← Back

Qemu

qemu

Vendor: Qemu • 419 CVEs

CVEs (419)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Canonical
DebianQemu
3Debian Linux
QemuUbuntu Linux
May 6, 2026
Nov 14, 2014
N/A· v4
N/A· v3
7.2 HIGH· v2
The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecified parameters related to rectangle handling.
4Canonical
DebianQemu+1 more
7Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+4 more
May 6, 2026
Nov 7, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which trigger...Show more
The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized socket.Show less
1Qemu
1Qemu
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
hw/usb/bus.c in QEMU 1.6.2 allows remote attackers to execute arbitrary code via crafted savevm data, which triggers a heap-based buffer overflow, related to "USB post load checks."
2Qemu
Suse
2Linux Enterprise Server
Qemu
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a large image size, which triggers a buffer...Show more
Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a large image size, which triggers a buffer overflow or out-of-bounds read.Show less
2Qemu
Suse
2Linux Enterprise Server
Qemu
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service (crash) via a large L2 table in a QCOW version 1 image.
1Qemu
1Qemu
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted config length in a savevm image.
1Qemu
1Qemu
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Array index error in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image.
1Qemu
1Qemu
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds array access.
1Qemu
1Qemu
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The usb_device_post_load function in hw/usb/bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, related to a negative setup_len or setup_index value.
2Opensuse
Qemu
2Opensuse
Qemu
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in scoop_gpio_handler_update in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a large (1) prev_level, (2) gpio_level, or (3) gpio_dir value in a savevm image.
1Qemu
1Qemu
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple buffer overflows in the tsc210x_load function in hw/input/tsc210x.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted (1) precision, (2) nextprecision, (3) function, or (4...Show more
Multiple buffer overflows in the tsc210x_load function in hw/input/tsc210x.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted (1) precision, (2) nextprecision, (3) function, or (4) nextfunction value in a savevm image.Show less
1Qemu
1Qemu
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple buffer overflows in the ssd0323_load function in hw/display/ssd0323.c in QEMU before 1.7.2 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted (...Show more
Multiple buffer overflows in the ssd0323_load function in hw/display/ssd0323.c in QEMU before 1.7.2 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted (1) cmd_len, (2) row, or (3) col values; (4) row_start and row_end values; or (5) col_star and col_end values in a savevm image.Show less
1Qemu
1Qemu
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a savevm image.
1Qemu
1Qemu
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in hw/intc/openpic.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via vectors related to IRQDest elements.
1Qemu
1Qemu
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the pxa2xx_ssp_load function in hw/arm/pxa2xx.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted s->rx_level value in a savevm...Show more
Buffer overflow in the pxa2xx_ssp_load function in hw/arm/pxa2xx.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted s->rx_level value in a savevm image.Show less
1Qemu
1Qemu
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in target-arm/machine.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a negative value in cpreg_vmstate_array_len in a savevm image.
1Qemu
1Qemu
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in hw/ssi/pl022.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted tx_fifo_head and rx_fifo_head values in a savevm image.
1Qemu
1Qemu
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in hw/pci/pcie_aer.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large log_num value in a savevm image.
1Qemu
1Qemu
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in hw/timer/hpet.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via vectors related to the number of timers.
1Qemu
1Qemu
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in hw/ide/ahci.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via vectors related to migrating ports.