CVE Tools

Spice-project

7 CVEs tracked since 2013. Since Aug 2013, none of them reached CISA KEV.

Spice-project CVEs per month

Aug 2013 to Jun 2016. Point at a month, or focus the strip and use the arrow keys.
Spice-project CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2013-0810
2013-09null or fewer
2013-10null or fewer
2013-1110
2013-12null or fewer
2014-01null or fewer
2014-02null or fewer
2014-03null or fewer
2014-04null or fewer
2014-05null or fewer
2014-06null or fewer
2014-07null or fewer
2014-08null or fewer
2014-09null or fewer
2014-10null or fewer
2014-11null or fewer
2014-12null or fewer
2015-01null or fewer
2015-02null or fewer
2015-03null or fewer
2015-04null or fewer
2015-05null or fewer
2015-06null or fewer
2015-07null or fewer
2015-08null or fewer
2015-0910
2015-10null or fewer
2015-11null or fewer
2015-12null or fewer
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-04null or fewer
2016-05null or fewer
2016-0640

Products

The products that kept showing up in Spice-project's monthly top three, with their CVEs summed over those months.

  1. Spice74 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Spice-project.

  1. CVE-2021-3700A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amoun...6.4
  2. CVE-2021-20201A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a ...5.3
  3. CVE-2020-14355Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are af...6.6
  4. CVE-2019-3813Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execu...7.5
  5. CVE-2018-10893Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute ...7.6
  6. CVE-2018-10873A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentic...8.3
  7. CVE-2016-9578A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process t...7.5
  8. CVE-2016-9577A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading t...7.5
  9. CVE-2017-7506spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or serve...8.8
  10. CVE-2016-0749The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecting to a guest VM, ...9.8
  11. CVE-2016-2150SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.7.1
  12. CVE-2015-5261Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.7.1
  13. CVE-2015-5260Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host...7.8
  14. CVE-2015-3247Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) ...6.9
  15. CVE-2013-4282Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.5.0

The record

Peak rank
#44 in Jun 2016
Busiest month shown
Jun 2016, 4 CVEs
Months with a KEV entry
0 since Aug 2013
Monthly snapshots
4 since 2013
Spice-project's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store