Home/Product/virglrenderer project virglrenderer
Product

virglrenderer project virglrenderer

21 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2022-0175
all versions
A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocatin
5.5MEDIUM
CVE-2022-0135
>= 0.8.1 and < 0.10.0
An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to
7.8HIGH
CVE-2020-8003
<= 0.8.1
A double-free vulnerability in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of service by tr
5.5MEDIUM
CVE-2020-8002
<= 0.8.1
A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of service via co
5.5MEDIUM
CVE-2019-18391
<= 0.8.0
A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0
5.5MEDIUM
CVE-2019-18390
<= 0.8.0
An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS u
7.1HIGH
CVE-2019-18389
<= 0.8.0
A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0
7.8HIGH
CVE-2019-18388
<= 0.8.0
A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service v
5.5MEDIUM
CVE-2017-5956
<= 0.5.0
The vrend_draw_vbo function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds
5.5MEDIUM
CVE-2016-10214
<= 0.5.0
Memory leak in the virgl_resource_attach_backing function in virglrenderer before 0.6.0 allows local guest OS users to cause a den
6.5MEDIUM
CVE-2017-5937
<= 0.5.0
The util_format_is_pure_uint function in vrend_renderer.c in Virgil 3d project (aka virglrenderer) 0.6.0 and earlier allows local
6.5MEDIUM
CVE-2017-5580
<= 0.5.0
The parse_instruction function in gallium/auxiliary/tgsi/tgsi_text.c in virglrenderer before 0.6.0 allows local guest OS users to
7.1HIGH
CVE-2016-10163
<= 0.5.0
Memory leak in the vrend_renderer_context_create_internal function in vrend_decode.c in virglrenderer before 0.6.0 allows local gu
6.5MEDIUM
CVE-2017-6386
< 0.8.0
Memory leak in the vrend_create_vertex_elements_state function in vrend_renderer.c in virglrenderer allows local guest OS users to
6.5MEDIUM
CVE-2017-6317
<= 0.5.0
Memory leak in the add_shader_program function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to ca
6.5MEDIUM
CVE-2017-6210
<= 0.5.0
The vrend_decode_reset function in vrend_decode.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of s
6.5MEDIUM
CVE-2017-6209
<= 0.5.0
Stack-based buffer overflow in the parse_identifier function in tgsi_text.c in the TGSI auxiliary module in the Gallium driver in
6.5MEDIUM
CVE-2017-5994
<= 0.5.0
Heap-based buffer overflow in the vrend_create_vertex_elements_state function in vrend_renderer.c in virglrenderer before 0.6.0 al
5.5MEDIUM
CVE-2017-5993
<= 0.5.0
Memory leak in the vrend_renderer_init_blit_ctx function in vrend_blitter.c in virglrenderer before 0.6.0 allows local guest OS us
6.5MEDIUM
CVE-2017-5957
< 0.6.0
Stack-based buffer overflow in the vrend_decode_set_framebuffer_state function in vrend_decode.c in virglrenderer before 926b9b346
5.5MEDIUM
CVE-2017-6355
<= 0.5.0
Integer overflow in the vrend_create_shader function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users
5.5MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin