Home/Product/spice project spice
Product

spice project spice

15 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2021-20201
< 0.14.92
A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of se
5.3MEDIUM
CVE-2020-14355
< 0.14.2
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before
6.6MEDIUM
CVE-2019-3813
>= 0.5.2 and <= 0.14.1
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This
7.5HIGH
CVE-2018-10893
all versions
Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicio
7.6HIGH
CVE-2018-10873
< 0.14.1
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked suff
8.3HIGH
CVE-2016-9578
< 0.13.90
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE
7.5HIGH
CVE-2016-9577
< 0.13.90
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send cra
7.5HIGH
CVE-2017-7506
all versions
spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authentic
8.8HIGH
CVE-2016-2150
all versions
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters,
7.1HIGH
CVE-2016-0749
all versions
The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execu
9.8CRITICAL
CVE-2015-5261
<= 0.12.5
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the hos
7.1HIGH
CVE-2015-5260
<= 0.12.5
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption
7.8HIGH
CVE-2015-3247
all versions
Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a d
CVE-2013-4282
all versions
Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a
CVE-2013-4130
<= 0.12.3
The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE before 0.12.
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin