Vulnerability record · CVE-2010-0430 · published 27 December 2013
CVE-2010-0430: Redhat enterprise virtualization hypervisor memory buffer overflow vulnerability
Redhat · Enterprise Virtualization Hypervisor
libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 and possibly other products, allows guest OS users to read from or write to arbitrary QEMU memory by modifying the address that is used by Cairo for memory mappings.
Description
libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 and possibly other products, allows guest OS users to read from or write to arbitrary QEMU memory by modifying the address that is used by Cairo for memory mappings.
AV:A/AC:M/Au:S/C:C/I:C/A:C
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://rhn.redhat.com/errata/RHSA-2010-0271.html | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=568702 | |
| https://rhn.redhat.com/errata/RHSA-2010-0476.html | Vendor Advisory |
| http://rhn.redhat.com/errata/RHSA-2010-0271.html | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=568702 | |
| https://rhn.redhat.com/errata/RHSA-2010-0476.html | Vendor Advisory |
Track CVE-2010-0430 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-0430), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.