Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

448 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.5)0.87%—QemuOpensuse LeapDebian LinuxCanonical Ubuntu Linux5/3/202017/6/2026
QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd.
ModificadaMedia (6)4.0%—QemuRedhat OpenstackRedhat Enterprise LinuxDebian Linux+111/2/202017/6/2026
An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Block (LBA) in an iscsi_co_block_status() routine. A remote user could use this flaw to crash the QEMU…
ModificadaAlta (8.8)0.96%—QemuRedhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+211/2/202016/6/2026
The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm image, related to virtio-block or virtio-serial read.
ModificadaBaja (3.5)0.98%—QemuFedoraproject FedoraNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+731/1/202017/6/2026
The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors.
ModificadaMedia (6.5)3.0%—QemuFedoraproject FedoraArista EOS23/1/202017/6/2026
Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial of service (QEMU process crash) via a crafted virtio control message.
ModificadaMedia (6.5)2.3%—QemuFedoraproject FedoraCanonical Ubuntu LinuxArista EOS23/1/202017/6/2026
The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets.
ModificadaMedia (6.5)3.6%—QemuFedoraproject FedoraCanonical Ubuntu LinuxSuse Linux Enterprise Debuginfo+423/1/202017/6/2026
Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.
ModificadaAlta (7.5)4.2%—Libslirp Project LibslirpQemu21/1/202017/6/2026
tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows.
ModificadaMedia (5.6)3.6%—Libslirp Project LibslirpQemuDebian LinuxOpensuse Leap16/1/202017/6/2026
tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.
ModificadaAlta (7.8)0.46%—QemuCanonical Ubuntu LinuxDebian Linux2/1/202016/6/2026
Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.
ModificadaAlta (7.5)3.4%—Qemu31/12/201917/6/2026
An issue was discovered in ide_dma_cb() in hw/ide/core.c in QEMU 2.4.0 through 4.2.0. The guest system can crash the QEMU process in the host system via a special SCSI_IOCTL_SEND_COMMAND. It hits an assertion that implies that the size of successful DMA transfers there must be a multiple of 512 (the size of a sector).…
ModificadaAlta (7.8)0.51%—QemuDebian LinuxNovell Open Desktop ServerNovell Open Enterprise Server30/12/201916/6/2026
A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the matching host's qemu address space and thus…
ModificadaBaja (3.8)0.51%—QemuCanonical Ubuntu LinuxOpensuse Leap24/9/201917/6/2026
In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read next opcode. This can lead to an infinite loop if the next opcode is…
ModificadaAlta (7.5)4.0%—Libslirp Project LibslirpQemu6/9/201917/6/2026
libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_input.c.
ModificadaAlta (7.8)0.52%—QemuDebian LinuxOpensuse LeapCanonical Ubuntu Linux3/7/201917/6/2026
qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass.
ModificadaCrítica (9.8)4.9%—Qemu24/6/201917/6/2026
The QMP guest_exec command in QEMU 4.0.0 and earlier is prone to OS command injection, which allows the attacker to achieve code execution, denial of service, or information disclosure by sending a crafted QMP command to the listening server. Note: This has been disputed as a non-issue since QEMU's -qmp interface is…
ModificadaCrítica (9.8)23%💥 ExploitQemu24/6/201917/6/2026
The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote attacker to achieve code execution, denial of service, or information disclosure by sending a crafted QMP command to the listening server. Note: This has been disputed as a non-issue since QEMU's…
ModificadaMedia (5.5)0.52%—Qemu3/6/201917/6/2026
tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure.
ModificadaCrítica (9.8)4.4%—Qemu31/5/201917/6/2026
In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated load_image function, which has a buffer overflow risk.
ModificadaAlta (7.5)5.5%—Qemu24/5/201917/6/2026
interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference.
ModificadaAlta (7.5)3.0%—Qemu22/5/201917/6/2026
QEMU 3.0.0 has an Integer Overflow because the qga/commands*.c files do not check the length of the argument list or the number of environment variables. NOTE: This has been disputed as not exploitable
ModificadaAlta (7.5)2.8%—Qemu19/4/201917/6/2026
hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, which allows the attacker to cause a denial of service via a device driver.
ModificadaBaja (3.3)0.60%—QemuOpensuse Leap21/3/201917/6/2026
hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/system-id and /proc/device-tree/model system attributes with a guest.
ModificadaAlta (7.8)0.61%—QemuOpensuse LeapFedoraproject FedoraCanonical Ubuntu Linux21/3/201917/6/2026
In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.
ModificadaMedia (5.5)0.56%—QemuFedoraproject Fedora21/3/201917/6/2026
In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations.