CVE-2016-3712

Description

Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.138

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in QEMU 2.5.0Windows
Multiple Vulnerabilities are affected in QEMU 2.5.0Windows
Multiple Vulnerabilities are affected in Citrix XenCenter 7.0Windows
Integer Overflow or Wraparound Vulnerability (CVE-2016-3712)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234