Loading vulnerability details…
CVSS v3.1
N/A
EPSS
0.49%
Published
Jun 7, 2016
Modified
May 6, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.
Weaknesses (CWE)
Affected Products (16)
References (20)