Debian Qemu vulnerabilities
424 known vulnerabilities affecting debian/qemu.
Total CVEs
424
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH85MEDIUM226LOW102UNKNOWN1
Vulnerabilities
Page 8 of 22
CVE-2007-5729P4HIGHCVSS 7.2fixed in qemu 0.9.0-2 (bookworm)2007
CVE-2007-5729 [HIGH] CVE-2007-5729: qemu - The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code b...
The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_TCNT register, which triggers a heap-based buffer overflow in the slirp library, aka NE2000 "mtu" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the soc
debian
CVE-2015-5225P4HIGHCVSS 7.2fixed in qemu 1:2.4+dfsg-1a (bookworm)2015
CVE-2015-5225 [HIGH] CVE-2015-5225: qemu - Buffer overflow in the vnc_refresh_server_surface function in the VNC display dr...
Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service (heap memory corruption and process crash) or possibly execute arbitrary code on the host via unspecified vectors, related to refreshing the server display surface.
Scope: local
bookworm: resolved (fixed in 1:2.4+dfsg
debian
CVE-2015-5166P4HIGHCVSS 7.2fixed in qemu 1:2.4+dfsg-1a (bookworm)2015
CVE-2015-5166 [HIGH] CVE-2015-5166: qemu - Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completel...
Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completely unplug emulated block devices, which allows local HVM guest users to gain privileges by unplugging a block device twice.
Scope: local
bookworm: resolved (fixed in 1:2.4+dfsg-1a)
bullseye: resolved (fixed in 1:2.4+dfsg-1a)
forky: resolved (fixed in 1:2.4+dfsg-1a)
sid: resolved (fixed in 1:2.
debian
CVE-2016-6351P4MEDIUMCVSS 6.7fixed in qemu 1:2.6+dfsg-3.1 (bookworm)2016
CVE-2016-6351 [MEDIUM] CVE-2016-6351: qemu - The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when buil...
The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or execute arbitrary code on the QEMU host via vectors involving DMA read into ESP command buffer.
Scope: local
bookworm: resolved
debian
CVE-2020-8608P4MEDIUMCVSS 5.6fixed in libslirp 4.2.0-1 (bookworm)2020
CVE-2020-8608 [MEDIUM] CVE-2020-8608: libslirp - In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return val...
In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code.
Scope: local
bookworm: resolved (fixed in 4.2.0-1)
bullseye: resolved (fixed in 4.2.0-1)
forky: resolved (fixed in 4.2.0-1)
sid: resolved (fixed in 4.2.0-1)
trixie: resolved (fixed in 4.2.0-1)
debian
CVE-2023-4135P4LOWCVSS 6.0fixed in qemu 1:8.0.4+dfsg-2 (forky)2023
CVE-2023-4135 [MEDIUM] CVE-2023-4135: qemu - A heap out-of-bounds memory read flaw was found in the virtual nvme device in QE...
A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate an offset provided by the guest before computing a host heap pointer, which is used for copying data back to the guest. Arbitrary heap memory relative to an allocated buffer can be disclosed.
Scope: local
bookworm: resolved
bullseye: resolved
forky: re
debian
CVE-2011-4111P4MEDIUMCVSS 6.8fixed in qemu 0.15.1+dfsg-2 (bookworm)2011
CVE-2011-4111 [MEDIUM] CVE-2011-4111: qemu - Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-...
Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR message.
Scope: local
bookworm: resolved (fixed in 0.15.1+dfsg-2)
bullseye: resolved (fixed in 0.15.1+dfsg-2)
forky:
debian
CVE-2017-13673P4MEDIUMCVSS 6.5fixed in qemu 1:2.10.0+dfsg-2 (bookworm)2017
CVE-2017-13673 [MEDIUM] CVE-2017-13673: qemu - The vga display update in mis-calculated the region for the dirty bitmap snapsho...
The vga display update in mis-calculated the region for the dirty bitmap snapshot in case split screen mode is used causing a denial of service (assertion failure) in the cpu_physical_memory_snapshot_get_dirty function.
Scope: local
bookworm: resolved (fixed in 1:2.10.0+dfsg-2)
bullseye: resolved (fixed in 1:2.10.0+dfsg-2)
forky: resolved (fixed in 1:2.10.0+dfsg-2)
s
debian
CVE-2012-3515P4HIGHCVSS 7.2fixed in qemu 1.1.2+dfsg-1 (bookworm)2012
CVE-2012-3515 [HIGH] CVE-2012-3515: qemu - Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certai...
Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers the overwrite of a "device model's address space."
Scope: local
bookworm: resolved (fixed in 1.1.2+dfsg-1)
bullseye: resolved (fixed in 1.1.2+dfsg-1)
fork
debian
CVE-2013-4344P4LOWCVSS 7.2fixed in qemu 1.6.0+dfsg-2 (bookworm)2013
CVE-2013-4344 [HIGH] CVE-2013-4344: qemu - Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI ...
Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.
