cve,link,title,description,vendor,products,score,severity,epss,cisa,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2019-3813,https://securityvulnerability.io/vulnerability/CVE-2019-3813,,"Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.",Red Hat,Spice,7.5,HIGH,0.0018500000005587935,false,false,false,false,,false,false,2019-02-04T18:29:00.000Z,0 CVE-2018-10893,https://securityvulnerability.io/vulnerability/CVE-2018-10893,,"Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.",Red Hat,Spice-client,7.6,HIGH,0.00107999995816499,false,false,false,false,,false,false,2018-09-11T15:00:00.000Z,0 CVE-2016-9578,https://securityvulnerability.io/vulnerability/CVE-2016-9578,,A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.,Red Hat,Spice,7.5,HIGH,0.01534000039100647,false,false,false,false,,false,false,2018-07-27T21:00:00.000Z,0 CVE-2016-9577,https://securityvulnerability.io/vulnerability/CVE-2016-9577,,A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.,Red Hat,Spice,7.5,HIGH,0.0038399999029934406,false,false,false,false,,false,false,2018-07-27T20:00:00.000Z,0 CVE-2017-15108,https://securityvulnerability.io/vulnerability/CVE-2017-15108,,"spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.",Red Hat,Spice-vdagent,7.8,HIGH,0.0006200000061653554,false,false,false,false,,false,false,2018-01-20T00:00:00.000Z,0