Vulnerability index

Browse CVEs

149 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xen HIGH 7.1
CVE-2021-28692

inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such…

Mitigation only
Fix from $1,950 2021-06-30
Xen MEDIUM 5.5
CVE-2021-28693

xen/arm: Boot modules are not scrubbed The bootloader will load boot modules (e.g. kernel, initramfs...) in a temporary area before they are copied b…

Fix: after 4.15.0
Fix from $1,600 2021-06-30
Xen MEDIUM 6.5
CVE-2021-28690

x86: TSX Async Abort protections not restored after S3 This issue relates to the TSX Async Abort speculative security vulnerability. Please see https…

Fix: after 4.15.0
Fix from $1,600 2021-06-29
Xen MEDIUM 5.5
CVE-2021-28687

HVM soft-reset crashes toolstack libxl requires all data structures passed across its public interface to be initialized before use and disposed of a…

Fix: after 4.15.0
Fix from $1,600 2021-06-11
Xen MEDIUM 5.5
CVE-2021-28689

x86: Speculative vulnerabilities with bare (non-shim) 32-bit PV guests 32-bit x86 PV guest kernels run in ring 1. At the time when Xen was developed,…

Fix: 4.12.0+
Fix from $1,600 2021-06-11
Xapi HIGH 7.5
CVE-2020-29487

An issue was discovered in Xen XAPI before 2020-12-15. Certain xenstore keys provide feedback from the guest, and are therefore watched by toolstack.…

Fix: 2020-12-15+
Fix from $1,950 2020-12-15
Xen HIGH 8.8
CVE-2020-29040

An issue was discovered in Xen through 4.14.x allowing x86 HVM guest OS users to cause a denial of service (stack corruption), cause a data leak, or …

Fix: after 4.14.0
Fix from $1,950 2020-11-24
Xen HIGH 7.8
CVE-2018-19963

An issue was discovered in Xen 4.11 allowing HVM guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges beca…

Patch available
Fix from $1,950 2018-12-08
Xen MEDIUM 6.5
CVE-2018-19964

An issue was discovered in Xen 4.11.x allowing x86 guest OS users to cause a denial of service (host OS hang) because the p2m lock remains unavailabl…

Fix: after 4.11.1
Fix from $1,600 2018-12-08
Xen HIGH 8.8
CVE-2018-18883

An issue was discovered in Xen 4.9.x through 4.11.x, on Intel x86 platforms, allowing x86 HVM and PVH guests to cause a host OS denial of service (NU…

Fix: after 4.11.0
Fix from $1,950 2018-11-01
Xen MEDIUM 6.5
CVE-2018-15470

An issue was discovered in Xen through 4.11.x. The logic in oxenstored for handling writes depended on the order of evaluation of expressions making …

Fix: after 4.11.0
Fix from $1,600 2018-08-17
Xen MEDIUM 6.0
CVE-2018-15468

An issue was discovered in Xen through 4.11.x. The DEBUGCTL MSR contains several debugging features, some of which virtualise cleanly, but some do no…

Fix: after 4.11.0
Fix from $1,600 2018-08-17
Xen MEDIUM 6.5
CVE-2018-5244

In Xen 4.10, new infrastructure was introduced as part of an overhaul to how MSR emulation happens for guests. Unfortunately, one tracking structure …

Mitigation only
Fix from $1,600 2018-01-05
Xen HIGH 7.8
CVE-2017-17563

An issue was discovered in Xen through 4.9.x allowing guest OS users to cause a denial of service (host OS crash) or gain host OS privileges by lever…

Fix: after 4.9.1
Fix from $1,950 2017-12-12
Xen HIGH 7.8
CVE-2017-17564

An issue was discovered in Xen through 4.9.x allowing guest OS users to cause a denial of service (host OS crash) or gain host OS privileges by lever…

Fix: after 4.9.1
Fix from $1,950 2017-12-12
Xen HIGH 7.8
CVE-2017-17566

An issue was discovered in Xen through 4.9.x allowing PV guest OS users to cause a denial of service (host OS crash) or gain host OS privileges in sh…

Fix: after 4.9.1
Fix from $1,950 2017-12-12
Xen MEDIUM 5.6
CVE-2017-17565

An issue was discovered in Xen through 4.9.x allowing PV guest OS users to cause a denial of service (host OS crash) if shadow mode and log-dirty mod…

Fix: after 4.9.1
Fix from $1,600 2017-12-12
Xen HIGH 8.8
CVE-2017-17045

An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to gain privileges on the host OS, obtain sensitive information, or cause a …

Fix: after 4.9.1
Fix from $1,950 2017-11-28
Xen MEDIUM 6.5
CVE-2017-17044

An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to cause a denial of service (infinite loop and host OS hang) by leveraging …

Fix: after 4.9.1
Fix from $1,600 2017-11-28
Xen MEDIUM 6.5
CVE-2017-17046

An issue was discovered in Xen through 4.9.x on the ARM platform allowing guest OS users to obtain sensitive information from DRAM after a reboot, be…

Fix: after 4.9.1
Fix from $1,600 2017-11-28
Xen CRITICAL 9.1
CVE-2017-15597

An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page refer…

Fix: after 4.9.0
Fix from $2,300 2017-10-30
Xen HIGH 8.8
CVE-2017-15590

An issue was discovered in Xen through 4.9.x allowing x86 guest OS users to cause a denial of service (hypervisor crash) or possibly gain privileges …

Patch available
Fix from $1,950 2017-10-18
Xen HIGH 8.8
CVE-2017-15592

An issue was discovered in Xen through 4.9.x allowing x86 HVM guest OS users to cause a denial of service (hypervisor crash) or possibly gain privile…

Fix: after 4.9.0
Fix from $1,950 2017-10-18
Xen HIGH 8.8
CVE-2017-15594

An issue was discovered in Xen through 4.9.x allowing x86 SVM PV guest OS users to cause a denial of service (hypervisor crash) or gain privileges be…

Fix: after 4.9.0
Fix from $1,950 2017-10-18
Xen HIGH 8.8
CVE-2017-15595

An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to cause a denial of service (unbounded recursion, stack consumption, and…

Fix: after 4.9.0
Fix from $1,950 2017-10-18
Xen HIGH 7.8
CVE-2017-15588

An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to execute arbitrary code on the host OS because of a race condition that…

Patch available
Fix from $1,950 2017-10-18
Xen MEDIUM 6.5
CVE-2017-15589

An issue was discovered in Xen through 4.9.x allowing x86 HVM guest OS users to obtain sensitive information from the host OS (or an arbitrary guest …

Patch available
Fix from $1,600 2017-10-18
Xen MEDIUM 6.5
CVE-2017-15591

An issue was discovered in Xen 4.5.x through 4.9.x allowing attackers (who control a stub domain kernel or tool stack) to cause a denial of service (…

Patch available
Fix from $1,600 2017-10-18
Xen MEDIUM 6.5
CVE-2017-15593

An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to cause a denial of service (memory leak) because reference counts are m…

Fix: after 4.9.0
Fix from $1,600 2017-10-18
Xen MEDIUM 6.0
CVE-2017-15596

An issue was discovered in Xen 4.4.x through 4.9.x allowing ARM guest OS users to cause a denial of service (prevent physical CPU usage) because of l…

Patch available
Fix from $1,600 2017-10-18