← Back

CVE-2016-0749

nvd nist
Published: Jun 9, 2016Modified: May 6, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecting to a guest VM, which triggers a heap-based buffer overflow.

Affected (17)

Show all products
2 products
Leap
Opensuse
1 product
Debian Linux
7 products
Enterprise Linux
Enterprise Linux Desktop
Enterprise Linux Server
Enterprise Linux Workstation
Enterprise Linux Hpc Node Eus
Enterprise Linux Server Aus
Enterprise Linux Server Eus
1 product
Spice
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 42.1
Version 13.2
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Configuration C
5 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 6.0
Version 6.0
Version 6.0
Version 6.0
Version 6.0
Configuration D
8 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Redhat
Version 7.0
Version 7.0
Version 7.0
Version 7.2
Version 7.0
Version 7.2
Version 7.2
Version 7.0
Running on/withPlatform Versions
Microsoft
Windows
All versions
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (16)

Timeline

No history available yet.