[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2016-4454":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T08:53:30.047Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":68,"aliases":69,"duplicate_of":9,"upstream":70,"downstream":71,"duplicates":96,"related":97,"reserved_at":9,"published_at":106,"modified_at":107,"state":108,"summary":109,"references_raw":118,"kevs":163,"epss":164,"epss_history":167,"metrics":429,"affected":440},"CVE-2016-4454","The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to obtain sensitive host memory information or cause a denial of service (QEMU process crash) by changing FIFO registers and issuing a VGA command, which triggers an out-of-bounds read.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-119","Improper Restriction of Operations within the Bounds of a Memory Buffer","The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.","weakness","Stable","Class","High",[20,24,28,32,36,40,44,48,52,56,60,64],{"id":21,"name":22,"techniques":23},"CAPEC-10","Buffer Overflow via Environment Variables",[],{"id":25,"name":26,"techniques":27},"CAPEC-100","Overflow Buffers",[],{"id":29,"name":30,"techniques":31},"CAPEC-123","Buffer Manipulation",[],{"id":33,"name":34,"techniques":35},"CAPEC-14","Client-side Injection-induced Buffer Overflow",[],{"id":37,"name":38,"techniques":39},"CAPEC-24","Filter Failure through Buffer Overflow",[],{"id":41,"name":42,"techniques":43},"CAPEC-42","MIME Conversion",[],{"id":45,"name":46,"techniques":47},"CAPEC-44","Overflow Binary Resource File",[],{"id":49,"name":50,"techniques":51},"CAPEC-45","Buffer Overflow via Symbolic Links",[],{"id":53,"name":54,"techniques":55},"CAPEC-46","Overflow Variables and Tags",[],{"id":57,"name":58,"techniques":59},"CAPEC-47","Buffer Overflow via Parameter Expansion",[],{"id":61,"name":62,"techniques":63},"CAPEC-8","Buffer Overflow in an API Call",[],{"id":65,"name":66,"techniques":67},"CAPEC-9","Buffer Overflow in Local Command-Line Utilities",[],[],[],[],[72,74,76,78,80,82,84,86,88,90,92,94],{"_key":73},"SUSE-SU-2016:2093-1",{"_key":75},"SUSE-SU-2016:2100-1",{"_key":77},"SUSE-SU-2016:2533-1",{"_key":79},"SUSE-SU-2016:2589-1",{"_key":81},"SUSE-SU-2016:2628-1",{"_key":83},"SUSE-SU-2016:2725-1",{"_key":85},"SUSE-SU-2016:2781-1",{"_key":87},"UBUNTU-CVE-2016-4454",{"_key":89},"USN-3047-1",{"_key":91},"OPENSUSE-SU-2024:10233-1",{"_key":93},"DLA-1599-1",{"_key":95},"DEBIAN-CVE-2016-4454",[],[98,99,100,101,102,103,104,105],{"_key":73},{"_key":75},{"_key":77},{"_key":79},{"_key":81},{"_key":83},{"_key":85},{"_key":91},"2016-06-01T22:00:00.000Z","2024-08-06T00:32:25.681Z","Modified",{"cisa_kev":110,"cisa_ransomware":110,"cisa_vendor":9,"epss_severity":111,"epss_score":112,"severity":113,"severity_score":114,"severity_version":115,"severity_source":116,"severity_vector":117,"severity_status":108},false,"low",0.00072,"medium",6,"v3.1","nvd","CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H",[119,127,133,138,142,147,153,159],{"url":120,"sources":121,"tags":123},"http://www.ubuntu.com/usn/USN-3047-1",[122,116],"cve.org",[124,125,126],"Vendor Advisory","X Refsource UBUNTU","Third Party Advisory",{"url":128,"sources":129,"tags":130},"http://www.openwall.com/lists/oss-security/2016/05/30/3",[122,116],[131,132,126],"Mailing List","X Refsource MLIST",{"url":134,"sources":135,"tags":136},"https://security.gentoo.org/glsa/201609-01",[122,116],[124,137,126],"X Refsource GENTOO",{"url":139,"sources":140,"tags":141},"http://www.ubuntu.com/usn/USN-3047-2",[122,116],[124,125,126],{"url":143,"sources":144,"tags":145},"https://lists.gnu.org/archive/html/qemu-devel/2016-05/msg05271.html",[122,116],[131,132,146,124],"Patch",{"url":148,"sources":149,"tags":150},"http://www.securityfocus.com/bid/90927",[122,116],[151,152,126],"VDB Entry","X Refsource