Kvm Qumranet Kvm vulnerabilities
4 known vulnerabilities affecting kvm_qumranet/kvm.
Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2010-0419MEDIUMCVSS 4.4v832010-03-05
CVE-2010-0419 [MEDIUM] CWE-264 CVE-2010-0419: The x86 emulator in KVM 83, when a guest is configured for Symmetric Multiprocessing (SMP), does not
The x86 emulator in KVM 83, when a guest is configured for Symmetric Multiprocessing (SMP), does not properly restrict writing of segment selectors to segment registers, which might allow guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by leveraging access to a (1) IO port or (2) MMIO region, and replaci
nvd
CVE-2010-0306MEDIUMCVSS 4.1v832010-02-12
CVE-2010-0306 [MEDIUM] CVE-2010-0306: The x86 emulator in KVM 83, when a guest is configured for Symmetric Multiprocessing (SMP), does not
The x86 emulator in KVM 83, when a guest is configured for Symmetric Multiprocessing (SMP), does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) to restrict instruction execution, which allows guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by leveraging access to a (1) IO port or (2) MM
nvd
CVE-2008-4539HIGHCVSS 7.2≤ 812008-12-29
CVE-2008-4539 [HIGH] CVE-2008-4539: Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on
Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for a connection, aka the LGD-54XX "bitblt" heap overflow. NOTE: this issue exists because of an incorrect fix for CVE-2007-1320.
nvd
CVE-2008-2382MEDIUMCVSS 5.0PoC≤ 79v1+77 more2008-12-24
CVE-2008-2382 [MEDIUM] CWE-399 CVE-2008-2382: The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KV
The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote attackers to cause a denial of service (infinite loop) via a certain message.
nvd