QEMU 3.0.0 has an Integer Overflow because the qga/commands*.c files do not check the length of the argument list or the number of environment variables. NOTE: This has been disputed as not exploitable
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 66.2%