Spice Project maintains a specialized remote-graphics protocol and virtualization library that, despite a narrow product scope, occupies a prominent position in virtual machine and thin-client infrastructure where memory safety and input handling are security-critical. Its vulnerability profile clusters around buffer-management and input-validation weaknesses—including buffer overflows, out-of-bounds operations, and resource exhaustion—that are characteristic of low-level protocol implementations and that skew toward meaningful severity outcomes. Defenders should treat protocol library updates as high-priority for any virtualization or remote-access stack relying on this vendor; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spice Project over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-0749CRITICAL The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connectin | Jun 9, 2016 | 9.8 | 34 | NO | NO |
CVE-2018-10873HIGH A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server | Aug 17, 2018 | 8.8 | 29 | NO | NO |
CVE-2017-7506HIGH spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into c | Jul 18, 2017 | 8.8 | 29 | NO | NO |
CVE-2018-10893HIGH Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, pote | Sep 11, 2018 | 8.8 | 28 | NO | NO |
CVE-2019-3813HIGH Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst | Feb 4, 2019 | 7.5 | 24 | NO | NO |
CVE-2020-14355MEDIUM Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) | Oct 7, 2020 | 6.6 | 23 | NO | NO |
CVE-2016-9577HIGH A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap o | Jul 27, 2018 | 8.8 | 23 | NO | NO |
CVE-2016-2150HIGH SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261. | Jun 9, 2016 | 7.1 | 22 | NO | NO |
CVE-2015-5260HIGH Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary | Jun 7, 2016 | 7.8 | 21 | NO | NO |
CVE-2015-3247MEDIUM Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and | Sep 8, 2015 | 6.9 | 21 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spice Project.
Media articles that mention a CVE ID that affects a product developed by Spice Project — matched by CVE ID, not by vendor name.