VDB
GCVE-VVD-MAGEIA-2019-100
GCVE-VVD-MAGEIA-2019-100
Advisory Published
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds
read due to an off-by-one error in memslot_get_virt. This may lead to a
denial of service, or, in the worst case, code-execution by unauthenticated
attackers. (CVE-2019-3813)
A vulnerability was discovered in SPICE before version 0.14.1 where the
generated code used for demarshalling messages lacked sufficient bounds
checks. A malicious client or server, after authentication, could send
specially crafted messages to its peer which would result in a crash or,
potentially, other impacts. (CVE-2018-10873)
Multiple integer overflow and buffer overflow issues were discovered in
spice-client's handling of LZ compressed frames. A malicious server could
cause the client to crash or, potentially, execute arbitrary code.
(CVE-2018-10893)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | flash-player-plugin | 0 (affected), 32.0.0.238-1.mga6.nonfree (unaffected) | — |
| Mageia | flash-player-plugin | 0 (affected), 32.0.0.238-1.mga7.nonfree (unaffected) | — |
| Mageia | spice | 0 (affected), 0.13.90-1.2.mga6 (unaffected), 0 (affected), 0.13.90-1.2.mga6 (unaffected) | — |
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.