BID",{"url":154,"sources":155,"tags":156},"https://bugzilla.redhat.com/show_bug.cgi?id=1336429",[122,116],[157,158,126],"X Refsource CONFIRM","Issue Tracking",{"url":160,"sources":161,"tags":162},"https://lists.debian.org/debian-lts-announce/2018/11/msg00038.html",[122,116],[131,132,126],[],{"date":165,"score":112,"percentile":166},"2026-06-03",0.22059,[168,172,175,178,181,184,187,190,193,195,198,200,203,206,209,212,215,218,221,224,227,230,233,236,238,241,244,247,250,253,256,259,262,265,267,270,273,276,279,282,285,288,290,293,296,299,302,305,308,310,313,316,319,322,325,328,331,334,337,340,343,346,349,352,355,357,360,362,365,368,371,374,377,379,382,385,388,391,394,397,400,403,406,409,412,415,418,421,424,426],{"date":169,"score":170,"percentile":171},"2025-11-04",0.00062,0.19401,{"date":173,"score":170,"percentile":174},"2025-11-05",0.19406,{"date":176,"score":170,"percentile":177},"2025-11-06",0.19411,{"date":179,"score":170,"percentile":180},"2025-11-07",0.19421,{"date":182,"score":170,"percentile":183},"2025-11-08",0.19424,{"date":185,"score":170,"percentile":186},"2025-11-09",0.19396,{"date":188,"score":170,"percentile":189},"2025-11-10",0.19351,{"date":191,"score":170,"percentile":192},"2025-11-11",0.19354,{"date":194,"score":170,"percentile":186},"2025-11-12",{"date":196,"score":170,"percentile":197},"2025-11-13",0.19418,{"date":199,"score":170,"percentile":177},"2025-11-14",{"date":201,"score":170,"percentile":202},"2025-11-15",0.1938,{"date":204,"score":170,"percentile":205},"2025-11-16",0.19342,{"date":207,"score":170,"percentile":208},"2025-11-17",0.1927,{"date":210,"score":170,"percentile":211},"2025-11-18",0.15018,{"date":213,"score":170,"percentile":214},"2025-11-19",0.15034,{"date":216,"score":170,"percentile":217},"2025-11-20",0.15045,{"date":219,"score":170,"percentile":220},"2025-11-21",0.1926,{"date":222,"score":170,"percentile":223},"2025-11-22",0.19258,{"date":225,"score":170,"percentile":226},"2025-11-23",0.19235,{"date":228,"score":170,"percentile":229},"2025-11-24",0.19198,{"date":231,"score":170,"percentile":232},"2025-11-25",0.19189,{"date":234,"score":170,"percentile":235},"2025-11-26",0.19181,{"date":237,"score":170,"percentile":235},"2025-11-27",{"date":239,"score":170,"percentile":240},"2025-11-28",0.19165,{"date":242,"score":170,"percentile":243},"2025-11-29",0.19156,{"date":245,"score":170,"percentile":246},"2025-11-30",0.19159,{"date":248,"score":170,"percentile":249},"2025-12-01",0.19202,{"date":251,"score":170,"percentile":252},"2025-12-02",0.19224,{"date":254,"score":170,"percentile":255},"2025-12-03",0.19241,{"date":257,"score":170,"percentile":258},"2025-12-04",0.19203,{"date":260,"score":170,"percentile":261},"2025-12-05",0.19255,{"date":263,"score":170,"percentile":264},"2025-12-06",0.19257,{"date":266,"score":170,"percentile":255},"2025-12-07",{"date":268,"score":170,"percentile":269},"2025-12-08",0.19264,{"date":271,"score":170,"percentile":272},"2025-12-09",0.19331,{"date":274,"score":170,"percentile":275},"2025-12-10",0.19407,{"date":277,"score":170,"percentile":278},"2025-12-11",0.19447,{"date":280,"score":170,"percentile":281},"2025-12-12",0.19478,{"date":283,"score":170,"percentile":284},"2025-12-13",0.1949,{"date":286,"score":170,"percentile":287},"2025-12-14",0.19438,{"date":289,"score":170,"percentile":197},"2025-12-15",{"date":291,"score":170,"percentile":292},"2025-12-16",0.19453,{"date":294,"score":170,"percentile":295},"2025-12-17",0.19535,{"date":297,"score":170,"percentile":298},"2025-12-18",0.19625,{"date":300,"score":170,"percentile":301},"2025-12-19",0.19646,{"date":303,"score":170,"percentile":304},"2025-12-20",0.19618,{"date":306,"score":170,"percentile":307},"2025-12-21",0.19581,{"date":309,"score":170,"percentile":295},"2025-12-22",{"date":311,"score":170,"percentile":312},"2025-12-23",0.19539,{"date":314,"score":170,"percentile":315},"2025-12-24",0.19578,{"date":317,"score":170,"percentile