CVE-2014-0144

HIGH

QEMU <2.0.0 - Memory Corruption

Title source: llm

Description

QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/buffer overflows or crash caused by missing input validations which could allow a remote user to execute arbitrary code on the host with the privileges of the QEMU process.

Scores

CVSS v3 8.6
EPSS 0.0064
EPSS Percentile 70.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Classification

CWE
CWE-20
Status published

Affected Products (9)

qemu/qemu < 2.0.0
redhat/virtualization
redhat/enterprise_linux_desktop
redhat/enterprise_linux_eus
redhat/enterprise_linux_openstack_platform
redhat/enterprise_linux_server
redhat/enterprise_linux_server_aus
redhat/enterprise_linux_server_tus
redhat/enterprise_linux_workstation

Timeline

Published Sep 29, 2022
Tracked Since Feb 18, 2026