spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak. https://nvd.nist.gov/vuln/detail/CVE-2017-7506