Spice Project
15 known vulnerabilities
Top Products
A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a de
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display syste
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_
Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames.
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages l
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker coul
spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface p
The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or poss
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory
Frequently Asked Questions
How many CVEs affect Spice Project?
Spice Project has 15 CVE records in our database, including 1 critical and 9 high severity vulnerabilities.
What are the most severe Spice Project vulnerabilities?
Spice Project has 1 critical severity (CVSS 9.0+) and 9 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Spice Project vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Spice Project products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Spice Project Vulnerabilities
CyberStrike scans your infrastructure for Spice Project vulnerabilities and provides real-time remediation guidance.
Get Started