Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
448 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6) | 0.39% | — | QemuOpensuse LeapDebian Linux | 9/12/2016 | 17/6/2026 | Memory leak in hw/net/eepro100.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by repeatedly unplugging an i8255x (PRO100) NIC device. | |
| Modificada | Media (6) | 0.41% | — | QemuDebian LinuxOpensuse LeapRedhat Openstack+1 | 4/11/2016 | 17/6/2026 | The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) by leveraging failure to limit the ring descriptor count. | |
| Modificada | Media (6) | 0.44% | — | QemuDebian LinuxOpensuse LeapRedhat Openstack+1 | 4/11/2016 | 17/6/2026 | The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via an entry with the same value for buffer length and pointer position. | |
| Modificada | Media (6) | 0.36% | — | QemuOpensuse LeapRedhat OpenstackRedhat Virtualization+1 | 4/11/2016 | 17/6/2026 | The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via vectors involving a value of divider greater than baud base. | |
| Modificada | Media (6) | 0.39% | — | QemuOpensuse Leap | 4/11/2016 | 17/6/2026 | The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging failure to limit DMA buffer size. | |
| Modificada | Media (6) | 0.39% | — | QemuOpensuse LeapDebian Linux | 4/11/2016 | 17/6/2026 | The rc4030_write function in hw/dma/rc4030.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via a large interval timer reload value. | |
| Modificada | Media (6) | 0.39% | — | QemuOpensuse LeapDebian Linux | 4/11/2016 | 17/6/2026 | The v9fs_iov_vunmarshal function in fsdev/9p-iov-marshal.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) by sending an empty string parameter to a 9P operation. | |
| Modificada | Media (6) | 0.39% | — | QemuDebian LinuxOpensuse Leap | 4/11/2016 | 17/6/2026 | Memory leak in the v9fs_read function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors related to an I/O read operation. | |
| Modificada | Media (6) | 0.40% | — | QemuOpensuse LeapRedhat OpenstackRedhat Virtualization+1 | 4/11/2016 | 17/6/2026 | The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit the number of link Transfer Request Blocks (TRB) to process. | |
| Modificada | Media (4.4) | 0.40% | — | Qemu | 10/10/2016 | 17/6/2026 | The mptsas_process_scsi_io_request function in QEMU (aka Quick Emulator), when built with LSI SAS1068 Host Bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors involving MPTSASRequest objects. | |
| Modificada | Media (4.4) | 0.44% | — | QemuDebian Linux | 5/10/2016 | 17/6/2026 | The pcnet_rdra_addr function in hw/net/pcnet.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by setting the (1) receive or (2) transmit descriptor ring length to 0. | |
| Modificada | Media (4.4) | 0.43% | — | QemuDebian Linux | 5/10/2016 | 17/6/2026 | The mcf_fec_do_tx function in hw/net/mcf_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via vectors involving a buffer descriptor with a… | |
| Modificada | Media (4.4) | 0.41% | — | Qemu | 5/10/2016 | 17/6/2026 | The imx_fec_do_tx function in hw/net/imx_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via vectors involving a buffer descriptor with a… | |
| Modificada | Crítica (9.8) | 6.1% | — | QemuDebian Linux | 5/10/2016 | 17/6/2026 | Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code on the QEMU host via a large ethlite packet. | |
| Modificada | Media (6.7) | 0.47% | — | QemuCanonical Ubuntu LinuxDebian Linux | 7/9/2016 | 17/6/2026 | The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or execute arbitrary code on the QEMU host via vectors involving DMA read into… | |
| Modificada | Media (6) | 0.42% | — | QemuCanonical Ubuntu LinuxDebian Linux | 2/9/2016 | 17/6/2026 | The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds read and crash) via unspecified vectors. | |
| Modificada | Media (6) | 0.39% | — | QemuCanonical Ubuntu LinuxDebian Linux | 2/9/2016 | 17/6/2026 | The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest administrators to cause a denial of service (out-of-bounds write access) via vectors involving a MegaRAID Firmware Interface (MFI) command. | |
| Modificada | Media (4.4) | 0.41% | — | QemuCanonical Ubuntu LinuxDebian Linux | 2/9/2016 | 17/6/2026 | The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involving a MegaRAID Firmware Interface (MFI) command. | |
| Modificada | Media (6) | 0.37% | — | QemuCanonical Ubuntu LinuxDebian Linux | 2/9/2016 | 17/6/2026 | QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds array access) via vectors related to the (1) PVSCSI_CMD_SETUP_RINGS or (2) PVSCSI_CMD_SETUP_MSG_RING SCSI command. | |
| Modificada | Media (5.5) | 0.52% | — | Canonical Ubuntu LinuxOracle LinuxOracle VM ServerQemu+9 | 2/8/2016 | 17/6/2026 | The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion. | |
| Modificada | Media (6) | 0.39% | — | QemuCanonical Ubuntu Linux | 16/6/2016 | 17/6/2026 | The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via crafted values for the PSTART and PSTOP registers, involving ring buffer control. | |
| Modificada | Alta (7.1) | 0.42% | — | Qemu | 16/6/2016 | 17/6/2026 | Multiple integer overflows in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 allow local guest OS administrators to cause a denial of service (QEMU process crash) or obtain sensitive host memory information via a remote NDIS control message packet that is mishandled in the (1)… | |
| Modificada | Media (6.5) | 0.42% | — | QemuCanonical Ubuntu Linux | 16/6/2016 | 17/6/2026 | The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configuration descriptor objects, which allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving a remote NDIS… | |
| Modificada | Media (5) | 0.40% | — | QemuCanonical Ubuntu LinuxDebian Linux | 16/6/2016 | 17/6/2026 | The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors related to multiple eof_timers. | |
| Modificada | Alta (7.8) | 0.50% | — | QemuCanonical Ubuntu LinuxDebian Linux | 14/6/2016 | 17/6/2026 | The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allow local guest OS administrators to cause a denial of service (QEMU process crash) or execute arbitrary code on the QEMU host via vectors related to the information transfer buffer. |