Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
448 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.5) | 0.87% | — | QemuOpensuse LeapDebian LinuxCanonical Ubuntu Linux | 5/3/2020 | 17/6/2026 | QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd. | |
| Modificada | Media (6) | 4.0% | — | QemuRedhat OpenstackRedhat Enterprise LinuxDebian Linux+1 | 11/2/2020 | 17/6/2026 | An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Block (LBA) in an iscsi_co_block_status() routine. A remote user could use this flaw to crash the QEMU… | |
| Modificada | Alta (8.8) | 0.96% | — | QemuRedhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 11/2/2020 | 16/6/2026 | The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm image, related to virtio-block or virtio-serial read. | |
| Modificada | Baja (3.5) | 0.98% | — | QemuFedoraproject FedoraNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+7 | 31/1/2020 | 17/6/2026 | The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors. | |
| Modificada | Media (6.5) | 3.0% | — | QemuFedoraproject FedoraArista EOS | 23/1/2020 | 17/6/2026 | Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial of service (QEMU process crash) via a crafted virtio control message. | |
| Modificada | Media (6.5) | 2.3% | — | QemuFedoraproject FedoraCanonical Ubuntu LinuxArista EOS | 23/1/2020 | 17/6/2026 | The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets. | |
| Modificada | Media (6.5) | 3.6% | — | QemuFedoraproject FedoraCanonical Ubuntu LinuxSuse Linux Enterprise Debuginfo+4 | 23/1/2020 | 17/6/2026 | Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop. | |
| Modificada | Alta (7.5) | 4.2% | — | Libslirp Project LibslirpQemu | 21/1/2020 | 17/6/2026 | tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows. | |
| Modificada | Media (5.6) | 3.6% | — | Libslirp Project LibslirpQemuDebian LinuxOpensuse Leap | 16/1/2020 | 17/6/2026 | tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.46% | — | QemuCanonical Ubuntu LinuxDebian Linux | 2/1/2020 | 16/6/2026 | Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process. | |
| Modificada | Alta (7.5) | 3.4% | — | Qemu | 31/12/2019 | 17/6/2026 | An issue was discovered in ide_dma_cb() in hw/ide/core.c in QEMU 2.4.0 through 4.2.0. The guest system can crash the QEMU process in the host system via a special SCSI_IOCTL_SEND_COMMAND. It hits an assertion that implies that the size of successful DMA transfers there must be a multiple of 512 (the size of a sector).… | |
| Modificada | Alta (7.8) | 0.51% | — | QemuDebian LinuxNovell Open Desktop ServerNovell Open Enterprise Server | 30/12/2019 | 16/6/2026 | A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the matching host's qemu address space and thus… | |
| Modificada | Baja (3.8) | 0.51% | — | QemuCanonical Ubuntu LinuxOpensuse Leap | 24/9/2019 | 17/6/2026 | In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read next opcode. This can lead to an infinite loop if the next opcode is… | |
| Modificada | Alta (7.5) | 4.0% | — | Libslirp Project LibslirpQemu | 6/9/2019 | 17/6/2026 | libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_input.c. | |
| Modificada | Alta (7.8) | 0.52% | — | QemuDebian LinuxOpensuse LeapCanonical Ubuntu Linux | 3/7/2019 | 17/6/2026 | qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass. | |
| Modificada | Crítica (9.8) | 4.9% | — | Qemu | 24/6/2019 | 17/6/2026 | The QMP guest_exec command in QEMU 4.0.0 and earlier is prone to OS command injection, which allows the attacker to achieve code execution, denial of service, or information disclosure by sending a crafted QMP command to the listening server. Note: This has been disputed as a non-issue since QEMU's -qmp interface is… | |
| Modificada | Crítica (9.8) | 23% | 💥 Exploit | Qemu | 24/6/2019 | 17/6/2026 | The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote attacker to achieve code execution, denial of service, or information disclosure by sending a crafted QMP command to the listening server. Note: This has been disputed as a non-issue since QEMU's… | |
| Modificada | Media (5.5) | 0.52% | — | Qemu | 3/6/2019 | 17/6/2026 | tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure. | |
| Modificada | Crítica (9.8) | 4.4% | — | Qemu | 31/5/2019 | 17/6/2026 | In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated load_image function, which has a buffer overflow risk. | |
| Modificada | Alta (7.5) | 5.5% | — | Qemu | 24/5/2019 | 17/6/2026 | interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference. | |
| Modificada | Alta (7.5) | 3.0% | — | Qemu | 22/5/2019 | 17/6/2026 | QEMU 3.0.0 has an Integer Overflow because the qga/commands*.c files do not check the length of the argument list or the number of environment variables. NOTE: This has been disputed as not exploitable | |
| Modificada | Alta (7.5) | 2.8% | — | Qemu | 19/4/2019 | 17/6/2026 | hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, which allows the attacker to cause a denial of service via a device driver. | |
| Modificada | Baja (3.3) | 0.60% | — | QemuOpensuse Leap | 21/3/2019 | 17/6/2026 | hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/system-id and /proc/device-tree/model system attributes with a guest. | |
| Modificada | Alta (7.8) | 0.61% | — | QemuOpensuse LeapFedoraproject FedoraCanonical Ubuntu Linux | 21/3/2019 | 17/6/2026 | In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow. | |
| Modificada | Media (5.5) | 0.56% | — | QemuFedoraproject Fedora | 21/3/2019 | 17/6/2026 | In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations. |