Vulnerability index

Browse CVEs

149 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.3 CVE-2016-7777 Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM registe… Xen after 4.7.0 Fix from $1,6002016-10-07 MEDIUM 6.7 CVE-2016-7154 Use-after-free vulnerability in the FIFO event channel code in Xen 4.4.x allows local guest OS administrators to cause a denial of service (host cras… Xen Patch available Fix from $1,6002016-09-21 HIGH 8.2 CVE-2016-7093 Xen 4.5.3, 4.6.3, and 4.7.x allow local HVM guest OS administrators to overwrite hypervisor memory and consequently gain host OS privileges by levera… Xen Patch available Fix from $1,9502016-09-21 HIGH 8.2 CVE-2016-7092 The get_page_from_l3e function in arch/x86/mm.c in Xen allows local 32-bit PV guest OS administrators to gain host OS privileges via vectors related … Xen Patch available Fix from $1,9502016-09-21 MEDIUM 5.6 CVE-2016-5242 The p2m_teardown function in arch/arm/p2m.c in Xen 4.4.x through 4.6.x allows local guest OS users with access to the driver domain to cause a denial… Xen Mitigation only Fix from $1,6002016-06-07 HIGH 7.5 CVE-2015-8554 Buffer overflow in hw/pt-msi.c in Xen 4.6.x and earlier, when using the qemu-xen-traditional (aka qemu-dm) device model, allows local x86 HVM guest a… Xen after 4.6.1 Fix from $1,9502016-04-14 HIGH 8.2 CVE-2015-8550 Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privilege… Xen Mitigation only Fix from $1,9502016-04-14 MEDIUM 5.5 CVE-2016-2271 VMX in Xen 4.6.x and earlier, when using an Intel or Cyrix CPU, allows local HVM guest users to cause a denial of service (guest crash) via vectors r… Xen Patch available Fix from $1,6002016-02-19 HIGH 8.5 CVE-2016-1570 The PV superpage functionality in arch/x86/mm.c in Xen 3.4.0, 3.4.1, and 4.1.x through 4.6.x allows local PV guests to obtain sensitive information, … Xen Mitigation only Fix from $1,9502016-01-22 MEDIUM 5.0 CVE-2015-8615 The hvm_set_callback_via function in arch/x86/hvm/irq.c in Xen 4.6 does not limit the number of printk console messages when logging the new callback… Xen Mitigation only Fix from $1,6002016-01-08 HIGH 7.8 CVE-2015-8341 The libxl toolstack library in Xen 4.1.x through 4.6.x does not properly release mappings of files used as kernels and initial ramdisks when managing… Xen Mitigation only Fix from $1,9502015-12-17 HIGH 7.2 CVE-2015-8338 Xen 4.6.x and earlier does not properly enforce limits on page order inputs for the (1) XENMEM_increase_reservation, (2) XENMEM_populate_physmap, (3)… Xen after 4.6.0 Fix from $1,9502015-12-17 HIGH 7.2 CVE-2015-7835 The mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not properly validate level 2 page table entries, which allows local PV gues… Xen Mitigation only Fix from $1,9502015-10-30 MEDIUM 6.8 CVE-2015-3259 Stack-based buffer overflow in the xl command line utility in Xen 4.1.x through 4.5.x allows local guest administrators to gain privileges via a long… Xen Patch available Fix from $1,6002015-07-16 HIGH 7.8 CVE-2015-4104 Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, which allows local x86 HVM guest users to cause a denial of service (… Xen Mitigation only Fix from $1,9502015-06-03 HIGH 7.8 CVE-2015-0361 Use-after-free vulnerability in Xen 4.2.x, 4.3.x, and 4.4.x allows remote domains to cause a denial of service (system crash) via a crafted hypercall… Xen Patch available Fix from $1,9502015-01-07 HIGH 8.3 CVE-2014-7188 The hvm_msr_read_intercept function in arch/x86/hvm/hvm.c in Xen 4.1 through 4.4.x uses an improper MSR range for x2APIC emulation, which allows loca… Xen Patch available Fix from $1,9502014-10-02 HIGH 7.4 CVE-2014-3969 Xen 4.4.x, when running on an ARM system, does not properly check write permissions on virtual addresses, which allows local guest administrators to … Xen Patch available Fix from $1,9502014-06-05 MEDIUM 5.5 CVE-2014-3967 The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x does not properly check the return value from the IRQ setup check, which allows local HV… Xen Patch available Fix from $1,6002014-06-05 MEDIUM 5.5 CVE-2014-3968 The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x allows local guest HVM administrators to cause a denial of service (host crash) via a la… Xen Patch available Fix from $1,6002014-06-05 MEDIUM 6.7 CVE-2014-3124 The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM administrators to cause a denial of service (hypervisor crash) or poss… Xen Patch available Fix from $1,6002014-05-07 MEDIUM 6.2 CVE-2014-3125 Xen 4.4.x, when running on an ARM system, does not properly context switch the CNTKCTL_EL1 register, which allows local guest users to modify the har… Xen Patch available Fix from $1,6002014-05-02 MEDIUM 5.5 CVE-2014-2986 The vgic_distr_mmio_write function in the virtual guest interrupt controller (GIC) distributor (arch/arm/vgic.c) in Xen 4.4.x, when running on an ARM… Xen Patch available Fix from $1,6002014-04-28 MEDIUM 5.5 CVE-2014-2915 Xen 4.4.x, when running on ARM systems, does not properly restrict access to hardware features, which allows local guest users to cause a denial of s… Xen Mitigation only Fix from $1,6002014-04-24 MEDIUM 5.8 CVE-2014-1895 Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op.c in Xen 4.2.x and 4.3.x, when the maximum number of physical CP… Xen Patch available Fix from $1,6002014-04-01 MEDIUM 5.2 CVE-2014-1891 Multiple integer overflows in the (1) FLASK_GETBOOL, (2) FLASK_SETBOOL, (3) FLASK_USER, and (4) FLASK_CONTEXT_TO_SID suboperations in the flask hyper… Xen after 4.3.0 Fix from $1,6002014-04-01 MEDIUM 5.2 CVE-2014-1892 Xen 3.3 through 4.1, when XSM is enabled, allows local users to cause a denial of service via vectors related to a "large memory allocation," a diffe… Xen Patch available Fix from $1,6002014-04-01 MEDIUM 5.2 CVE-2014-1893 Multiple integer overflows in the (1) FLASK_GETBOOL and (2) FLASK_SETBOOL suboperations in the flask hypercall in Xen 4.1.x, 3.3.x, 3.2.x, and earlie… Xen after 4.1.6.1 Fix from $1,6002014-04-01 MEDIUM 5.2 CVE-2014-1894 Multiple integer overflows in unspecified suboperations in the flask hypercall in Xen 3.2.x and earlier, when XSM is enabled, allow local users to ca… Xen after 3.2.3 Fix from $1,6002014-04-01 HIGH 8.3 CVE-2014-1666 The do_physdev_op function in Xen 4.1.5, 4.1.6.1, 4.2.2 through 4.2.3, and 4.3.x does not properly restrict access to the (1) PHYSDEVOP_prepare_msix … Xen Patch available Fix from $1,9502014-01-26