Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

448 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.56%—QemuOpensuse LeapFedoraproject FedoraCanonical Ubuntu Linux21/3/201917/6/2026
In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value.
ModificadaMedia (5.5)0.43%—QemuFedoraproject FedoraCanonical Ubuntu LinuxOpensuse Leap19/2/201917/6/2026
QEMU, through version 2.10 and through version 3.1.0, is vulnerable to an out-of-bounds read of up to 128 bytes in the hw/i2c/i2c-ddc.c:i2c_ddc() function. A local attacker with permission to execute i2c commands could exploit this to read stack memory of the qemu process on the host.
ModificadaAlta (7.5)3.7%—QemuCanonical Ubuntu LinuxFedoraproject Fedora20/12/201817/6/2026
hw/rdma/vmw/pvrdma_main.c in QEMU does not implement a read operation (such as uar_read by analogy to uar_write), which allows attackers to cause a denial of service (NULL pointer dereference).
ModificadaMedia (5.5)0.49%—QemuCanonical Ubuntu Linux20/12/201817/6/2026
hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqWqe ring element with a large num_sge value.
ModificadaAlta (7.5)3.9%—QemuCanonical Ubuntu Linux20/12/201817/6/2026
QEMU can have an infinite loop in hw/rdma/vmw/pvrdma_dev_ring.c because return values are not checked (and -1 is mishandled).
ModificadaMedia (5.5)0.49%—QemuCanonical Ubuntu LinuxOpensuse Leap20/12/201817/6/2026
hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled.
ModificadaAlta (7.5)3.7%—QemuCanonical Ubuntu Linux20/12/201817/6/2026
hw/rdma/vmw/pvrdma_cmd.c in QEMU allows attackers to cause a denial of service (NULL pointer dereference or excessive memory allocation) in create_cq_ring or create_qp_rings.
ModificadaMedia (5.5)0.49%—QemuCanonical Ubuntu LinuxFedoraproject Fedora17/12/201817/6/2026
pvrdma_realize in hw/rdma/vmw/pvrdma_main.c in QEMU has a Memory leak after an initialisation error.
ModificadaMedia (5.3)1.1%—QemuDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+113/12/201817/6/2026
A flaw was found in qemu Media Transfer Protocol (MTP). The code opening files in usb_mtp_get_object and usb_mtp_get_partial_object and directories in usb_mtp_object_readdir doesn't consider that the underlying filesystem may have changed since the time lstat(2) was called in usb_mtp_object_alloc, a classical TOCTTOU…
ModificadaMedia (4.7)0.40%—QemuDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+113/12/201817/6/2026
v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) because of a race condition during file renaming.
ModificadaMedia (5.5)0.53%—QemuCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+113/12/201817/6/2026
hw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is being accessed by a second thread, leading to (for example) a use-after-free outcome.
ModificadaAlta (7.8)0.42%—QemuFedoraproject FedoraCanonical Ubuntu Linux12/12/201817/6/2026
A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the in usb_mtp_write_data function in hw/usb/dev-mtp.c due to an improper filename sanitization. When the guest device is mounted in read-write mode, this allows to read/write arbitrary files which may lead do DoS scenario…
ModificadaMedia (5.7)0.94%—QemuOpensuse Leap6/12/201817/6/2026
The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption.
ModificadaMedia (5.5)0.52%—QemuCanonical Ubuntu LinuxOpensuse Leap15/11/201817/6/2026
The pnv_lpc_do_eccb function in hw/ppc/pnv_lpc.c in Qemu before 3.1 allows out-of-bounds write or read access to PowerNV memory.
ModificadaAlta (7.8)0.54%—QemuCanonical Ubuntu Linux2/11/201817/6/2026
An OOB heap buffer r/w access issue was found in the NVM Express Controller emulation in QEMU. It could occur in nvme_cmb_ops routines in nvme device. A guest user/process could use this flaw to crash the QEMU process resulting in DoS or potentially run arbitrary code with privileges of the QEMU process.
ModificadaMedia (5.5)0.44%—QemuRedhat Enterprise LinuxRedhat Openstack19/10/201817/6/2026
Qemu has integer overflows because IOReadHandler and its associated functions use a signed integer data type for a size value.
ModificadaMedia (6.5)3.1%—QemuCanonical Ubuntu LinuxDebian Linux16/10/201817/6/2026
Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS.
ModificadaCrítica (9.8)4.7%—QemuDebian LinuxCanonical Ubuntu LinuxRedhat Openstack+29/10/201817/6/2026
qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact.
ModificadaAlta (7.5)4.5%—QemuCanonical Ubuntu LinuxDebian LinuxOracle Linux+29/10/201817/6/2026
Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used.
ModificadaAlta (7.5)6.3%—QemuCanonical Ubuntu LinuxDebian LinuxRedhat Virtualization+19/10/201817/6/2026
Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used.
ModificadaMedia (5.5)0.50%—Qemu29/8/201817/6/2026
qemu-seccomp.c in QEMU might allow local OS guest users to cause a denial of service (guest crash) by leveraging mishandling of the seccomp policy for threads other than the main thread.
ModificadaCrítica (9.8)12%💥 ExploitQemuCanonical Ubuntu LinuxRedhat Enterprise Linux27/7/201817/6/2026
A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of size up to 4096 bytes, which in fact should be limited to 256 bytes, causing an out-of-bounds stack write in the qemu process. If NBD server requires TLS, the attacker…
ModificadaCrítica (9.9)4.4%—QemuCitrix XenserverRedhat OpenstackDebian Linux+527/7/201817/6/2026
A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU…
ModificadaMedia (6.5)3.0%—QemuRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+227/7/201817/6/2026
An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use this flaw to crash the QEMU process.
ModificadaCrítica (9.9)3.6%—QemuCitrix XenserverRedhat OpenstackDebian Linux+627/7/201817/6/2026
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary…
Orbitaley — Vulnerabilidades