QEMU is a widely embedded open-source machine emulator and virtualizer whose narrow product scope belies its prominence in the vulnerability landscape due to pervasive deployment across hypervisors, cloud platforms, and development environments. The vendor's disclosures cluster densely around memory-safety weaknesses—improper buffer-bounds restrictions, out-of-bounds reads and writes, NULL-pointer dereferences, and infinite loops—reflecting the low-level device-emulation and memory-management demands of the codebase. These weakness classes are characteristic of C-based system software and recur across QEMU's device drivers, CPU emulation, and I/O subsystems, where memory-corruption flaws can enable guest-to-host escape and lateral movement within virtualized infrastructure. Defenders should treat QEMU patches as high-priority when deployed in cloud, container, or critical virtualization environments; current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Qemu over time
Signals from CVEs in this vendor scope (421 CVEs).
421 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12928CRITICAL The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote attacker to achieve code execution, denial of service, or i | Jun 24, 2019 | 9.8 | 53 | NO | YES |
CVE-2017-15118CRITICAL A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of size up to 4096 bytes, which i | Jul 27, 2018 | 9.8 | 48 | NO | YES |
CVE-2018-12617HIGH qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 has an integer overflow causing a g_malloc0() call to trigger | Jun 21, 2018 | 7.5 | 48 | NO | YES |
CVE-2015-3456HIGH The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or p | May 13, 2015 | 7.7 | 42 | NO | YES |
CVE-2015-8556CRITICAL Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1. | Mar 24, 2017 | 10.0 | 41 | NO | YES |
CVE-2016-4002CRITICAL Buffer overflow in the mipsnet_receive function in hw/net/mipsnet.c in QEMU, when the guest NIC is configured to accept large packets, allows remote attackers to cause a denial of | Apr 26, 2016 | 9.8 | 34 | NO | NO |
CVE-2018-17963CRITICAL qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impac | Oct 9, 2018 | 9.8 | 33 | NO | NO |
CVE-2016-9603CRITICAL A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update i | Jul 27, 2018 | 9.9 | 33 | NO | NO |
CVE-2017-16845CRITICAL hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access. | Nov 17, 2017 | 10.0 | 33 | NO | NO |
CVE-2016-7161CRITICAL Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code on the QEMU host via a large et | Oct 5, 2016 | 9.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (421 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Qemu.
Media articles that mention a CVE ID that affects a product developed by Qemu — matched by CVE ID, not by vendor name.