CVE-2015-5261 PUBLISHED

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.

EPSS 0.09% · 25.9th percentile

Risk Scores

EPSS Score
0.09%
25.9th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSspice0
Ubuntu:14.04:LTSspice0.12.4-0nocelt1.1, 0.12.4-0nocelt1.1ubuntu1, 0.12.4-0nocelt2

Timeline

References

Open in Interactive Console →