9.8
CVSSv3

CVE-2017-8380

Published: 28/08/2017 Updated: 06/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in the "megasas_mmio_write" function in Qemu 2.9.0 allows remote malicious users to have unspecified impact via unknown vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu 2.9.0

Vendor Advisories

Several security issues were fixed in QEMU ...
USN-3414-1 introduced a regression in QEMU ...
Debian Bug report logs - #860785 qemu: CVE-2017-7471: 9p: virtfs allows guest to change filesystem attributes on host Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 20 Apr 2017 05:18:02 UTC Sever ...
Debian Bug report logs - #861348 qemu: CVE-2017-8086: 9pfs: host memory leakage via v9pfs_list_xattr Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 27 Apr 2017 19:45:02 UTC Severity: normal Tags: ...
Debian Bug report logs - #861351 qemu: CVE-2017-8112: scsi: vmw_pvscsi: infinite loop in pvscsi_log2 Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 27 Apr 2017 20:09:01 UTC Severity: normal Tags ...
Debian Bug report logs - #862289 qemu: CVE-2017-8379: host memory lekage via keyboard events Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 10 May 2017 16:45:01 UTC Severity: minor Tags: patch, s ...
Debian Bug report logs - #862282 qemu: CVE-2017-8380: scsi: megasas: out-of-bounds read in megasas_mmio_write Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 10 May 2017 15:09:04 UTC Severity: nor ...
Debian Bug report logs - #862280 qemu: CVE-2017-8309: audio: host memory leakage via capture buffer Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 10 May 2017 14:57:04 UTC Severity: minor Tags: f ...
Buffer overflow in the "megasas_mmio_write" function in Qemu 290 allows remote attackers to have unspecified impact via unknown vectors ...