVE-2023-2861P4MEDIUMCVSS 6.0fixed in qemu 1:7.2+dfsg-7+deb12u1 (bookworm)2023
CVE-2023-2861 [MEDIUM] CVE-2023-2861: qemu - A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU.... A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit opening special files on the host side, potentially allowing a malicious client to escape from the exported 9p tree by creating and opening a device file in the shared folder. Scope: local bookworm: resolved (fixed in 1:7.2+dfsg-7+deb12u1) bullseye: open fo
debian
CVE-2018-10839P4MEDIUMCVSS 6.5fixed in qemu 1:3.1+dfsg-1 (bookworm)2018
CVE-2018-10839 [MEDIUM] CVE-2018-10839: qemu - Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable... Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS. Scope: local bookworm: resolved (fixed in 1:3.1+dfsg-1) bullseye: resolved (fixed
debian
CVE-2015-5278P4MEDIUMCVSS 6.5fixed in qemu 1:2.4+dfsg-3 (bookworm)2015
CVE-2015-5278 [MEDIUM] CVE-2015-5278: qemu - The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows att... The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets. Scope: local bookworm: resolved (fixed in 1:2.4+dfsg-3) bullseye: resolved (fixed in 1:2.4+dfsg-3) forky: resolved (fixed in 1:2.4+dfsg-3) sid:
debian
CVE-2023-6683P4MEDIUMCVSS 6.5fixed in qemu 1:7.2+dfsg-7+deb12u4 (bookworm)2023
CVE-2023-6683 [MEDIUM] CVE-2023-6683: qemu - A flaw was found in the QEMU built-in VNC server while processing ClientCutText ... A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() was called and had the chance to initialize the clipboard peer, leading to a NULL pointer dereference. This could allow a malicious authenticated VNC client to crash QEMU and trigger a denial of
debian
CVE-2022-3165P4MEDIUMCVSS 6.5fixed in qemu 1:7.2+dfsg-1 (bookworm)2022
CVE-2022-3165 [MEDIUM] CVE-2022-3165: qemu - An integer underflow issue was found in the QEMU VNC server while processing Cli... An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending a specially crafted payload message, resulting in a denial of service. Scope: local bookworm: resolved (fixed in 1:7.2+dfsg-1) bullseye: resolved forky: resolved (fixed in
debian
CVE-2015-8666P4HIGHCVSS 7.9fixed in qemu 1:2.5+dfsg-1 (bookworm)2015
CVE-2015-8666 [HIGH] CVE-2015-8666: qemu - Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC sys... Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC system emulator. Scope: local bookworm: resolved (fixed in 1:2.5+dfsg-1) bullseye: resolved (fixed in 1:2.5+dfsg-1) forky: resolved (fixed in 1:2.5+dfsg-1) sid: resolved (fixed in 1:2.5+dfsg-1) trixie: resolved (fixed in 1:2.5+dfsg-1)
debian
CVE-2007-5730P4HIGHCVSS 7.2fixed in qemu 0.9.0-2 (bookworm)2007
CVE-2007-5730 [HIGH] CVE-2007-5730: qemu - Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other prod... Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to execute arbitrary code via crafted data in the "net socket listen" option, aka QEMU "net socket" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the correct identif
debian
CVE-2020-14364P4MEDIUMCVSS 5.0fixed in qemu 1:5.1+dfsg-4 (bookworm)2020
CVE-2020-14364 [MEDIUM] CVE-2020-14364: qemu - An out-of-bounds read/write access flaw was found in the USB emulator of the QEM... An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[4096]' in the do_token_in, do_token_out routines. This flaw allows a guest user to crash the QEMU process, resulting in a denial of service, or the pote
debian
CVE-2017-2633P4MEDIUMCVSS 5.4fixed in qemu 2.1+dfsg-1 (bookworm)2017
CVE-2017-2633 [MEDIUM] CVE-2017-2633: qemu - An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1... An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use this flaw to crash the QEMU process. Scope: local bookworm: resolved (fixed in 2.1+dfsg-1) bullseye: resolved (fixed in 2.
debian
CVE-2014-0222P4HIGHCVSS 7.5fixed in qemu 2.0.0+dfsg-6 (bookworm)2014
CVE-2014-0222 [HIGH] CVE-2014-0222: qemu - Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 ... Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service (crash) via a large L2 table in a QCOW version 1 image. Scope: local bookworm: resolved (fixed in 2.0.0+dfsg-6) bullseye: resolved (fixed in 2.0.0+dfsg-6) forky: resolved (fixed in 2.0.0+dfsg-6) sid: resolved (fixed in 2.0.0+dfsg-6) trixie:
debian
CVE-2015-5745P4MEDIUMCVSS 6.5fixed in qemu 1:2.4+dfsg-1a (bookworm)2015
CVE-2015-5745 [MEDIUM] CVE-2015-5745: qemu - Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c ... Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial of service (QEMU process crash) via a crafted virtio control message. Scope: local bookworm: resolved (fixed in 1:2.4+dfsg-1a) bullseye: resolved (fixed in 1:2.4+dfsg-1a) forky: resolved (fixed in 1:2.4+dfsg-1a) sid: resolved (fixed
debian
CVE-2020-27616P4MEDIUMCVSS 6.5fixed in qemu 1:5.2+dfsg-1 (bookworm)2020
CVE-2020-27616 [MEDIUM] CVE-2020-27616: qemu - ati_2d_blt in hw/display/ati_2d.c in QEMU 4.2.1 can encounter an outside-limits ... ati_2d_blt in hw/display/ati_2d.c in QEMU 4.2.1 can encounter an outside-limits situation in a calculation. A guest can crash the QEMU process. Scope: local bookworm: resolved (fixed in 1:5.2+dfsg-1) bullseye: resolved (fixed in 1:5.2+dfsg-1) forky: resolved (fixed in 1:5.2+dfsg-1) sid: resolved (fixed in 1:5.2+dfsg-1) trixie: resolved (fixed in 1:5.2+dfsg-1)
debian
Debian Qemu vulnerabilities | cvebase