CVE-2014-5263 describes an out-of-bounds access vulnerability in QEMU version 1.6.0, specifically within the vmstate_xhci_event function in hw/usb/hcd-xhci.c. This flaw, caused by a missing VMSTATE_END_OF_LIST macro, allows attackers to trigger a denial of service, memory corruption, and potentially gain privileges. With a CVSS score of 6.8, it is considered a medium-severity vulnerability that can be exploited remotely with medium attack complexity. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.6.0CPE matchmatch criteria | cpe:2.3:a:qemu:qemu:1.6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.