Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-20808

In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation. It occurs in the ati_cursor_define() routine while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting in a denial of service.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 29.4%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 2.1
Products affected by CVE-2019-20808
  • Qemu » Qemu » Version: 4.1.0
    cpe:2.3:a:qemu:qemu:4.1.0


Contact Us

Shodan ® - All rights reserved