296,869
Total vulnerabilities in the database
The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involving a MegaRAID Firmware Interface (MFI) command.
| Software | From | Fixed in | 
|---|---|---|
| qemu / qemu | - | 2.6.2.x | 
| canonical / ubuntu_linux | 16.04 | 16.04.x | 
| canonical / ubuntu_linux | 12.04 | 12.04.x | 
| canonical / ubuntu_linux | 14.04 | 14.04.x | 
| debian / debian_linux | 8.0 | 8.0.x |