Vulnerability index

Browse CVEs

149 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-23558 The adjustments made for XSA-379 as well as those subsequently becoming XSA-387 still left a race window, when a HVM or PVH guest does a grant table … Xen Patch available Fix from $1,9502026-05-19 MEDIUM 6.5 CVE-2026-23557 Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() triggering. In case xenstored w… Xen Patch available Fix from $1,6002026-05-19 HIGH 7.8 CVE-2026-23554 The Intel EPT paging code uses an optimization to defer flushing of any cached EPT state until the p2m lock is dropped, so that multiple modification… Xen Patch available Fix from $1,9502026-03-23 HIGH 7.1 CVE-2026-23555 Any guest issuing a Xenstore command accessing a node using the (illegal) node path "/local/domain/", will crash xenstored due to a clobbered error i… Xen Patch available Fix from $1,9502026-03-23 HIGH 8.8 CVE-2025-58150 Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest co… Xen Patch available Fix from $1,9502026-01-28 HIGH 7.5 CVE-2025-58148 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hyper… Xen Patch available Fix from $1,9502025-10-31 HIGH 7.5 CVE-2025-58149 When passing through PCI devices, the detach logic in libxl won't remove access permissions to any 64bit memory BARs the device might have. As a res… Xen Patch available Fix from $1,9502025-10-31 HIGH 7.5 CVE-2025-58147 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hyper… Xen Patch available Fix from $1,9502025-10-31 CRITICAL 9.8 CVE-2025-58142 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple … Xen 4.17.0+ Fix from $2,3002025-09-11 CRITICAL 9.8 CVE-2025-58143 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple … Xen 4.17.0+ Fix from $2,3002025-09-11 HIGH 7.5 CVE-2025-58144 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issue… Xen 4.17.0+ Fix from $1,9502025-09-11 HIGH 7.5 CVE-2025-58145 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issue… Xen 4.17.0+ Fix from $1,9502025-09-11 CRITICAL 9.8 CVE-2025-27466 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple … Xen 4.17.0+ Fix from $2,3002025-09-11 HIGH 7.5 CVE-2025-1713 When setting up interrupt remapping for legacy PCI(-X) devices, including PCI(-X) bridges, a lookup of the upstream bridge is required. This lookup, … Xen Patch available Fix from $1,9502025-07-17 MEDIUM 6.5 CVE-2024-45818 The hypervisor contains code to accelerate VGA memory accesses for HVM guests, when the (virtual) VGA is in "standard" mode. Locking involved there … Xen 4.20.0+ Fix from $1,6002024-12-19 MEDIUM 5.5 CVE-2024-45819 PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local memory, which are then copied… Xen Patch available Fix from $1,6002024-12-19 HIGH 7.5 CVE-2024-31145 Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or … Xen Patch available Fix from $1,9502024-09-25 HIGH 7.5 CVE-2024-31146 When multiple devices share resources and one of them is to be passed through to a guest, security of the entire system and of respective guests indi… Xen Patch available Fix from $1,9502024-09-25 HIGH 7.3 CVE-2024-45817 In x86's APIC (Advanced Programmable Interrupt Controller) architecture, error conditions are reported in a status register. Furthermore, the OS can… Xen Patch available Fix from $1,9502024-09-25 HIGH 7.5 CVE-2024-31143 An optional feature of PCI MSI called "Multiple Message" allows a device to use multiple consecutive interrupt vectors. Unlike for MSI-X, the settin… Xen Patch available Fix from $1,9502024-07-18 MEDIUM 5.5 CVE-2023-46835 The current setup of the quarantine page tables assumes that the quarantine domain (dom_io) has been initialized with an address width of DEFAULT_DOM… Xen Patch available Fix from $1,6002024-01-05 HIGH 7.8 CVE-2023-34322 For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. Since Xen itself needs to… Xen 4.15.0+ Fix from $1,9502024-01-05 HIGH 7.8 CVE-2023-34325 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] libfsimage contains… Xen Patch available Fix from $1,9502024-01-05 HIGH 7.8 CVE-2023-34326 The caching invalidation guidelines from the AMD-Vi specification (48882—Rev 3.07-PUB—Oct 2022) is incorrect on some hardware, as devices will malfun… Xen Mitigation only Fix from $1,9502024-01-05 MEDIUM 5.5 CVE-2023-34323 When a transaction is committed, C Xenstored will first check the quota is correct before attempting to commit any nodes. It would be possible that … Xen 4.17.0+ Fix from $1,6002024-01-05 MEDIUM 5.5 CVE-2023-34327 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] AMD CPUs since ~201… Xen Patch available Fix from $1,6002024-01-05 MEDIUM 5.5 CVE-2023-34328 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] AMD CPUs since ~201… Xen 4.14.0+ Fix from $1,6002024-01-05 HIGH 7.5 CVE-2022-42330 Guests can cause Xenstore crash via soft reset When a guest issues a "Soft Reset" (e.g. for performing a kexec) the libxl based Xen toolstack will no… Xen Mitigation only Fix from $1,9502023-01-26 MEDIUM 5.3 CVE-2022-33749 XAPI open file limit DoS It is possible for an unauthenticated client on the network to cause XAPI to hit its file-descriptor limit. This causes XAPI… Xapi Patch available Fix from $1,6002022-10-11 HIGH 7.0 CVE-2021-28703 grant table v2 status pages may remain accessible after de-allocation (take two) Guest get permitted access to certain Xen-owned pages of memory. The… Xen 14.4+ Fix from $1,9502021-12-07