Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
448 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.8) | 0.20% | — | QemuAI | 20/9/2024 | 17/6/2026 | A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complete / virito_crypto_req_complete could be larger than the true size of the data which has been sent to guest. Once virtqueue_push() finally calls… | |
| Modificada | Media (5.5) | 0.29% | — | QemuRedhat Enterprise Linux | 19/9/2024 | 17/6/2026 | A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition. | |
| Aplazada | Media (4.3) | 0.55% | — | Openstack IronicAIOpenstack Ironic-python-agentAIQemu-imgAI | 6/9/2024 | 17/6/2026 | In OpenStack Ironic before 26.0.1 and ironic-python-agent before 9.13.1, there is a vulnerability in image processing, in which a crafted image could be used by an authenticated user to exploit undesired behaviors in qemu-img, including possible unauthorized access to potentially sensitive data. The affected/fixed… | |
| Aplazada | Alta (7.5) | 1.0% | — | QemuAI | 5/8/2024 | 1/9/2026 | A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline. | |
| Modificada | Media (6.8) | 0.66% | — | QemuRedhat Enterprise Linux | 5/7/2024 | 17/6/2026 | A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within RSS becomes controllable. Setting excessively large values may cause an index out-of-bounds issue, potentially resulting in heap overflow access. This flaw allows a… | |
| Aplazada | Alta (7.8) | 0.34% | — | Qemu-imgAI | 2/7/2024 | 17/6/2026 | A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices in QMP could cause the qemu-img process on the host to consume large amounts of memory or CPU time, leading to denial of service or read/write to an existing… | |
| Aplazada | Media (5.5) | 0.32% | — | QemuAI | 14/5/2024 | 17/6/2026 | A flaw was found in the QEMU Virtio PCI Bindings (hw/virtio/virtio-pci.c). An improper release and use of the irqfd for vector 0 during the boot process leads to a guest triggerable crash via vhost_net_stop(). This flaw allows a malicious guest to crash the QEMU process on the host. | |
| Modificada | Media (5.5) | 0.45% | — | QemuRedhat Enterprise Linux | 10/4/2024 | 17/6/2026 | A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c when trying to calculate the checksum of a short-sized fragmented packet. This flaw allows a malicious guest to crash QEMU and cause a denial of service condition. | |
| Aplazada | Alta (8.2) | 0.30% | — | QemuAIQemu Virtio GPUAIQemu Virtio Serial BUSAIQemu Virtio CryptoAI | 9/4/2024 | 17/6/2026 | A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest user to crash the QEMU process on the host, resulting in a denial… | |
| Analizada | Alta (8.8) | 1.4% | — | Qemu | 20/2/2024 | 17/6/2026 | QEMU before 8.2.0 has an integer underflow, and resultant buffer overflow, via a TI command when an expected non-DMA transfer length is less than the length of the available FIFO data. This occurs in esp_do_nodma in hw/scsi/esp.c because of an underflow of async_len. | |
| Analizada | Media (6) | 0.29% | — | Qemu | 19/2/2024 | 17/6/2026 | An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIOV_TOTAL_VF, and thus interaction with hw/nvme/ctrl.c is mishandled. | |
| Analizada | Media (5.3) | 0.60% | — | Qemu | 19/2/2024 | 17/6/2026 | An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF implementations. | |
| Analizada | Media (6.5) | 1.3% | — | QemuRedhat Enterprise Linux | 12/1/2024 | 17/6/2026 | A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() was called and had the chance to initialize the clipboard peer, leading to a NULL pointer dereference. This could allow a malicious… | |
| Modificada | Media (5.3) | 0.33% | — | QemuRedhat Enterprise LinuxFedoraproject Fedora | 2/1/2024 | 17/6/2026 | A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virtio_net_flush_tx function if guest features VIRTIO_NET_F_HASH_REPORT, VIRTIO_F_VERSION_1 and VIRTIO_NET_F_MRG_RXBUF are enabled. This could allow a malicious user to overwrite local variables… | |
| Modificada | Alta (7.1) | 0.38% | — | Qemu | 6/12/2023 | 17/6/2026 | A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit opening special files on the host side, potentially allowing a malicious client to escape from the exported 9p tree by creating and opening a device file in the shared folder. | |
| Modificada | Alta (7) | 0.23% | — | QemuRedhat Enterprise Linux | 3/11/2023 | 17/6/2026 | A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potentially overwriting the VM's boot code). This could be used, for example, by L2 guests with a virtual disk (vdiskL2) stored on a virtual disk of an L1 (vdiskL1) hypervisor to read… | |
| Modificada | Media (5.6) | 0.26% | — | QemuRedhat Enterprise Linux | 13/9/2023 | 17/6/2026 | A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service. | |
| Modificada | Media (6.5) | 1.9% | — | QemuRedhat Enterprise LinuxFedoraproject Fedora | 13/9/2023 | 17/6/2026 | A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lead to an infinite loop when inflating an attacker controlled zlib buffer in the `inflate_buffer` function. This could allow a remote authenticated client who is able to send a clipboard to the VNC… | |
| Modificada | Alta (8.2) | 0.24% | — | QemuRedhat Enterprise Linux | 13/9/2023 | 17/6/2026 | This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for Red Hat Enterprise Linux 9.1 via RHSA-2022:7967 included a version of qemu-kvm that was actually missing the fix for CVE-2021-3750. | |
| Modificada | Media (5.5) | 0.41% | — | Qemu | 11/9/2023 | 17/6/2026 | QEMU through 8.0.0 could trigger a division by zero in scsi_disk_reset in hw/scsi/scsi-disk.c because scsi_disk_emulate_mode_select does not prevent s->qdev.blocksize from being 256. This stops QEMU and the guest immediately. | |
| Modificada | Alta (8.8) | 0.70% | — | QemuDebian Linux | 28/8/2023 | 17/6/2026 | An issue was discovered in TCG Accelerator in QEMU 4.2.0, allows local attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS). Note: This is disputed as a bug and not a valid security issue by multiple third parties. | |
| Modificada | Crítica (10) | 1.7% | — | Qemu | 22/8/2023 | 17/6/2026 | The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier, allows remote attackers to crash the host qemu and potentially execute code on the host via execute a malformed program in the guest OS. Note: This has been disputed by multiple third parties as not a… | |
| Modificada | Media (5.5) | 0.36% | — | Qemu | 14/8/2023 | 17/6/2026 | QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/ctrl.c because there is no check for whether an endurance group is configured before checking whether Flexible Data Placement is enabled. | |
| Modificada | Media (6.5) | 0.37% | — | QemuFedoraproject Fedora | 4/8/2023 | 17/6/2026 | A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate an offset provided by the guest before computing a host heap pointer, which is used for copying data back to the guest. Arbitrary heap memory relative to an allocated buffer can be disclosed. | |
| Modificada | Media (6.5) | 0.23% | — | QemuFedoraproject FedoraDebian Linux | 3/8/2023 | 17/6/2026 | A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption requests in virtio_crypto_handle_sym_req. There is no check for the value of `src_len` and `dst_len` in virtio_crypto_sym_op_helper, potentially leading to a heap buffer overflow when the two values differ. |