The Spice Gtk Project maintains a specialized graphics and display client library for SPICE protocol connections, primarily deployed in virtualization and remote-desktop environments where its narrow product scope belies its critical placement in the display pipeline. Known vulnerabilities in this component have centered on input handling within the protocol parser, reflecting the complexity inherent to processing untrusted remote display streams. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spice Gtk Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12194CRITICAL A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the cl | Mar 14, 2018 | 9.8 | 31 | NO | NO |
CVE-2016-3066MEDIUM The spice-gtk widget allows remote authenticated users to obtain information from the host clipboard. | Jun 6, 2017 | 6.5 | 22 | NO | NO |
CVE-2013-4324MEDIUM spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended acces | Oct 3, 2013 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spice Gtk Project.
Media articles that mention a CVE ID that affects a product developed by Spice Gtk Project — matched by CVE ID, not by vendor name.