Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
448 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7) | 0.44% | — | Qemu | 26/4/2017 | 17/6/2026 | The disas_insn function in target/i386/translate.c in QEMU before 2.9.0, when TCG mode without hardware acceleration is used, does not limit the instruction size, which allows local users to gain privileges by creating a modified basic block that injects code into a setuid program, as demonstrated by procmail. NOTE:… | |
| Modificada | Media (5.5) | 0.50% | — | QemuDebian Linux | 20/4/2017 | 17/6/2026 | hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors related to copying VGA data via the cirrus_bitblt_rop_fwd_transp_ and cirrus_bitblt_rop_fwd_ functions. | |
| Modificada | Alta (7.5) | 3.9% | — | QemuDebian Linux | 13/4/2017 | 17/6/2026 | The Human Monitor Interface support in QEMU allows remote attackers to cause a denial of service (out-of-bounds write and application crash). | |
| Modificada | Alta (7.7) | 5.6% | — | QemuCanonical Ubuntu LinuxDebian LinuxSuse Linux Enterprise Debuginfo+6 | 13/4/2017 | 17/6/2026 | Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption). | |
| Modificada | Media (6.5) | 0.39% | — | QemuDebian Linux | 13/4/2017 | 17/6/2026 | The eepro100 emulator in QEMU qemu-kvm blank allows local guest users to cause a denial of service (application crash and infinite loop) via vectors involving the command block list. | |
| Modificada | Alta (7.9) | 0.43% | — | QemuDebian Linux | 11/4/2017 | 17/6/2026 | Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC system emulator. | |
| Modificada | Media (6.5) | 0.43% | — | QemuDebian Linux | 11/4/2017 | 17/6/2026 | Stack-based buffer overflow in the megasas_ctrl_get_info function in QEMU, when built with SCSI MegaRAID SAS HBA emulation support, allows local guest users to cause a denial of service (QEMU instance crash) via a crafted SCSI controller CTRL_GET_INFO command. | |
| Modificada | Media (6.5) | 0.46% | — | QemuDebian Linux | 11/4/2017 | 17/6/2026 | Memory leak in QEMU, when built with a VMWARE VMXNET3 paravirtual NIC emulator support, allows local guest users to cause a denial of service (host memory consumption) by trying to activate the vmxnet3 device repeatedly. | |
| Modificada | Media (6.5) | 3.1% | — | QemuDebian Linux | 11/4/2017 | 17/6/2026 | Qemu, when built with VNC display driver support, allows remote attackers to cause a denial of service (arithmetic exception and application crash) via crafted SetPixelFormat messages from a client. | |
| Modificada | Media (6) | 0.38% | — | QemuDebian Linux | 10/4/2017 | 17/6/2026 | The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a denial of service (file descriptor or memory consumption) via vectors related to an already in-use fid. | |
| Modificada | Media (5.5) | 0.46% | — | QemuDebian LinuxRedhat OpenstackRedhat Virtualization | 27/3/2017 | 17/6/2026 | The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors related to control transfer descriptor sequence. | |
| Modificada | Alta (8.8) | 0.53% | — | Qemu | 27/3/2017 | 17/6/2026 | Integer overflow in hw/virtio/virtio-crypto.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code on the host via a crafted virtio-crypto request, which triggers a heap-based buffer overflow. | |
| Modificada | Media (5.5) | 0.41% | — | Qemu | 27/3/2017 | 17/6/2026 | The cirrus_do_copy function in hw/display/cirrus_vga.c in QEMU (aka Quick Emulator), when cirrus graphics mode is VGA, allows local guest OS privileged users to cause a denial of service (divide-by-zero error and QEMU process crash) via vectors involving blit pitch values. | |
| Modificada | Crítica (10) | 13% | 💥 Exploit | Qemu | 24/3/2017 | 17/6/2026 | Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1. | |
| Modificada | Alta (7.5) | 3.9% | — | Qemu | 20/3/2017 | 17/6/2026 | Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 device, allows remote attackers to cause a denial of service (out-of-bounds access and QEMU process crash) via vectors related to VLAN stripping. | |
| Modificada | Media (5.5) | 0.42% | — | QemuDebian Linux | 20/3/2017 | 17/6/2026 | The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local OS guest privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors involving the transfer mode register during multi block transfer. | |
| Modificada | Media (6.5) | 0.39% | — | Qemu | 16/3/2017 | 17/6/2026 | Memory leak in the virgl_cmd_resource_unref function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_UNREF commands sent without detaching the backing storage beforehand. | |
| Modificada | Media (6.5) | 0.39% | — | QemuDebian Linux | 16/3/2017 | 17/6/2026 | Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) via MegaRAID Firmware Interface (MFI) commands with the sglist size set to a value over 2 Gb. | |
| Modificada | Media (6.5) | 0.44% | — | QemuDebian Linux | 16/3/2017 | 17/6/2026 | The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds heap access and crash) or execute arbitrary code on the QEMU host via vectors involving the data transfer length. | |
| Modificada | Media (5.5) | 0.40% | — | QemuSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Server FOR SAP+1 | 15/3/2017 | 17/6/2026 | Integer overflow in the emulated_apdu_from_guest function in usb/dev-smartcard-reader.c in Quick Emulator (Qemu), when built with the CCID Card device emulator support, allows local users to cause a denial of service (application crash) via a large Application Protocol Data Units (APDU) unit. | |
| Modificada | Media (6.5) | 0.40% | — | QemuDebian Linux | 15/3/2017 | 17/6/2026 | Memory leak in the serial_exit_core function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations. | |
| Modificada | Media (6.5) | 0.40% | — | Qemu | 15/3/2017 | 17/6/2026 | Memory leak in the virtio_gpu_resource_attach_backing function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_ATTACH_BACKING commands. | |
| Modificada | Media (6.5) | 0.40% | — | Qemu | 15/3/2017 | 17/6/2026 | Memory leak in the virgl_resource_attach_backing function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_ATTACH_BACKING commands. | |
| Modificada | Media (6.5) | 0.40% | — | QemuDebian Linux | 15/3/2017 | 17/6/2026 | Memory leak in hw/audio/es1370.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations. | |
| Modificada | Media (6.5) | 0.40% | — | QemuDebian Linux | 15/3/2017 | 17/6/2026 | Memory leak in hw/audio/ac97.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations. |