QEMU(Quick Emulator)是法国法布里斯-贝拉(Fabrice Bellard)个人开发者的一套模拟处理器软件。该软件具有速度快、跨平台等特点。 QEMU 存在安全漏洞,该漏洞源于其Tulip设备仿真中发现了DMA重入问题。当 Tulip 读取或写入 rx/tx 描述符或复制 rx/tx 帧时,它不会检查目标地址是否为其自己的MMIO地址。这可能导致设备多次触发MMIO处理程序,从而导致栈或堆的缓冲区溢出。攻击者可能使用此漏洞使主机上的QEMU 进程崩溃,从而导致拒绝服务情况。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | QEMU | Will be fixed in QEMU 7.2.0-rc0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-38342 | 8.5 HIGH | Safe Software FME Server 代码问题漏洞 |
| CVE-2022-20386 | Google Android 安全漏洞 | |
| CVE-2022-38616 | SmartVista SVFE2 SQL注入漏洞 | |
| CVE-2022-38537 | Archery SQL注入漏洞 | |
| CVE-2022-38329 | Shopxian CMS 跨站请求伪造漏洞 | |
| CVE-2022-37703 | Amanda 路径遍历漏洞 | |
| CVE-2021-0697 | Google Pixel 资源管理错误漏洞 | |
| CVE-2021-0871 | Google Pixel 输入验证错误漏洞 | |
| CVE-2021-0942 | Google Pixel 缓冲区错误漏洞 | |
| CVE-2021-0943 | Google Pixel 缓冲区错误漏洞 | |
| CVE-2022-20385 | Google Android 缓冲区错误漏洞 | |
| CVE-2022-3170 | Linux kernel 缓冲区错误漏洞 | |
| CVE-2022-20387 | Google Android 安全漏洞 | |
| CVE-2022-20388 | Google Android 安全漏洞 | |
| CVE-2022-20389 | Google Android 安全漏洞 | |
| CVE-2022-20390 | Google Android 安全漏洞 | |
| CVE-2022-20391 | Google Android 安全漏洞 | |
| CVE-2022-20392 | Google Android 输入验证错误漏洞 | |
| CVE-2022-20393 | Google Android 数字错误漏洞 | |
| CVE-2022-20395 | Google Android 路径遍历漏洞 |
Showing top 20 of 63 CVEs. View all on vendor page → →
No comments yet