Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-7840
Description:The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrary code via a crafted (1) offset or (2) length value in savevm data.
Test IDs: 1.3.6.1.4.1.25623.1.0.871324   1.3.6.1.4.1.25623.1.0.868790   1.3.6.1.4.1.25623.1.1.4.2015.0357.1  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-7840
RHSA-2015:0349
http://rhn.redhat.com/errata/RHSA-2015-0349.html
RHSA-2015:0624
http://rhn.redhat.com/errata/RHSA-2015-0624.html
[qemu-devel] 20141112 [PATCH 0/4] migration: fix CVE-2014-7840
http://thread.gmane.org/gmane.comp.emulators.qemu/306117
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=0be839a2701369f669532ea5884c15bead1c6e08
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=0be839a2701369f669532ea5884c15bead1c6e08
https://bugzilla.redhat.com/show_bug.cgi?id=1163075
https://bugzilla.redhat.com/show_bug.cgi?id=1163075
qemu-cve20147840-code-exec(99194)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99194




© 1998-2025 E-Soft Inc. All rights reserved.