Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Spice Project

First CVE: Aug 20, 2013Active for: 13 yearsTotal CVEs: 15
45.7
VTI Score
High

Spice Project maintains a specialized remote-graphics protocol and virtualization library that, despite a narrow product scope, occupies a prominent position in virtual machine and thin-client infrastructure where memory safety and input handling are security-critical. Its vulnerability profile clusters around buffer-management and input-validation weaknesses—including buffer overflows, out-of-bounds operations, and resource exhaustion—that are characteristic of low-level protocol implementations and that skew toward meaningful severity outcomes. Defenders should treat protocol library updates as high-priority for any virtualization or remote-access stack relying on this vendor; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
1.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Spice Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 20, 2013
12 years ago
Most Recent CVE
May 28, 2021
1,883 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-0749CRITICAL
The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connectin
Jun 9, 20169.834NONO
CVE-2018-10873HIGH
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server
Aug 17, 20188.829NONO
CVE-2017-7506HIGH
spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into c
Jul 18, 20178.829NONO
CVE-2018-10893HIGH
Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, pote
Sep 11, 20188.828NONO
CVE-2019-3813HIGH
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst
Feb 4, 20197.524NONO
CVE-2020-14355MEDIUM
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk)
Oct 7, 20206.623NONO
CVE-2016-9577HIGH
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap o
Jul 27, 20188.823NONO
CVE-2016-2150HIGH
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
Jun 9, 20167.122NONO
CVE-2015-5260HIGH
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary
Jun 7, 20167.821NONO
CVE-2015-3247MEDIUM
Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and
Sep 8, 20156.921NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
33%
60%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (20.0%)
Network8 (53.3%)
Unknown3 (20.0%)
Physical0 (0.0%)
Adjacent Network1 (6.7%)
Attack Complexity
Low11 (73.3%)
High1 (6.7%)
Unknown3 (20.0%)
User Interaction
None12 (80.0%)
Unknown3 (20.0%)
Required0 (0.0%)
Privileges Required
Low7 (46.7%)
High1 (6.7%)
None4 (26.7%)
Unknown3 (20.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Spice Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Spice Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Spice Project's Products

View all 1 CNAs →

Top CWEs