Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
448 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 3.0% | — | Qemu | 29/8/2017 | 17/6/2026 | The vga display update in mis-calculated the region for the dirty bitmap snapshot in case split screen mode is used causing a denial of service (assertion failure) in the cpu_physical_memory_snapshot_get_dirty function. | |
| Modificada | Crítica (9.8) | 3.9% | — | Qemu | 28/8/2017 | 17/6/2026 | Buffer overflow in the "megasas_mmio_write" function in Qemu 2.9.0 allows remote attackers to have unspecified impact via unknown vectors. | |
| Modificada | Media (6.5) | 0.39% | — | QemuDebian Linux | 23/8/2017 | 17/6/2026 | QEMU (aka Quick Emulator), when built with the IDE disk and CD/DVD-ROM Emulator support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) by flushing an empty CDROM device drive. | |
| Modificada | Media (5.5) | 0.41% | — | Qemu | 10/8/2017 | 17/6/2026 | The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x before 2.0.0 allows local users to cause a denial of service (NULL pointer dereference) via a crafted image which causes an error, related to the initialization of the snapshot_offset and nb_snapshots fields. | |
| Modificada | Alta (7.8) | 0.51% | — | Qemu | 10/8/2017 | 17/6/2026 | Multiple buffer overflows in QEMU before 1.7.2 and 2.x before 2.0.0, allow local users to cause a denial of service (crash) or possibly execute arbitrary code via a large (1) L1 table in the qcow2_snapshot_load_tmp in the QCOW 2 block driver (block/qcow2-snapshot.c) or (2) uncompressed chunk, (3) chunk length, or (4)… | |
| Modificada | Alta (7) | 0.40% | — | Redhat Enterprise LinuxQemu | 10/8/2017 | 17/6/2026 | Multiple integer overflows in the block drivers in QEMU, possibly before 2.0.0, allow local users to cause a denial of service (crash) via a crafted catalog size in (1) the parallels_open function in block/parallels.c or (2) bochs_open function in bochs.c, a large L1 table in the (3) qcow2_snapshot_load_tmp in… | |
| Modificada | Media (5.5) | 0.38% | — | Qemu | 10/8/2017 | 17/6/2026 | QEMU, possibly before 2.0.0, allows local users to cause a denial of service (divide-by-zero error and crash) via a zero value in the (1) tracks field to the seek_to_sector function in block/parallels.c or (2) extent_size field in the bochs function in block/bochs.c. | |
| Modificada | Media (4.4) | 0.50% | — | QemuDebian Linux | 2/8/2017 | 17/6/2026 | The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds access and guest instance crash) by leveraging use of qemu_map_ram_ptr to access guest ram block area. | |
| Modificada | Media (5.5) | 0.44% | — | QemuDebian Linux | 2/8/2017 | 17/6/2026 | Stack-based buffer overflow in hw/usb/redirect.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU process crash) via vectors related to logging debug messages. | |
| Modificada | Alta (7.5) | 4.0% | — | QemuDebian LinuxRedhat VirtualizationRedhat Openstack+6 | 2/8/2017 | 17/6/2026 | qemu-nbd in QEMU (aka Quick Emulator) does not ignore SIGPIPE, which allows remote attackers to cause a denial of service (daemon crash) by disconnecting during a server-to-client reply attempt. | |
| Modificada | Media (5.5) | 0.41% | — | QemuDebian Linux | 25/7/2017 | 17/6/2026 | The dhcp_decode function in slirp/bootp.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) via a crafted DHCP options string. | |
| Modificada | Alta (7.8) | 0.63% | — | QemuCanonical Ubuntu LinuxDebian LinuxRedhat Openstack+7 | 25/7/2017 | 17/6/2026 | Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC client updating its display after a VGA operation. | |
| Modificada | Alta (7.5) | 4.1% | — | QemuDebian Linux | 6/7/2017 | 17/6/2026 | The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Server support, allows remote attackers to cause a denial of service (segmentation fault and server crash) by leveraging failure to ensure that all initialization occurs before talking to a client in the nbd_negotiate… | |
| Modificada | Media (5.5) | 0.41% | — | QemuDebian Linux | 16/6/2017 | 17/6/2026 | QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving megasas command processing. | |
| Modificada | Media (5.5) | 0.43% | — | QemuDebian Linux | 16/6/2017 | 17/6/2026 | QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest OS privileged users to cause a denial of service (infinite recursive call) via vectors involving control transfer descriptors sequencing. | |
| Modificada | Media (5.5) | 0.43% | — | Qemu | 16/6/2017 | 17/6/2026 | Memory leak in QEMU (aka Quick Emulator), when built with USB EHCI Emulation support, allows local guest OS privileged users to cause a denial of service (memory consumption) by repeatedly hot-unplugging the device. | |
| Modificada | Media (5.5) | 0.42% | — | QemuDebian Linux | 16/6/2017 | 17/6/2026 | Memory leak in QEMU (aka Quick Emulator), when built with IDE AHCI Emulation support, allows local guest OS privileged users to cause a denial of service (memory consumption) by repeatedly hot-unplugging the AHCI device. | |
| Modificada | Media (5.6) | 0.35% | — | QemuDebian Linux | 8/6/2017 | 17/6/2026 | QEMU (aka Quick Emulator) before 2.9.0, when built with the USB OHCI Emulation support, allows local guest OS users to cause a denial of service (infinite loop) by leveraging an incorrect return value, a different vulnerability than CVE-2017-6505. | |
| Modificada | Media (5.6) | 0.34% | — | QemuDebian Linux | 8/6/2017 | 17/6/2026 | QEMU (aka Quick Emulator), when built with the e1000e NIC emulation support, allows local guest OS privileged users to cause a denial of service (infinite loop) via vectors related to setting the initial receive / transmit descriptor head (TDH/RDH) outside the allocated descriptor buffer. | |
| Modificada | Media (5.5) | 0.41% | — | Qemu | 1/6/2017 | 17/6/2026 | Memory leak in the virtio_gpu_set_scanout function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (memory consumption) via a large number of "VIRTIO_GPU_CMD_SET_SCANOUT:" commands. | |
| Modificada | Media (6.5) | 0.41% | — | QemuDebian LinuxRedhat Openstack | 23/5/2017 | 17/6/2026 | Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) by rapidly generating large keyboard events. | |
| Modificada | Alta (7.5) | 4.5% | — | QemuDebian LinuxRedhat Openstack | 23/5/2017 | 17/6/2026 | Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a denial of service (memory consumption) by repeatedly starting and stopping audio capture. | |
| Modificada | Alta (7.8) | 0.37% | — | QemuDebian Linux | 17/5/2017 | 17/6/2026 | Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing virtfs metadata files in mapped-file security mode. A guest user could use this flaw to escalate their privileges inside guest. | |
| Modificada | Media (6.5) | 0.41% | — | QemuDebian Linux | 2/5/2017 | 17/6/2026 | hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and CPU consumption) via the message ring page count. | |
| Modificada | Media (6.5) | 0.42% | — | QemuDebian Linux | 2/5/2017 | 17/6/2026 | Memory leak in the v9fs_list_xattr function in hw/9pfs/9p-xattr.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (memory consumption) via vectors involving the orig_value variable. |