SPICE Spice vdagent是SPICE团队的一系列虚拟桌面代理软件。 Spice vdagent存在数字错误漏洞,该漏洞源于整数溢出问题,恶意或受损SPICE主机通过发送特制消息触发堆缓冲区溢出,导致spice-vdagent守护进程崩溃并造成虚拟机拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
any |
affected | ||
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12856 | 8.8 HIGH | Vscode-java: vscode: command injection vulnerability in the javadoc hover provider of the |
| CVE-2026-12912 | 7.3 HIGH | Libtiff: libtiff: heap-based buffer overflow via crafted pixarlog-compressed tiff image |
| CVE-2026-13601 | 7.1 HIGH | Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclos |
| CVE-2026-13595 | 6.8 MEDIUM | Util-linux: util-linux: heap use-after-free in libblkid nested partition probing |
| CVE-2026-13757 | 6.2 MEDIUM | P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing |
| CVE-2026-57966 | 4.4 MEDIUM | Spice-vdagent: path traversal in file transfer via unsanitized filename |
No comments yet