Vulnerability index

Browse CVEs

149 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xen HIGH 7.7
CVE-2011-1763

The get_free_port function in Xen allows local authenticated DomU users to cause a denial of service or possibly gain privileges via unspecified vect…

Mitigation only
Fix from $1,950 2014-01-07
Xen MEDIUM 6.1
CVE-2011-1780

The instruction emulation in Xen 3.0.3 allows local SMP guest users to cause a denial of service (host crash) by replacing the instruction that cause…

Mitigation only
Fix from $1,600 2014-01-07
Xen MEDIUM 5.5
CVE-2011-1166

Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of service (host crash) by specifying user mode execution without user-mo…

Fix: after 4.0.1
Fix from $1,600 2014-01-07
Xen MEDIUM 5.2
CVE-2013-4553

The XEN_DOMCTL_getmemlist hypercall in Xen 3.4.x through 4.3.x (possibly 4.3.1) does not always obtain the page_alloc_lock and mm_rwlock in the same …

Mitigation only
Fix from $1,600 2013-12-24
Xen MEDIUM 5.2
CVE-2013-4554

Xen 3.0.3 through 4.1.x (possibly 4.1.6.1), 4.2.x (possibly 4.2.3), and 4.3.x (possibly 4.3.1) does not properly prevent access to hypercalls, which …

Mitigation only
Fix from $1,600 2013-12-24
Xen MEDIUM 6.8
CVE-2013-6400

Xen 4.2.x and 4.3.x, when using Intel VT-d and a PCI device has been assigned, does not clear the flag that suppresses IOMMU TLB flushes when unspeci…

Mitigation only
Fix from $1,600 2013-12-13
Xen HIGH 7.9
CVE-2013-6375

Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properly flush the TLB after clearing a present translation table entry, whi…

Mitigation only
Fix from $1,950 2013-11-23
Xen MEDIUM 5.7
CVE-2013-4551

Xen 4.2.x and 4.3.x, when nested virtualization is disabled, does not properly check the emulation paths for (1) VMLAUNCH and (2) VMRESUME, which all…

Mitigation only
Fix from $1,600 2013-11-18
Xen MEDIUM 5.2
CVE-2013-4416

The Ocaml xenstored implementation (oxenstored) in Xen 4.1.x, 4.2.x, and 4.3.x allows local guest domains to cause a denial of service (domain shutdo…

Mitigation only
Fix from $1,600 2013-11-02
Xen MEDIUM 5.4
CVE-2013-4356

Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more than 5TB of RAM, which allows l…

Mitigation only
Fix from $1,600 2013-10-09
Xen MEDIUM 5.5
CVE-2011-2901

Off-by-one error in the __addr_ok macro in Xen 3.3 and earlier allows local 64 bit PV guest administrators to cause a denial of service (host crash) …

Fix: after 3.3.0
Fix from $1,600 2013-10-01
Xen MEDIUM 6.5
CVE-2013-4329

The xenlight library (libxl) in Xen 4.0.x through 4.2.x, when IOMMU is disabled, provides access to a busmastering-capable PCI passthrough device bef…

Patch available
Fix from $1,600 2013-09-12
Xen HIGH 7.4
CVE-2013-1432

Xen 4.1.x and 4.2.x, when the XSA-45 patch is in place, does not properly maintain references on pages stored for deferred cleanup, which allows loca…

Patch available
Fix from $1,950 2013-08-28
Xen HIGH 7.4
CVE-2013-2211

The libxenlight (libxl) toolstack library in Xen 4.0.x, 4.1.x, and 4.2.x uses weak permissions for xenstore keys for paravirtualised and emulated ser…

Mitigation only
Fix from $1,950 2013-08-28
Xen MEDIUM 5.7
CVE-2013-2212

The vmx_set_uc_mode function in Xen 3.3 through 4.3, when disabling caches, allows local HVM guests with access to memory mapped I/O regions to cause…

Mitigation only
Fix from $1,600 2013-08-28
Xen MEDIUM 5.2
CVE-2013-2077

Xen 4.0.x, 4.1.x, and 4.2.x does not properly restrict the contents of a XRSTOR, which allows local PV guest users to cause a denial of service (unha…

Mitigation only
Fix from $1,600 2013-08-28
Xen MEDIUM 6.9
CVE-2013-2194

Multiple integer overflows in the Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an u…

Fix: after 4.2.2
Fix from $1,600 2013-08-23
Xen MEDIUM 6.9
CVE-2013-2195

The Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an unspecified impact via a crafte…

Fix: after 4.2.2
Fix from $1,600 2013-08-23
Xen MEDIUM 6.9
CVE-2013-2196

Multiple unspecified vulnerabilities in the Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to…

Fix: after 4.2.2
Fix from $1,600 2013-08-23
Xen MEDIUM 6.9
CVE-2013-1964

Xen 4.0.x and 4.1.x incorrectly releases a grant reference when releasing a non-v1, non-transitive grant, which allows local guest administrators to …

Mitigation only
Fix from $1,600 2013-05-21
Xen MEDIUM 6.1
CVE-2012-5634

Xen 4.2.x, 4.1.x, and 4.0, when using Intel VT-d for PCI passthrough, does not properly configure VT-d when supporting a device that is behind a lega…

Mitigation only
Fix from $1,600 2013-02-14
Xen MEDIUM 6.9
CVE-2012-5513

The XENMEM_exchange handler in Xen 4.2 and earlier does not properly check the memory address, which allows local PV guest OS administrators to cause…

Fix: after 4.2.0
Fix from $1,600 2012-12-13
Xen HIGH 7.2
CVE-2012-6030

The do_tmem_op function in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 allow local guest OS users to cause a denial of service (host cras…

Mitigation only
Fix from $1,950 2012-11-23
Xen MEDIUM 6.9
CVE-2012-6035

The do_tmem_destroy_pool function in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 does not properly validate pool ids, which allows local …

Mitigation only
Fix from $1,600 2012-11-23
Xen MEDIUM 6.9
CVE-2012-3497

(1) TMEMC_SAVE_GET_CLIENT_WEIGHT, (2) TMEMC_SAVE_GET_CLIENT_CAP, (3) TMEMC_SAVE_GET_CLIENT_FLAGS and (4) TMEMC_SAVE_END in the Transcendent Memory (T…

Mitigation only
Fix from $1,600 2012-11-23
Xen HIGH 7.2
CVE-2009-3525

The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows…

Patch available
Fix from $1,950 2009-10-05
Xen MEDIUM 5.0
CVE-2009-1758

The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and probably other versions allows…

Fix: after 3.3.1
Fix from $1,600 2009-05-22
Xen MEDIUM 6.9
CVE-2008-4993

qemu-dm.debug in Xen 3.2.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/args temporary file.

Mitigation only
Fix from $1,600 2008-11-07
Xen MEDIUM 6.8
CVE-2008-3687

Heap-based buffer overflow in the flask_security_label function in Xen 3.3, when compiled with the XSM:FLASK module, allows unprivileged domain users…

Patch available
Fix from $1,600 2008-08-14