Kvm Group's vulnerability footprint centers on QEMU-KVM, a widely embedded hypervisor and machine-emulation component that sits in the virtualization layer of many infrastructure deployments. The durable signal reflects this component's role in handling untrusted guest input and managing memory access, with observed weaknesses clustering around improper input validation and memory-buffer boundary violations. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kvm Group over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-0029HIGH Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000.c) in qemu-kvm 0.12, and possibly other versions, allows guest OS users to cause a denia | Jan 27, 2012 | 7.4 | 25 | NO | NO |
CVE-2011-2512MEDIUM The virtio_queue_notify in qemu-kvm 0.14.0 and earlier does not properly validate the virtqueue number, which allows guest users to cause a denial of service (guest crash) and poss | Jun 21, 2012 | 5.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kvm Group.
Media articles that mention a CVE ID that affects a product developed by Kvm Group — matched by CVE ID, not by vendor name.