6.5
CVSSv3

CVE-2015-5278

Published: 23/01/2020 Updated: 30/11/2021
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

The ne2000_receive function in hw/net/ne2000.c in QEMU prior to 2.4.0.1 allows malicious users to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu

fedoraproject fedora 21

fedoraproject fedora 22

fedoraproject fedora 23

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

canonical ubuntu linux 15.04

arista eos 4.12

arista eos 4.13

arista eos 4.14

arista eos 4.15

Vendor Advisories

Several security issues were fixed in QEMU ...
Debian Bug report logs - #799073 qemu: CVE-2015-5278: Infinite loop in ne2000_receive() function Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 15 Sep 2015 16:03:02 UTC Severity: important Tags: ...
Debian Bug report logs - #799074 qemu: CVE-2015-5279: Heap overflow vulnerability in ne2000_receive() function Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 15 Sep 2015 16:09:02 UTC Severity: im ...
Several vulnerabilities were discovered in qemu-kvm, a full virtualization solution on x86 hardware CVE-2015-5278 Qinghao Tang of QIHU 360 Inc discovered an infinite loop issue in the NE2000 NIC emulation A privileged guest user could use this flaw to mount a denial of service (QEMU process crash) CVE-2015-5279 Qinghao Tang of ...
Several vulnerabilities were discovered in qemu, a fast processor emulator CVE-2015-5278 Qinghao Tang of QIHU 360 Inc discovered an infinite loop issue in the NE2000 NIC emulation A privileged guest user could use this flaw to mount a denial of service (QEMU process crash) CVE-2015-5279 Qinghao Tang of QIHU 360 Inc discovered ...