NVD

Id
8639  
Name
CVE-2011-1751  
Description
The pciej_write function in hw/acpi_piix4.c in the PIIX4 Power Management emulation in qemu-kvm does not check if a device is hotpluggable before unplugging the PCI-ISA bridge, which allows privileged guest users to cause a denial of service (guest crash) and possibly execute arbitrary code by sending a crafted value to the 0xae08 (PCI_EJ_BASE) I/O port, which leads to a use-after-free related to "active qemu timers."  
Reject
 
CVSS Version
2  
CVSS Score
7.4  
Severity
High  
CVSS Base Score
7.4  
CVSS Impact Subscore
10  
CVSS Exploit Subscore
4.4  
CVSS Vector
(AV:A/AC:M/Au:S/C:C/I:C/A:C)  
Pub Date
2017-01-07  
Published
2012-06-21  
Modified Date
2016-12-07  
Seq
2011-1751  

Actions