CVE-2014-3461: Qemu

Medium severity, CVSS 6.8. EPSS: 2.7% chance of exploitation in the next 30 days.

hw/usb/bus.c in QEMU 1.6.2 allows remote attackers to execute arbitrary code via crafted savevm data, which triggers a heap-based buffer overflow, related to "USB post load checks."

Affected products

  • Qemu Qemu: version 1.6.2 only

Published 2014-11-04. Last modified 2026-06-17.