Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Qemu

First CVE: May 2, 2007Active for: 19 yearsTotal CVEs: 421
35.0
VTI Score
Medium

QEMU is a widely embedded open-source machine emulator and virtualizer whose narrow product scope belies its prominence in the vulnerability landscape due to pervasive deployment across hypervisors, cloud platforms, and development environments. The vendor's disclosures cluster densely around memory-safety weaknesses—improper buffer-bounds restrictions, out-of-bounds reads and writes, NULL-pointer dereferences, and infinite loops—reflecting the low-level device-emulation and memory-management demands of the codebase. These weakness classes are characteristic of C-based system software and recur across QEMU's device drivers, CPU emulation, and I/O subsystems, where memory-corruption flaws can enable guest-to-host escape and lateral movement within virtualized infrastructure. Defenders should treat QEMU patches as high-priority when deployed in cloud, container, or critical virtualization environments; current severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
421
Total CVEs
More Total CVEs than 100% of tracked vendors
23.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Qemu over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2007
19 years ago
Most Recent CVE
Jul 25, 2025
364 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (421 CVEs).

421 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-12928CRITICAL
The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote attacker to achieve code execution, denial of service, or i
Jun 24, 20199.853NOYES
CVE-2017-15118CRITICAL
A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of size up to 4096 bytes, which i
Jul 27, 20189.848NOYES
CVE-2018-12617HIGH
qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 has an integer overflow causing a g_malloc0() call to trigger
Jun 21, 20187.548NOYES
CVE-2015-3456HIGH
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or p
May 13, 20157.742NOYES
CVE-2015-8556CRITICAL
Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.
Mar 24, 201710.041NOYES
CVE-2016-4002CRITICAL
Buffer overflow in the mipsnet_receive function in hw/net/mipsnet.c in QEMU, when the guest NIC is configured to accept large packets, allows remote attackers to cause a denial of
Apr 26, 20169.834NONO
CVE-2018-17963CRITICAL
qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impac
Oct 9, 20189.833NONO
CVE-2016-9603CRITICAL
A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update i
Jul 27, 20189.933NONO
CVE-2017-16845CRITICAL
hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access.
Nov 17, 201710.033NONO
CVE-2016-7161CRITICAL
Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code on the QEMU host via a large et
Oct 5, 20169.833NONO
View all 421 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products421 CVEs
8%
57%
30%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local272 (64.6%)
Network68 (16.2%)
Unknown73 (17.3%)
Physical1 (0.2%)
Adjacent Network7 (1.7%)
Attack Complexity
Low318 (75.5%)
High30 (7.1%)
Unknown73 (17.3%)
User Interaction
None343 (81.5%)
Unknown73 (17.3%)
Required5 (1.2%)
Privileges Required
Low191 (45.4%)
High105 (24.9%)
None52 (12.4%)
Unknown73 (17.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (421 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.2% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
1.7% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Qemu.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Qemu — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Qemu's Products

View all 3 CNAs →

Top CWEs