Spice

Vendor:

First CVE: Aug 20, 2013 · Active for 12 years

15
Total CVEs
More Total CVEs than 93% of tracked products
1.9
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Spice over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 20, 2013
12 years ago
Most Recent CVE
May 28, 2021
1,886 days ago

CVE Severity & Scoring

Spice15 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local3 (20.0%)
Network8 (53.3%)
Unknown3 (20.0%)
Physical0 (0.0%)
Adjacent Network1 (6.7%)
Attack Complexity
Low11 (73.3%)
High1 (6.7%)
Unknown3 (20.0%)
User Interaction
None12 (80.0%)
Unknown3 (20.0%)
Required0 (0.0%)
Privileges Required
Low7 (46.7%)
High1 (6.7%)
None4 (26.7%)
Unknown3 (20.0%)

Top CVEs

Signals from CVEs in this product scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connectin
Jun 9, 20169.834NONO
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server
Aug 17, 20188.829NONO
spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into c
Jul 18, 20178.829NONO
Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, pote
Sep 11, 20188.828NONO
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst
Feb 4, 20197.524NONO
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk)
Oct 7, 20206.623NONO
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap o
Jul 27, 20188.823NONO
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
Jun 9, 20167.122NONO
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary
Jun 7, 20167.821NONO
Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and
Sep 8, 20156.921NONO

Exploit Exposure

Signals from CVEs in this product scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (15 CVEs).

Media Mentions

Signals from CVEs in this product scope (15 CVEs).

Top CNAs Publishing CVEs For Spice

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
0.9.126.93.4%00
0.9.026.93.4%00
0.8.326.93.4%00
0.8.226.93.4%00
0.8.126.93.4%00
0.8.026.93.4%00
0.7.326.93.4%00
0.7.226.93.4%00
0.7.126.93.4%00
0.7.026.93.4%00
0.6.426.93.4%00
0.6.326.93.4%00
0.6.226.93.4%00
0.6.126.93.4%00
0.6.026.93.4%00
0.5.326.93.4%00
0.5.226.93.4%00
0.13.018.84.2%00
0.12.818.84.2%00
0.12.718.84.2%00