{"id":"CVE-2016-3712","details":"Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.","modified":"2026-05-15T12:01:44.117957240Z","published":"2016-05-11T21:59:02.063Z","related":["SUSE-SU-2016:1560-1","SUSE-SU-2016:1698-1","SUSE-SU-2016:1703-1","SUSE-SU-2016:1785-1","SUSE-SU-2016:2533-1","SUSE-SU-2016:2725-1","openSUSE-SU-2024:10233-1","openSUSE-SU-2024:10285-1"],"database_specific":{"unresolved_ranges":[{"source":"CPE_FIELD","vendor_product":"canonical:ubuntu_linux","extracted_events":[{"last_affected":"12.04"},{"last_affected":"14.04"},{"last_affected":"15.10"},{"last_affected":"16.04"}],"cpes":["cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*"]},{"source":"CPE_FIELD","vendor_product":"citrix:xenserver","cpes":["cpe:2.3:a:citrix:xenserver:*:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"7.0"}]},{"source":"CPE_FIELD","vendor_product":"debian:debian_linux","extracted_events":[{"last_affected":"8.0"}],"cpes":["cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"]},{"source":"CPE_FIELD","vendor_product":"oracle:vm_server","extracted_events":[{"last_affected":"3.3"},{"last_affected":"3.4"}],"cpes":["cpe:2.3:o:oracle:vm_server:3.3:*:*:*:*:*:x86:*","cpe:2.3:o:oracle:vm_server:3.4:*:*:*:*:*:x86:*"]},{"source":"CPE_FIELD","vendor_product":"redhat:enterprise_linux_desktop","extracted_events":[{"last_affected":"6.0"},{"last_affected":"7.0"}],"cpes":["cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"]},{"source":"CPE_FIELD","vendor_product":"redhat:enterprise_linux_server","extracted_events":[{"last_affected":"6.0"},{"last_affected":"7.0"}],"cpes":["cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"]},{"source":"CPE_FIELD","vendor_product":"redhat:enterprise_linux_server_aus","extracted_events":[{"last_affected":"7.3"},{"last_affected":"7.4"},{"last_affected":"7.6"},{"last_affected":"7.7"}],"cpes":["cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7:*:*:*:*:*:*:*"]},{"source":"CPE_FIELD","vendor_product":"redhat:enterprise_linux_server_eus","extracted_events":[{"last_affected":"7.3"},{"last_affected":"7.4"},{"last_affected":"7.5"},{"last_affected":"7.6"},{"last_affected":"7.7"}],"cpes":["cpe:2.3:o:redhat:enterprise_linux_server_eus:7.3:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_eus:7.4:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_eus:7.7:*:*:*:*:*:*:*"]},{"source":"CPE_FIELD","vendor_product":"redhat:enterprise_linux_server_tus","extracted_events":[{"last_affected":"7.3"},{"last_affected":"7.6"},{"last_affected":"7.7"}],"cpes":["cpe:2.3:o:redhat:enterprise_linux_server_tus:7.3:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_tus:7.7:*:*:*:*:*:*:*"]},{"source":"CPE_FIELD","vendor_product":"redhat:enterprise_linux_workstation","extracted_events":[{"last_affected":"6.0"},{"last_affected":"7.0"}],"cpes":["cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"]}]},"references":[{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-2585.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2017-0621.html"},{"type":"ADVISORY","url":"http://support.citrix.com/article/CTX212736"},{"type":"ADVISORY","url":"http://www.debian.org/security/2016/dsa-3573"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2016/05/09/4"},{"type":"ADVISORY","url":"http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/90314"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1035794"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-2974-1"},{"type":"ADVISORY","url":"http://xenbits.xen.org/xsa/advisory-179.html"},{"type":"FIX","url":"https://lists.gnu.org/archive/html/qemu-devel/2016-05/msg01196.html"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}