Known Vulnerabilities for products from Spice-space
Listed below are 9 of the newest known vulnerabilities associated with the vendor "Spice-space".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-57966 json | A path traversal vulnerability was found in spice-vdagent. This flaw allows a malicious or compromised SPICE host to write ar... | Not Provided | 2026-06-29 | 2026-07-08 |
| CVE-2026-57965 json | A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a special... | Not Provided | 2026-06-29 | 2026-07-08 |
| CVE-2021-3700 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.4 - MEDIUM | 2022-02-24 | 2022-04-25 |
| CVE-2020-25653 json | A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw may a... | 6.3 - MEDIUM | 2020-11-26 | 2023-11-07 |
| CVE-2020-25652 json | A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be established vi... | 5.5 - MEDIUM | 2020-11-26 | 2023-11-07 |
| CVE-2020-25651 json | A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the cl... | 6.4 - MEDIUM | 2020-11-26 | 2023-11-07 |
| CVE-2020-25650 json | A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any... | 5.5 - MEDIUM | 2020-11-25 | 2023-11-07 |
| CVE-2020-23793 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 8.6 - HIGH | 2023-08-22 | 2023-08-26 |
| CVE-2017-15108 json | spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local atta... | 7.8 - HIGH | 2018-01-20 | 2022-10-07 |
Known software with vulnerabilities from Spice-space
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Spice-space | Spice-vdagent | 0.17.0 |