Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Michael Gruys

#23951of 53,632
9.9Total CVSS
Vulnerabilities · 1
PT-2009-5891
9.9
2009-10-23
Qemu · Qemu · CVE-2009-3616
**Name of the Vulnerable Software and Affected Versions** QEMU versions 0.10.6 and earlier **Description** The issue is related to multiple use-after-free vulnerabilities in the VNC server component of QEMU. These vulnerabilities might allow guest OS users to execute arbitrary code on the host OS. This can be achieved by establishing a connection from a VNC client and then performing specific actions such as disconnecting during data transfer, sending a message using incorrect integer data types, or using the Fuzzy Screen Mode protocol. The vulnerabilities are related to double free issues. **Recommendations** For QEMU versions 0.10.6 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.