VendorsSpice Projectspice0.5.3
Vulnerabilities

Spice Project SPICE 0.5.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2017-7506
spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.
Published 2017-07-18 · Modified
8.8EPSS 0.042
CVE-2013-4130
The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE before 0.12.4 do not properly perform ring loops, which might allow remote attackers to cause a denial of service (reachable assertion and server exit) by triggering a network error.
Published 2013-08-20 · Modified
5.0EPSS 0.026