Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2015-8817

QEMU (aka Quick Emulator) built to use 'address_space_translate' to map an address to a MemoryRegionSection is vulnerable to an OOB r/w access issue. It could occur while doing pci_dma_read/write calls. Affects QEMU versions >= 1.6.0 and <= 2.3.1. A privileged user inside guest could use this flaw to crash the guest instance resulting in DoS.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.6%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 2.1
References
Products affected by CVE-2015-8817
  • Qemu » Qemu » Version: 1.6.0
    cpe:2.3:a:qemu:qemu:1.6.0
  • Qemu » Qemu » Version: 1.6.1
    cpe:2.3:a:qemu:qemu:1.6.1
  • Qemu » Qemu » Version: 1.6.2
    cpe:2.3:a:qemu:qemu:1.6.2
  • Qemu » Qemu » Version: 1.7.1
    cpe:2.3:a:qemu:qemu:1.7.1
  • Qemu » Qemu » Version: 2.0.0
    cpe:2.3:a:qemu:qemu:2.0.0
  • Qemu » Qemu » Version: 2.0.2
    cpe:2.3:a:qemu:qemu:2.0.2
  • Qemu » Qemu » Version: 2.1.0
    cpe:2.3:a:qemu:qemu:2.1.0
  • Qemu » Qemu » Version: 2.1.1
    cpe:2.3:a:qemu:qemu:2.1.1
  • Qemu » Qemu » Version: 2.1.2
    cpe:2.3:a:qemu:qemu:2.1.2
  • Qemu » Qemu » Version: 2.1.3
    cpe:2.3:a:qemu:qemu:2.1.3
  • Qemu » Qemu » Version: 2.2.0
    cpe:2.3:a:qemu:qemu:2.2.0
  • Qemu » Qemu » Version: 2.2.1
    cpe:2.3:a:qemu:qemu:2.2.1
  • Qemu » Qemu » Version: 2.3.0
    cpe:2.3:a:qemu:qemu:2.3.0
  • Qemu » Qemu » Version: 2.3.1
    cpe:2.3:a:qemu:qemu:2.3.1


Contact Us

Shodan ® - All rights reserved