peter bassill · operator
$ cve CVE-2016-0749 JSON

CVE-2016-0749

9.8
CRITICAL · CVSS 3.0 · EPSS 8.5% (pctl 95)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecting to a guest VM, which triggers a heap-based buffer overflow.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS8.49% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploitnone known
Published2016-06-09
Last modified2026-06-17

Affected (12)

VendorProduct
debiandebian linux
microsoftwindows
opensuseleap
opensuseopensuse
redhatenterprise linux
redhatenterprise linux desktop
redhatenterprise linux hpc node eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux workstation
spice projectspice

References

→ the Explorer  ·  watch your stack  ·  NVD