Latest CVE Feed
-
7.5
HIGHCVE-2013-4542
The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds array access.... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4541
The usb_device_post_load function in hw/usb/bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, related to a negative setup_len or setup_index value.... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4540
Buffer overflow in scoop_gpio_handler_update in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a large (1) prev_level, (2) gpio_level, or (3) gpio_dir value in a savevm image.... Read more
- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4539
Multiple buffer overflows in the tsc210x_load function in hw/input/tsc210x.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted (1) precision, (2) nextprecision, (3) function, or (4) nextfunction value in a savevm im... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4538
Multiple buffer overflows in the ssd0323_load function in hw/display/ssd0323.c in QEMU before 1.7.2 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted (1) cmd_len, (2) row, or (3) col val... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4537
The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a savevm image.... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4534
Buffer overflow in hw/intc/openpic.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via vectors related to IRQDest elements.... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4533
Buffer overflow in the pxa2xx_ssp_load function in hw/arm/pxa2xx.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted s->rx_level value in a savevm image.... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4531
Buffer overflow in target-arm/machine.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a negative value in cpreg_vmstate_array_len in a savevm image.... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4530
Buffer overflow in hw/ssi/pl022.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted tx_fifo_head and rx_fifo_head values in a savevm image.... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4529
Buffer overflow in hw/pci/pcie_aer.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large log_num value in a savevm image.... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4527
Buffer overflow in hw/timer/hpet.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via vectors related to the number of timers.... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4526
Buffer overflow in hw/ide/ahci.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via vectors related to migrating ports.... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4151
The virtio_load function in virtio/virtio.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds write.... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4150
The virtio_net_load function in hw/net/virtio-net.c in QEMU 1.5.0 through 1.7.x before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via vectors in which the value of curr_queues is greater than max_queues, ... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4149
Buffer overflow in virtio_net_load function in net/virtio-net.c in QEMU 1.3.0 through 1.7.x before 1.7.2 might allow remote attackers to execute arbitrary code via a large MAC table.... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4148
Integer signedness error in the virtio_net_load function in hw/net/virtio-net.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, which triggers a buffer overflow.... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-8474
CA Cloud Service Management (CSM) before Summer 2014 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML document containing an external entity decla... Read more
Affected Products : cloud_service_management- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-8473
Cross-site request forgery (CSRF) vulnerability in CA Cloud Service Management (CSM) before Summer 2014 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.... Read more
Affected Products : cloud_service_management- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-8472
CA Cloud Service Management (CSM) before Summer 2014 does not properly verify authentication tokens from an Identity Provider, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors.... Read more
Affected Products : cloud_service_management- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025