VDB
DEBIAN-CVE-2016-9603
DEBIAN-CVE-2016-9603
PUBLISHED
CVSS 9.899999618530273 CRITICAL
A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU process or, potentially, execute arbitrary code on the host with privileges of the QEMU process.
Risk Scores
CVSS v3.0
9.899999618530273
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:11 | xen | 0, 0, 0 |
| Debian:11 | qemu | 0, 0, 0 |
| Debian:12 | qemu | 0, 0, 0 |
| Debian:13 | xen | 0, 0, 0 |
| Debian:14 | xen | 0, 0, 0 |
| Debian:14 | qemu | 0, 0, 0 |
| Debian:12 | xen | 0, 0, 0 |
| Debian:13 | qemu | 0, 0, 0 |
Timeline
- Jul 27, 2018 CVE Published
- Apr 28, 2026 CVE Updated