Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
448 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.56% | — | QemuOpensuse LeapFedoraproject FedoraCanonical Ubuntu Linux | 21/3/2019 | 17/6/2026 | In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value. | |
| Modificada | Media (5.5) | 0.43% | — | QemuFedoraproject FedoraCanonical Ubuntu LinuxOpensuse Leap | 19/2/2019 | 17/6/2026 | QEMU, through version 2.10 and through version 3.1.0, is vulnerable to an out-of-bounds read of up to 128 bytes in the hw/i2c/i2c-ddc.c:i2c_ddc() function. A local attacker with permission to execute i2c commands could exploit this to read stack memory of the qemu process on the host. | |
| Modificada | Alta (7.5) | 3.7% | — | QemuCanonical Ubuntu LinuxFedoraproject Fedora | 20/12/2018 | 17/6/2026 | hw/rdma/vmw/pvrdma_main.c in QEMU does not implement a read operation (such as uar_read by analogy to uar_write), which allows attackers to cause a denial of service (NULL pointer dereference). | |
| Modificada | Media (5.5) | 0.49% | — | QemuCanonical Ubuntu Linux | 20/12/2018 | 17/6/2026 | hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqWqe ring element with a large num_sge value. | |
| Modificada | Alta (7.5) | 3.9% | — | QemuCanonical Ubuntu Linux | 20/12/2018 | 17/6/2026 | QEMU can have an infinite loop in hw/rdma/vmw/pvrdma_dev_ring.c because return values are not checked (and -1 is mishandled). | |
| Modificada | Media (5.5) | 0.49% | — | QemuCanonical Ubuntu LinuxOpensuse Leap | 20/12/2018 | 17/6/2026 | hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled. | |
| Modificada | Alta (7.5) | 3.7% | — | QemuCanonical Ubuntu Linux | 20/12/2018 | 17/6/2026 | hw/rdma/vmw/pvrdma_cmd.c in QEMU allows attackers to cause a denial of service (NULL pointer dereference or excessive memory allocation) in create_cq_ring or create_qp_rings. | |
| Modificada | Media (5.5) | 0.49% | — | QemuCanonical Ubuntu LinuxFedoraproject Fedora | 17/12/2018 | 17/6/2026 | pvrdma_realize in hw/rdma/vmw/pvrdma_main.c in QEMU has a Memory leak after an initialisation error. | |
| Modificada | Media (5.3) | 1.1% | — | QemuDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+1 | 13/12/2018 | 17/6/2026 | A flaw was found in qemu Media Transfer Protocol (MTP). The code opening files in usb_mtp_get_object and usb_mtp_get_partial_object and directories in usb_mtp_object_readdir doesn't consider that the underlying filesystem may have changed since the time lstat(2) was called in usb_mtp_object_alloc, a classical TOCTTOU… | |
| Modificada | Media (4.7) | 0.40% | — | QemuDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+1 | 13/12/2018 | 17/6/2026 | v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) because of a race condition during file renaming. | |
| Modificada | Media (5.5) | 0.53% | — | QemuCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+1 | 13/12/2018 | 17/6/2026 | hw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is being accessed by a second thread, leading to (for example) a use-after-free outcome. | |
| Modificada | Alta (7.8) | 0.42% | — | QemuFedoraproject FedoraCanonical Ubuntu Linux | 12/12/2018 | 17/6/2026 | A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the in usb_mtp_write_data function in hw/usb/dev-mtp.c due to an improper filename sanitization. When the guest device is mounted in read-write mode, this allows to read/write arbitrary files which may lead do DoS scenario… | |
| Modificada | Media (5.7) | 0.94% | — | QemuOpensuse Leap | 6/12/2018 | 17/6/2026 | The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption. | |
| Modificada | Media (5.5) | 0.52% | — | QemuCanonical Ubuntu LinuxOpensuse Leap | 15/11/2018 | 17/6/2026 | The pnv_lpc_do_eccb function in hw/ppc/pnv_lpc.c in Qemu before 3.1 allows out-of-bounds write or read access to PowerNV memory. | |
| Modificada | Alta (7.8) | 0.54% | — | QemuCanonical Ubuntu Linux | 2/11/2018 | 17/6/2026 | An OOB heap buffer r/w access issue was found in the NVM Express Controller emulation in QEMU. It could occur in nvme_cmb_ops routines in nvme device. A guest user/process could use this flaw to crash the QEMU process resulting in DoS or potentially run arbitrary code with privileges of the QEMU process. | |
| Modificada | Media (5.5) | 0.44% | — | QemuRedhat Enterprise LinuxRedhat Openstack | 19/10/2018 | 17/6/2026 | Qemu has integer overflows because IOReadHandler and its associated functions use a signed integer data type for a size value. | |
| Modificada | Media (6.5) | 3.1% | — | QemuCanonical Ubuntu LinuxDebian Linux | 16/10/2018 | 17/6/2026 | Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS. | |
| Modificada | Crítica (9.8) | 4.7% | — | QemuDebian LinuxCanonical Ubuntu LinuxRedhat Openstack+2 | 9/10/2018 | 17/6/2026 | qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact. | |
| Modificada | Alta (7.5) | 4.5% | — | QemuCanonical Ubuntu LinuxDebian LinuxOracle Linux+2 | 9/10/2018 | 17/6/2026 | Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used. | |
| Modificada | Alta (7.5) | 6.3% | — | QemuCanonical Ubuntu LinuxDebian LinuxRedhat Virtualization+1 | 9/10/2018 | 17/6/2026 | Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used. | |
| Modificada | Media (5.5) | 0.50% | — | Qemu | 29/8/2018 | 17/6/2026 | qemu-seccomp.c in QEMU might allow local OS guest users to cause a denial of service (guest crash) by leveraging mishandling of the seccomp policy for threads other than the main thread. | |
| Modificada | Crítica (9.8) | 12% | 💥 Exploit | QemuCanonical Ubuntu LinuxRedhat Enterprise Linux | 27/7/2018 | 17/6/2026 | A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of size up to 4096 bytes, which in fact should be limited to 256 bytes, causing an out-of-bounds stack write in the qemu process. If NBD server requires TLS, the attacker… | |
| Modificada | Crítica (9.9) | 4.4% | — | QemuCitrix XenserverRedhat OpenstackDebian Linux+5 | 27/7/2018 | 17/6/2026 | A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU… | |
| Modificada | Media (6.5) | 3.0% | — | QemuRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+2 | 27/7/2018 | 17/6/2026 | An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use this flaw to crash the QEMU process. | |
| Modificada | Crítica (9.9) | 3.6% | — | QemuCitrix XenserverRedhat OpenstackDebian Linux+6 | 27/7/2018 | 17/6/2026 | Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary… |