Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-9603

33
FAUCET Score

CVE-2016-9603 describes a critical heap buffer overflow vulnerability in QEMU's Cirrus CLGD 54xx VGA emulator, affecting products like Citrix, Debian, QEMU, and Red Hat. This flaw could be triggered when a VNC client updated its display after a guest-initiated VGA operation. With a CVSS score of 9.9 (Critical), a privileged guest user could crash the QEMU process or potentially execute arbitrary code on the host with QEMU's privileges. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.9.0CPE matchmatch criteria
cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*
6.0.2CPE matchmatch criteria
cpe:2.3:a:citrix:xenserver:6.0.2:*:*:*:*:*:*:*
6.2.0CPE matchmatch criteria
cpe:2.3:a:citrix:xenserver:6.2.0:sp1:*:*:*:*:*:*
6.5CPE matchmatch criteria
cpe:2.3:a:citrix:xenserver:6.5:sp1:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:a:citrix:xenserver:7.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

5.5MEDIUM

CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L

Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
1.3
Impact Score
3.7
CvssVersion
3.0

Exploit Intelligence

EPSS Score
4.45%
Probability of exploitation in next 30 days
EPSS Percentile
90.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0445 is in the 92nd percentile among its peer group of 1,124 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (13)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: qemu-kvm-2:0.12.1.2-2.503.el6_9.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: qemu-kvm-10:1.5.3-126.el7_3.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6Fixed in: qemu-kvm-rhev-2:0.12.1.2-2.503.el6_9.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7Fixed in: qemu-kvm-rhev-10:2.6.0-28.el7_3.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7Fixed in: qemu-kvm-rhev-10:2.6.0-28.el7_3.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7Fixed in: qemu-kvm-rhev-10:2.6.0-28.el7_3.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 10.0 (Newton)Fixed in: qemu-kvm-rhev-10:2.6.0-28.el7_3.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 8.0 (Liberty)Fixed in: qemu-kvm-rhev-10:2.6.0-28.el7_3.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 9.0 (Mitaka)Fixed in: qemu-kvm-rhev-10:2.6.0-28.el7_3.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 7Fixed in: qemu-kvm-rhev-10:2.6.0-28.el7_3.9
View patch
redhatpatch availablevia redhat_api
Product: RHEV 3.X Hypervisor and Agents for RHEL-6Fixed in: qemu-kvm-rhev-2:0.12.1.2-2.503.el6_9.3
View patch
redhatpatch availablevia redhat_api
Product: RHEV 3.X Hypervisor and Agents for RHEL-7Fixed in: qemu-kvm-rhev-10:2.6.0-28.el7_3.9
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: qemu-kvm-rhev

Vendor Advisories (1)

redhatCVE-2016-9603Important

Qemu: cirrus: heap buffer overflow via vnc connection

Mar 14, 2017

References

access.redhat.com / errata/RHSA-2017:0980
Third Party Advisory
access.redhat.com / errata/RHSA-2017:0981
Third Party Advisory
access.redhat.com / errata/RHSA-2017:0982
Third Party Advisory
access.redhat.com / errata/RHSA-2017:0983
Third Party Advisory
access.redhat.com / errata/RHSA-2017:0984
Third Party Advisory
access.redhat.com / errata/RHSA-2017:0985
Third Party Advisory
access.redhat.com / errata/RHSA-2017:0987
Third Party Advisory
access.redhat.com / errata/RHSA-2017:0988
Third Party Advisory
access.redhat.com / errata/RHSA-2017:1205
Third Party Advisory
access.redhat.com / errata/RHSA-2017:1206
Third Party Advisory
access.redhat.com / errata/RHSA-2017:1441
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
lists.debian.org / debian-lts-announce/2018/02/msg00005.html
Third Party Advisory
lists.debian.org / debian-lts-announce/2018/09/msg00007.html
security.gentoo.org / glsa/201706-03
Third Party Advisory
support.citrix.com / article/CTX221578
Third Party Advisory
securityfocus.com / bid/96893
Third Party AdvisoryVDB Entry
securitytracker.com / id/1038023
Third Party AdvisoryVDB Entry