Vulnerability index

Browse CVEs

149 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2017-14431 Memory leak in Xen 3.3 through 4.8.x allows guest OS users to cause a denial of service (ARM or x86 AMD host OS memory consumption) by continually re… Xen Patch available Fix from $1,6002017-09-13 HIGH 8.8 CVE-2017-14316 A parameter verification issue was discovered in Xen through 4.9.x. The function `alloc_heap_pages` allows callers to specify the first NUMA node tha… Xen after 4.9.0 Fix from $1,9502017-09-12 HIGH 8.8 CVE-2017-14319 A grant unmapping issue was discovered in Xen through 4.9.x. When removing or replacing a grant mapping, the x86 PV specific path needs to make sure … Xen after 4.9.0 Fix from $1,9502017-09-12 MEDIUM 6.5 CVE-2017-14318 An issue was discovered in Xen 4.5.x through 4.9.x. The function `__gnttab_cache_flush` handles GNTTABOP_cache_flush grant table operations. It check… Xen Patch available Fix from $1,6002017-09-12 MEDIUM 5.6 CVE-2017-14317 A domain cleanup issue was discovered in the C xenstore daemon (aka cxenstored) in Xen through 4.9.x. When shutting down a VM with a stubdomain, a ra… Xen after 4.9.0 Fix from $1,6002017-09-12 MEDIUM 6.5 CVE-2017-12855 Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use. A guest is expected not to modify the grant de… Xen Mitigation only Fix from $1,6002017-08-15 CRITICAL 10.0 CVE-2017-10912 Xen through 4.8.x mishandles page transfer, which allows guest OS users to obtain privileged host OS access, aka XSA-217. Xen after 4.8.1 Fix from $2,3002017-07-05 CRITICAL 10.0 CVE-2017-10918 Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access… Xen after 4.8.1 Fix from $2,3002017-07-05 CRITICAL 10.0 CVE-2017-10920 The grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed by only a GNTMAP_host_map unma… Xen after 4.8.1 Fix from $2,3002017-07-05 CRITICAL 10.0 CVE-2017-10921 The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows… Xen after 4.8.1 Fix from $2,3002017-07-05 CRITICAL 9.8 CVE-2017-10913 The grant-table feature in Xen through 4.8.x provides false mapping information in certain cases of concurrent unmap calls, which allows backend atta… Xen after 4.8.1 Fix from $2,3002017-07-05 CRITICAL 9.1 CVE-2017-10917 Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL po… Xen after 4.8.1 Fix from $2,3002017-07-05 CRITICAL 9.0 CVE-2017-10915 The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users t… Xen after 4.8.1 Fix from $2,3002017-07-05 HIGH 8.1 CVE-2017-10914 The grant-table feature in Xen through 4.8.x has a race condition leading to a double free, which allows guest OS users to cause a denial of service … Xen after 4.8.1 Fix from $1,9502017-07-05 HIGH 7.5 CVE-2017-10916 The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (MPX) and Protection Key (PKU)… Xen Mitigation only Fix from $1,9502017-07-05 HIGH 7.5 CVE-2017-10922 The grant-table feature in Xen through 4.8.x mishandles MMIO region grant references, which allows guest OS users to cause a denial of service (loss … Xen after 4.8.1 Fix from $1,9502017-07-05 MEDIUM 6.5 CVE-2017-10919 Xen through 4.8.x mishandles virtual interrupt injection, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-223. Xen after 4.8.1 Fix from $1,6002017-07-05 MEDIUM 6.5 CVE-2017-10923 Xen through 4.8.x does not validate a vCPU array index upon the sending of an SGI, which allows guest OS users to cause a denial of service (hypervis… Xen Mitigation only Fix from $1,6002017-07-05 HIGH 8.8 CVE-2017-8903 Xen through 4.8.x on 64-bit platforms mishandles page tables after an IRET hypercall, which might allow PV guest OS users to execute arbitrary code o… Xen Patch available Fix from $1,9502017-05-11 HIGH 8.8 CVE-2017-8904 Xen through 4.8.x mishandles the "contains segment descriptors" property during GNTTABOP_transfer (aka guest transfer) operations, which might allow … Xen Patch available Fix from $1,9502017-05-11 HIGH 8.8 CVE-2017-8905 Xen through 4.6.x on 64-bit platforms mishandles a failsafe callback, which might allow PV guest OS users to execute arbitrary code on the host OS, a… Xen Patch available Fix from $1,9502017-05-11 HIGH 8.2 CVE-2017-7228 An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The earlier XSA-29 fix introduced … Xen Patch available Fix from $1,9502017-04-04 MEDIUM 6.5 CVE-2016-9815 Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host panic) by sending an asynchronous abort. Xen Patch available Fix from $1,6002017-02-27 MEDIUM 6.5 CVE-2016-9816 Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving an asynchronous abort while at EL2. Xen Patch available Fix from $1,6002017-02-27 MEDIUM 6.5 CVE-2016-9817 Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving a (1) data or (2) prefetch abort wi… Xen Patch available Fix from $1,6002017-02-27 MEDIUM 6.5 CVE-2016-9818 Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving an asynchronous abort while at HYP. Xen Patch available Fix from $1,6002017-02-27 MEDIUM 6.5 CVE-2016-9384 Xen 4.7 allows local guest OS users to obtain sensitive host information by loading a 32-bit ELF symbol table. Xen Patch available Fix from $1,6002017-02-22 MEDIUM 5.5 CVE-2016-9377 Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM gues… Xen Patch available Fix from $1,6002017-02-22 MEDIUM 5.5 CVE-2016-9378 Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM gues… Xen Patch available Fix from $1,6002017-02-22 HIGH 7.8 CVE-2016-10013 Xen through 4.8.x allows local 64-bit x86 HVM guest OS users to gain privileges by leveraging mishandling of SYSCALL singlestep during emulation. Xen after 4.8.0 Fix from $1,9502017-01-26