Scope: local
bookworm: resolved (fixed in 1.6.0+dfsg-2)
bullseye: resolved (fixed in 1.6.0+dfsg-2)
forky: resolved (fixed in 1.6.0+dfsg-2)
sid: resolved (
debian
CVE-2015-8743P4HIGHCVSS 7.1fixed in qemu 1:2.5+dfsg-2 (bookworm)2015
CVE-2015-8743 [HIGH] CVE-2015-8743: qemu - QEMU (aka Quick Emulator) built with the NE2000 device emulation support is vuln...
QEMU (aka Quick Emulator) built with the NE2000 device emulation support is vulnerable to an OOB r/w access issue. It could occur while performing 'ioport' r/w operations. A privileged (CAP_SYS_RAWIO) user/process could use this flaw to leak or corrupt QEMU memory bytes.
Scope: local
bookworm: resolved (fixed in 1:2.5+dfsg-2)
bullseye: resolved (fixed in 1:2.5+dfsg-2)
fo
debian
CVE-2016-4439P4MEDIUMCVSS 6.7fixed in qemu 1:2.6+dfsg-2 (bookworm)2016
CVE-2016-4439 [MEDIUM] CVE-2016-4439: qemu - The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (F...
The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check command buffer length, which allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or potentially execute arbitrary code on the QEMU host via unspecified vectors.
Scope: local
bookworm: reso
debian
CVE-2020-11102P4MEDIUMCVSS 5.6fixed in qemu 1:4.2-4 (bookworm)2020
CVE-2020-11102 [MEDIUM] CVE-2020-11102: qemu - hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx b...
hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not validated against the r/w data length.
Scope: local
bookworm: resolved (fixed in 1:4.2-4)
bullseye: resolved (fixed in 1:4.2-4)
forky: resolved (fixed in 1:4.2-4)
sid: resolved (fixed in 1:4.2-4)
trixie: resolved (fixed in 1:4.2-4)
debian
CVE-2015-5239P4MEDIUMCVSS 6.5fixed in qemu 2.1+dfsg-1 (bookworm)2015
CVE-2015-5239 [MEDIUM] CVE-2015-5239: qemu - Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers...
Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in 2.1+dfsg-1)
trixie: reso
debian
CVE-2014-5263P4MEDIUMCVSS 6.8fixed in qemu 2.1+dfsg-1 (bookworm)2014
CVE-2014-5263 [MEDIUM] CVE-2014-5263: qemu - vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the lis...
vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the list with the VMSTATE_END_OF_LIST macro, which allows attackers to cause a denial of service (out-of-bounds access, infinite loop, and memory corruption) and possibly gain privileges via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1
debian
CVE-2008-4539P4LOWCVSS 7.2fixed in qemu 0.9.1+svn20081101-1 (bookworm)2008
CVE-2008-4539 [HIGH] CVE-2008-4539: qemu - Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kv...
Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for a connection, aka the LGD-54XX "bitblt" heap overflow. NOTE: this issue exists because of an incorrect fix for CVE-2007-1320.
Scope: local
bookworm: resolved (fixed in 0.9.
debian
CVE-2020-35506P4MEDIUMCVSS 6.7fixed in qemu 1:6.0+dfsg-3 (bookworm)2020
CVE-2020-35506 [MEDIUM] CVE-2020-35506: qemu - A use-after-free vulnerability was found in the am53c974 SCSI host bus adapter e...
A use-after-free vulnerability was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0 during the handling of the 'Information Transfer' command (CMD_TI). This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service or potential code execution with the privileges of the QEMU proces
debian
CVE-2020-13765P4MEDIUMCVSS 5.6fixed in qemu 1:4.2-1 (bookworm)2020
CVE-2020-13765 [MEDIUM] CVE-2020-13765: qemu - rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relat...
rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which allows attackers to trigger an invalid memory copy operation.
Scope: local
bookworm: resolved (fixed in 1:4.2-1)
bullseye: resolved (fixed in 1:4.2-1)
forky: resolved (fixed in 1:4.2-1)
sid: resolved (fixed in 1:4.2-1)
trixie: resolved (fixed in 1:4.2-
debian
CVE-2018-16872P4MEDIUMCVSS 5.3fixed in qemu 1:3.1+dfsg-2 (bookworm)2018
CVE-2018-16872 [MEDIUM] CVE-2018-16872: qemu - A flaw was found in qemu Media Transfer Protocol (MTP). The code opening files i...
A flaw was found in qemu Media Transfer Protocol (MTP). The code opening files in usb_mtp_get_object and usb_mtp_get_partial_object and directories in usb_mtp_object_readdir doesn't consider that the underlying filesystem may have changed since the time lstat(2) was called in usb_mtp_object_alloc, a classical TOCTTOU problem. An attacker with write access to the host
debian
CVE-2007-1320P4HIGHCVSS 7.2fixed in qemu 0.9.0-2 (bookworm)2007
CVE-2007-1320 [HIGH] CVE-2007-1320: qemu - Multiple heap-based buffer overflows in the cirrus_invalidate_region function in...
Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark non-existent regions as dirty," aka the "bitblt" heap overflow.
Scope: local
bookworm: resolved (fixed
debian