CVE-2018-10893: Spice Project Spice

High severity, CVSS 8.8. EPSS: 2.4% chance of exploitation in the next 30 days.

Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.

Affected products

Published 2018-09-11. Last modified 2026-06-17.