":318},"2025-12-25",0.19657,{"date":320,"score":170,"percentile":321},"2025-12-26",0.19651,{"date":323,"score":112,"percentile":324},"2025-12-27",0.22362,{"date":326,"score":170,"percentile":327},"2025-12-28",0.19612,{"date":329,"score":170,"percentile":330},"2025-12-29",0.19565,{"date":332,"score":170,"percentile":333},"2025-12-30",0.19558,{"date":335,"score":170,"percentile":336},"2025-12-31",0.19616,{"date":338,"score":170,"percentile":339},"2026-01-01",0.19711,{"date":341,"score":170,"percentile":342},"2026-01-02",0.19716,{"date":344,"score":170,"percentile":345},"2026-01-03",0.19694,{"date":347,"score":170,"percentile":348},"2026-01-04",0.19591,{"date":350,"score":170,"percentile":351},"2026-01-05",0.19568,{"date":353,"score":170,"percentile":354},"2026-01-06",0.19582,{"date":356,"score":170,"percentile":327},"2026-01-07",{"date":358,"score":170,"percentile":359},"2026-01-08",0.19669,{"date":361,"score":170,"percentile":359},"2026-01-09",{"date":363,"score":170,"percentile":364},"2026-01-10",0.19682,{"date":366,"score":170,"percentile":367},"2026-01-11",0.19648,{"date":369,"score":170,"percentile":370},"2026-01-12",0.19611,{"date":372,"score":170,"percentile":373},"2026-01-13",0.19585,{"date":375,"score":170,"percentile":376},"2026-01-14",0.19644,{"date":378,"score":170,"percentile":367},"2026-01-15",{"date":380,"score":170,"percentile":381},"2026-01-16",0.19675,{"date":383,"score":170,"percentile":384},"2026-01-17",0.19689,{"date":386,"score":170,"percentile":387},"2026-01-18",0.19643,{"date":389,"score":170,"percentile":390},"2026-01-19",0.19595,{"date":392,"score":170,"percentile":393},"2026-01-20",0.19579,{"date":395,"score":170,"percentile":396},"2026-01-21",0.19546,{"date":398,"score":170,"percentile":399},"2026-01-22",0.19489,{"date":401,"score":170,"percentile":402},"2026-01-23",0.19588,{"date":404,"score":170,"percentile":405},"2026-01-24",0.19614,{"date":407,"score":170,"percentile":408},"2026-01-25",0.19541,{"date":410,"score":170,"percentile":411},"2026-01-26",0.19443,{"date":413,"score":170,"percentile":414},"2026-01-27",0.19437,{"date":416,"score":170,"percentile":417},"2026-01-28",0.19436,{"date":419,"score":170,"percentile":420},"2026-01-29",0.19405,{"date":422,"score":170,"percentile":423},"2026-01-30",0.19416,{"date":425,"score":170,"percentile":180},"2026-01-31",{"date":427,"score":170,"percentile":428},"2026-02-01",0.19444,[430],{"source":116,"cvss_v2_0":431,"cvss_v3_0":9,"cvss_v3_1":436,"cvss_v4_0":9},{"baseScore":432,"baseSeverity":9,"vectorString":433,"impactScore":434,"exploitabilityScore":435},3.6,"AV:L/AC:L/Au:N/C:P/I:N/A:P",4.9,3.9,{"baseScore":114,"baseSeverity":437,"vectorString":117,"impactScore":438,"exploitabilityScore":439},"MEDIUM",8.7,2.1,[441,454,461],{"ecosystem":9,"name":442,"vendor":443,"product":444,"cpe_part":445,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":446},"ubuntu linux","canonical","ubuntu_linux","o",[447,450,452],{"version":448,"is_range":110,"range_type":449,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"12.04","cpe",{"version":451,"is_range":110,"range_type":449,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"14.04",{"version":453,"is_range":110,"range_type":449,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"16.04",{"ecosystem":9,"name":455,"vendor":456,"product":457,"cpe_part":445,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":458},"debian linux","debian","debian_linux",[459],{"version":460,"is_range":110,"range_type":449,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"8.0",{"ecosystem":9,"name":462,"vendor":462,"product":462,"cpe_part":463,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":464},"qemu","a",[465],{"version":466,"is_range":467,"range_type":449,"version_start":9,"version_start_type":9,"version_end":468,"version_end_type":469,"fixed_in":9},"lte2.6.0",true,"2.6.0","including"]