Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
spice vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2002-1628
Directory traversal vulnerability in vote.cgi for Mike Spice Mike's Vote CGI prior to 1.3 allows remote malicious users to write arbitrary files via .. (dot dot) sequences in the type parameter.
Mike Spice Mikes Vote Cgi 1.1
Mike Spice Mikes Vote Cgi 1.0
Mike Spice Mikes Vote Cgi 1.2
2.1
CVSSv2
CVE-2020-25650
A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/spice-vdagent-sock` could use this flaw to perform a memory ...
Spice-space Spice-vdagent
Debian Debian Linux 9.0
Fedoraproject Fedora 32
Fedoraproject Fedora 33
3.3
CVSSv2
CVE-2020-25651
A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of ...
Spice-space Spice-vdagent
Debian Debian Linux 9.0
Fedoraproject Fedora 32
Fedoraproject Fedora 33
4.9
CVSSv2
CVE-2020-25652
A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be established via the UNIX domain socket in `/run/spice-vdagentd/spice-vdagent-sock`. Any unprivileged local guest user could use this flaw to prevent legitimate agents fr...
Spice-space Spice-vdagent
Debian Debian Linux 9.0
Fedoraproject Fedora 32
Fedoraproject Fedora 33
5.4
CVSSv2
CVE-2020-25653
A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw may allow an unprivileged local guest user to become the active agent for spice-vdagentd, possibly resulting in a denial of service or information leakage from ...
Spice-space Spice-vdagent
Debian Debian Linux 9.0
Fedoraproject Fedora 32
Fedoraproject Fedora 33
5
CVSSv2
CVE-2021-20201
A flaw was found in spice in versions prior to 0.14.92. A DoS tool might make it easier for remote malicious users to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection.
Spice Project Spice
Redhat Enterprise Linux 7.0
Redhat Enterprise Linux 6.0
Redhat Enterprise Linux 8.0
5
CVSSv2
CVE-2013-4282
Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote malicious users to cause a denial of service (crash) via a long password in a SPICE ticket.
Spice Project Spice 0.12.0
Redhat Enterprise Linux 6.0
Redhat Enterprise Virtualization 3.0
Redhat Enterprise Linux 5
3.3
CVSSv2
CVE-2010-2792
Race condition in the SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to obtain sensitive information, and conduct man-in-the-middle attacks, by providing a UNIX socket for communication between this plug-in and the client (aka qspice-client) in qspice 0.3.0, and...
Redhat Spice-xpi 2.2
3.3
CVSSv2
CVE-2010-2794
The SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to overwrite arbitrary files via a symlink attack on an unspecified log file.
Redhat Spice-xpi 2.2
5
CVSSv2
CVE-2002-1627
Directory traversal vulnerability in quiz.cgi for Mike Spice Quiz Me! prior to 0.6 allows remote malicious users to write arbitrary files via .. (dot dot) sequences in the quiz parameter.
Mike Spice Quiz Me 0.5
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37884
CVE-2024-6003
remote
brute force
information disclosure
CVE-2024-27801
CVE-2024-30078
CVE-2024-31870
CVE-2024-6042
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »