[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2016-2538":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T14:53:31.930Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":18,"aliases":19,"duplicate_of":9,"upstream":20,"downstream":21,"duplicates":50,"related":51,"reserved_at":9,"published_at":62,"modified_at":63,"state":64,"summary":65,"references_raw":74,"kevs":120,"epss":121,"epss_history":124,"metrics":386,"affected":397},"CVE-2016-2538","Multiple integer overflows in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 allow local guest OS administrators to cause a denial of service (QEMU process crash) or obtain sensitive host memory information via a remote NDIS control message packet that is mishandled in the (1) rndis_query_response, (2) rndis_set_response, or (3) usb_net_handle_dataout function.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":9,"likelihood_of_exploit":9,"capec":17},"CWE-189","Numeric Errors","Weaknesses in this category are related to improper calculation or conversion of numbers.","category","Draft",[],[],[],[],[22,24,26,28,30,32,34,36,38,40,42,44,46,48],{"_key":23},"SUSE-SU-2016:0873-1",{"_key":25},"SUSE-SU-2016:1745-1",{"_key":27},"OPENSUSE-SU-2024:10196-1",{"_key":29},"SUSE-SU-2016:0955-1",{"_key":31},"SUSE-SU-2016:1318-1",{"_key":33},"SUSE-SU-2016:1560-1",{"_key":35},"SUSE-SU-2016:1698-1",{"_key":37},"SUSE-SU-2016:1703-1",{"_key":39},"SUSE-SU-2016:1785-1",{"_key":41},"UBUNTU-CVE-2016-2538",{"_key":43},"USN-2974-1",{"_key":45},"DLA-1599-1",{"_key":47},"MGASA-2016-0176",{"_key":49},"DEBIAN-CVE-2016-2538",[],[52,53,54,55,56,57,58,59,60,61],{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":39},{"_key":47},"2016-06-16T18:00:00.000Z","2024-08-05T23:32:20.691Z","Modified",{"cisa_kev":66,"cisa_ransomware":66,"cisa_vendor":9,"epss_severity":67,"epss_score":68,"severity":69,"severity_score":70,"severity_version":71,"severity_source":72,"severity_vector":73,"severity_status":64},false,"low",0.00088,"high",7.1,"v3.0","nvd","CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",[75,82,88,94,99,104,108,112,116],{"url":76,"sources":77,"tags":79},"http://www.securityfocus.com/bid/83336",[78,72],"cve.org",[80,81],"VDB Entry","X Refsource BID",{"url":83,"sources":84,"tags":85},"https://lists.gnu.org/archive/html/qemu-devel/2016-02/msg03658.html",[78,72],[86,87],"Mailing List","X Refsource MLIST",{"url":89,"sources":90,"tags":91},"https://security.gentoo.org/glsa/201604-01",[78,72],[92,93],"Vendor Advisory","X Refsource GENTOO",{"url":95,"sources":96,"tags":97},"http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=fe3c546c5ff2a6210f9a4d8561cc64051ca8603e",[78,72],[98],"X Refsource CONFIRM",{"url":100,"sources":101,"tags":102},"http://www.ubuntu.com/usn/USN-2974-1",[78,72],[92,103],"X Refsource UBUNTU",{"url":105,"sources":106,"tags":107},"http://www.openwall.com/lists/oss-security/2016/02/22/3",[78,72],[86,87],{"url":109,"sources":110,"tags":111},"https://bugzilla.redhat.com/show_bug.cgi?id=1303120",[78,72],[98],{"url":113,"sources":114,"tags":115},"https://lists.debian.org/debian-lts-announce/2018/11/msg00038.html",[78,72],[86,87],{"url":117,"sources":118,"tags":119},"http://lists.nongnu.org/archive/html/qemu-stable/2016-03/msg00064.html",[78,72],[86,87],[],{"date":122,"score":68,"percentile":123},"2026-06-04",0.25118,[125,128,131,134,136,138,141,144,147,150,153,155,158,161,164,167,170,173,176,179,182,185,188,191,194,197,200,203,206,209,212,214,217,220,223,225,228,231,234,237,240,243,246,249,252,255,258,261,264,267,270,272,275,278,281,284,287,290,293,296,299,302,305,308,311,314,317,320,323,326,329,332,334,337,340,343,346,348,351,354,357,360,363,365,368,371,374,377,380,383],{"date":126,"score":68,"percentile":127},"2025-11-04",0.25932,{"date":129,"score":68,"percentile":130},"2025-11-05",0.2591,{"date":132,"score":68,"percentile":133},"2025-11-06",0.25916,{"date":135,"score":68,"percentile":133},"2025-11-07",{"date":137,"score":68,"percentile":133},"2025-11-08",{"date":139,"score":68,"percentile":140},"2025-11-09",0.2587,{"date":142,"score":68,"percentile":143},"2025-11-10",0.25834,{"date":145,"score":68,"percentile":146},"2025-11-11",0.25845,{"date":148,"score":68,"percentile":149},"2025-11-12",0.25873,{"date":151,"score":68,"percentile":152},"2025-11-13",0.25876,{"date":154,"score":68,"percentile":140},"2025-11-14",{"date":156,"score":68,"percentile":157},"2025-11-15",0.25865,{"date":159,"score":68,"percentile":160},"2025-11-16",0.2582,{"date":162,"score":68,"percentile":163},"2025-11-17",0.25778,{"date":165,"score":68,"percentile":166},"2025-11-18",0.21205,{"date":168,"score":68,"percentile":169},"2025-11-19",0.21214,{"date":171,"score":68,"percentile":172},"2025-11-20",0.21187,{"date":174,"score":68,"percentile":175},"2025-11-21",0.257,{"date":177,"score":68,"percentile":178},"2025-11-22",0.25699,{"date":180,"score":68,"percentile":181},"2025-11-23",0.25655,{"date":183,"score":68,"percentile":184},"2025-11-24",0.25629,{"date":186,"score":68,"percentile":187},"2025-11-25",0.25619,{"date":189,"score":68,"percentile":190},"2025-11-26",0.25603,{"date":192,"score":68,"percentile":193},"2025-11-27",0.25605,{"date":195,"score":68,"percentile":196},"2025-11-28",0.25578,{"date":198,"score":68,"percentile":199},"2025-11-29",0.25568,{"date":201,"score":68,"percentile":202},"2025-11-30",0.25539,{"date":204,"score":68,"percentile":205},"2025-12-01",0.25572,{"date":207,"score":68,"percentile":208},"2025-12-02",0.25599,{"date":210,"score":68,"percentile":211},"2025-12-03",0.25608,{"date":213,"score":68,"percentile":202},"2025-12-04",{"date":215,"score":68,"percentile":216},"2025-12-05",0.25594,{"date":218,"score":68,"percentile":219},"2025-12-06",0.256,{"date":221,"score":68,"percentile":222},"2025-12-07",0.25566,{"date":224,"score":68,"percentile":199},"2025-12-08",{"date":226,"score":68,"percentile":227},"2025-12-09",0.25614,{"date":229,"score":68,"percentile":230},"2025-12-10",0.2568,{"date":232,"score":68,"percentile":233},"2025-12-11",0.25697,{"date":235,"score":68,"percentile":236},"2025-12-12",0.2571,{"date":238,"score":68,"percentile":239},"2025-12-13",0.25717,{"date":241,"score":68,"percentile":242},"2025-12-14",0.2569,{"date":244,"score":68,"percentile":245},"2025-12-15",0.25661,{"date":247,"score":68,"percentile":248},"2025-12-16",0.25672,{"date":250,"score":68,"percentile":251},"2025-12-17",0.25746,{"date":253,"score":68,"percentile":254},"2025-12-18",0.25805,{"date":256,"score":68,"percentile":257},"2025-12-19",0.25819,{"date":259,"score":68,"percentile":260},"2025-12-20",0.25787,{"date":262,"score":68,"percentile":263},"2025-12-21",0.25732,{"date":265,"score":68,"percentile":266},"2025-12-22",0.25692,{"date":268,"score":68,"percentile":269},"2025-12-23",0.25659,{"date":271,"score":68,"percentile":248},"2025-12-24",{"date":273,"score":68,"percentile":274},"2025-12-25",0.25744,{"date":276,"score":68,"percentile":277},"2025-12-26",0.25733,{"date":279,"score":68,"percentile":280},"2025-12-27",0.25729,{"date":282,"score":68,"percentile":283},"2025-12-28",0.2561,{"date":285,"score":68,"percentile":286},"2025-12-29",0.25584,{"date":288,"score":68,"percentile":289},"2025-12-30",0.25581,{"date":291,"score":68,"percentile":292},"2025-12-31",0.25641,{"date":294,"score":68,"percentile":295},"2026-01-01",0.2574,{"date":297,"score":68,"percentile":298},"2026-01-02",0.25735,{"date":300,"score":68,"percentile":301},"2026-01-03",0.25723,{"date":303,"score":68,"percentile":304},"2026-01-04",0.25627,{"date":306,"score":68,"percentile":307},"2026-01-05",0.25609,{"date":309,"score":68,"percentile":310},"2026-01-06",0.25617,{"date":312,"score":68,"percentile":313},"2026-01-07",0.25642,{"date":315,"score":68,"percentile":316},"2026-01-08",0.25689,{"date":318,"score":68,"percentile":319},"2026-01-09",0.25668,{"date":321,"score":68,"percentile":322},"2026-01-10",0.25643,{"date":324,"score":68,"percentile":325},"2026-01-11",0.25626,{"date":327,"score":68,"percentile":328},"2026-01-12",0.25583,{"date":330,"score":68,"percentile":331},"2026-01-13",0.25561,{"date":333,"score":68,"percentile":307},"2026-01-14",{"date":335,"score":68,"percentile":336},"2026-01-15",0.25601,{"date":338,"score":68,"percentile":339},"2026-01-16",0.25631,{"date":341,"score":68,"percentile":342},"2026-01-17",0.25635,{"date":344,"score":68,"percentile":345},"2026-01-18",0.25586,{"date":347,"score":68,"percentile":202},"2026-01-19",{"date":349,"score":68,"percentile":350},"2026-01-20",0.25519,{"date":352,"score":68,"percentile":353},"2026-01-21",0.25463,{"date":355,"score":68,"percentile":356},"2026-01-22",0.25442,{"date":358,"score":68,"percentile":359},"2026-01-23",0.2552,{"date":361,"score":68,"percentile":362},"2026-01-24",0.25526,{"date":364,"score":68,"percentile":356},"2026-01-25",{"date":366,"score":68,"percentile":367},"2026-01-26",0.25349,{"date":369,"score":68,"percentile":370},"2026-01-27",0.25333,{"date":372,"score":68,"percentile":373},"2026-01-28",0.25331,{"date":375,"score":68,"percentile":376},"2026-01-29",0.25292,{"date":378,"score":68,"percentile":379},"2026-01-30",0.25282,{"date":381,"score":68,"percentile":382},"2026-01-31",0.25276,{"date":384,"score":68,"percentile":385},"2026-02-01",0.25327,[387],{"source":72,"cvss_v2_0":388,"cvss_v3_0":393,"cvss_v3_1":9,"cvss_v4_0":9},{"baseScore":389,"baseSeverity":9,"vectorString":390,"impactScore":391,"exploitabilityScore":392},3.6,"AV:L/AC:L/Au:N/C:P/I:N/A:P",4.9,3.9,{"baseScore":70,"baseSeverity":394,"vectorString":73,"impactScore":395,"exploitabilityScore":396},"HIGH",8.7,4.6,[398],{"ecosystem":9,"name":399,"vendor":399,"product":399,"cpe_part":400,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":401},"qemu","a",[402],{"version":403,"is_range":404,"range_type":405,"version_start":9,"version_start_type":9,"version_end":406,"version_end_type":407,"fixed_in":9},"lte2.5.0",true,"cpe","2.5.0","including"]