CVE-2017-7506: Spice Project Spice

High severity, CVSS 8.8. EPSS: 4.2% chance of exploitation in the next 30 days.

spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.

Affected products

  • Spice Project Spice: version 0.5.2 only; version 0.5.3 only; version 0.6.0 only; version 0.6.1 only; version 0.6.2 only; version 0.6.3 only; …

Published 2017-07-18. Last modified 2026-06-17.