Mauro Matteo Cascella

2 exploits Active since Aug 2022
CVE-2022-0216 WRITEUP MEDIUM WRITEUP
QEMU - Use After Free
A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs while processing repeated messages to cancel the current SCSI request via the lsi_do_msgout function. This flaw allows a malicious privileged user within the guest to crash the QEMU process on the host, resulting in a denial of service.
CVSS 4.4
CVE-2022-3165 WRITEUP MEDIUM WRITEUP
Qemu < 7.1.0 - Integer Underflow
An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending a specially crafted payload message, resulting in a denial of service.
CVSS 6.5