Bochs is an open-source processor emulator that translates guest machine instructions for execution within a virtualized environment, and its vulnerability profile centers on memory-safety issues such as buffer boundary violations and out-of-bounds writes within the emulation core. Treat this as a compact, focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bochs Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-25220CRITICAL Bochs 2.6-5 contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized input string to the application. Attacker | Mar 28, 2026 | 9.8 | 33 | NO | NO |
CVE-2007-2893HIGH Heap-based buffer overflow in the bx_ne2k_c::rx_frame function in iodev/ne2k.cc in the emulated NE2000 device in Bochs 2.3 allows local users of the guest operating system to write | May 30, 2007 | 7.2 | 20 | NO | NO |
CVE-2004-2372HIGH Buffer overflow in Bochs before 2.1.1, if installed setuid, allows local users to execute arbitrary code via a long HOME environment variable, which is used if the .bochsrc, bochsr | Dec 31, 2004 | 7.2 | 20 | NO | NO |
The emulated floppy disk controller in Bochs 2.3 allows local users of the guest operating system to cause a denial of service (virtual machine crash) via unspecified vectors, resu | May 30, 2007 | 2.1 | 18 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bochs Project.
Media articles that mention a CVE ID that affects a product developed by Bochs Project — matched by CVE ID, not by vendor name.