KVM Qumranet is a virtualization hypervisor project with a narrowly scoped product footprint centered on the KVM kernel module, which despite its focused scope sits deeply embedded in Linux-based infrastructure as a foundational virtualization layer. Its observed vulnerabilities cluster around improper input validation and memory-buffer boundary issues inherent to a kernel-level hypervisor handling guest-to-host interfaces. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kvm Qumranet over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-2382MEDIUM The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote attackers to cause a denial of service (infin | Dec 24, 2008 | 5.0 | 26 | NO | YES |
CVE-2008-4539HIGH Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using | Dec 29, 2008 | 7.2 | 20 | NO | NO |
CVE-2010-0419MEDIUM The x86 emulator in KVM 83, when a guest is configured for Symmetric Multiprocessing (SMP), does not properly restrict writing of segment selectors to segment registers, which migh | Mar 5, 2010 | 4.4 | 15 | NO | NO |
CVE-2010-0306MEDIUM The x86 emulator in KVM 83, when a guest is configured for Symmetric Multiprocessing (SMP), does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) to restric | Feb 12, 2010 | 4.1 | 13 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kvm Qumranet.
Media articles that mention a CVE ID that affects a product developed by Kvm Qumranet — matched by CVE ID, not by vendor name.