Vulnerability index

Browse CVEs

33 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Xen HIGH 7.8
CVE-2023-34326

The caching invalidation guidelines from the AMD-Vi specification (48882—Rev 3.07-PUB—Oct 2022) is incorrect on some hardware, as devices will malfun…

Mitigation only
Fix from $1,950 2024-01-05
Xen HIGH 7.5
CVE-2022-42330

Guests can cause Xenstore crash via soft reset When a guest issues a "Soft Reset" (e.g. for performing a kexec) the libxl based Xen toolstack will no…

Mitigation only
Fix from $1,950 2023-01-26
Xen HIGH 7.1
CVE-2021-28692

inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such…

Mitigation only
Fix from $1,950 2021-06-30
Xen MEDIUM 6.5
CVE-2018-5244

In Xen 4.10, new infrastructure was introduced as part of an overhaul to how MSR emulation happens for guests. Unfortunately, one tracking structure …

Mitigation only
Fix from $1,600 2018-01-05
Xen MEDIUM 6.5
CVE-2017-12855

Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use. A guest is expected not to modify the grant de…

Mitigation only
Fix from $1,600 2017-08-15
Xen HIGH 7.5
CVE-2017-10916

The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (MPX) and Protection Key (PKU)…

Mitigation only
Fix from $1,950 2017-07-05
Xen MEDIUM 6.5
CVE-2017-10923

Xen through 4.8.x does not validate a vCPU array index upon the sending of an SGI, which allows guest OS users to cause a denial of service (hypervis…

Mitigation only
Fix from $1,600 2017-07-05
Xen MEDIUM 5.6
CVE-2016-5242

The p2m_teardown function in arch/arm/p2m.c in Xen 4.4.x through 4.6.x allows local guest OS users with access to the driver domain to cause a denial…

Mitigation only
Fix from $1,600 2016-06-07
Xen HIGH 8.2
CVE-2015-8550

Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privilege…

Mitigation only
Fix from $1,950 2016-04-14
Xen HIGH 8.5
CVE-2016-1570

The PV superpage functionality in arch/x86/mm.c in Xen 3.4.0, 3.4.1, and 4.1.x through 4.6.x allows local PV guests to obtain sensitive information, …

Mitigation only
Fix from $1,950 2016-01-22
Xen MEDIUM 5.0
CVE-2015-8615

The hvm_set_callback_via function in arch/x86/hvm/irq.c in Xen 4.6 does not limit the number of printk console messages when logging the new callback…

Mitigation only
Fix from $1,600 2016-01-08
Xen HIGH 7.8
CVE-2015-8341

The libxl toolstack library in Xen 4.1.x through 4.6.x does not properly release mappings of files used as kernels and initial ramdisks when managing…

Mitigation only
Fix from $1,950 2015-12-17
Xen HIGH 7.2
CVE-2015-7835

The mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not properly validate level 2 page table entries, which allows local PV gues…

Mitigation only
Fix from $1,950 2015-10-30
Xen HIGH 7.8
CVE-2015-4104

Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, which allows local x86 HVM guest users to cause a denial of service (…

Mitigation only
Fix from $1,950 2015-06-03
Xen MEDIUM 5.5
CVE-2014-2915

Xen 4.4.x, when running on ARM systems, does not properly restrict access to hardware features, which allows local guest users to cause a denial of s…

Mitigation only
Fix from $1,600 2014-04-24
Xen HIGH 7.7
CVE-2011-1763

The get_free_port function in Xen allows local authenticated DomU users to cause a denial of service or possibly gain privileges via unspecified vect…

Mitigation only
Fix from $1,950 2014-01-07
Xen MEDIUM 6.1
CVE-2011-1780

The instruction emulation in Xen 3.0.3 allows local SMP guest users to cause a denial of service (host crash) by replacing the instruction that cause…

Mitigation only
Fix from $1,600 2014-01-07
Xen MEDIUM 5.2
CVE-2013-4553

The XEN_DOMCTL_getmemlist hypercall in Xen 3.4.x through 4.3.x (possibly 4.3.1) does not always obtain the page_alloc_lock and mm_rwlock in the same …

Mitigation only
Fix from $1,600 2013-12-24
Xen MEDIUM 5.2
CVE-2013-4554

Xen 3.0.3 through 4.1.x (possibly 4.1.6.1), 4.2.x (possibly 4.2.3), and 4.3.x (possibly 4.3.1) does not properly prevent access to hypercalls, which …

Mitigation only
Fix from $1,600 2013-12-24
Xen MEDIUM 6.8
CVE-2013-6400

Xen 4.2.x and 4.3.x, when using Intel VT-d and a PCI device has been assigned, does not clear the flag that suppresses IOMMU TLB flushes when unspeci…

Mitigation only
Fix from $1,600 2013-12-13
Xen HIGH 7.9
CVE-2013-6375

Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properly flush the TLB after clearing a present translation table entry, whi…

Mitigation only
Fix from $1,950 2013-11-23
Xen MEDIUM 5.7
CVE-2013-4551

Xen 4.2.x and 4.3.x, when nested virtualization is disabled, does not properly check the emulation paths for (1) VMLAUNCH and (2) VMRESUME, which all…

Mitigation only
Fix from $1,600 2013-11-18
Xen MEDIUM 5.2
CVE-2013-4416

The Ocaml xenstored implementation (oxenstored) in Xen 4.1.x, 4.2.x, and 4.3.x allows local guest domains to cause a denial of service (domain shutdo…

Mitigation only
Fix from $1,600 2013-11-02
Xen MEDIUM 5.4
CVE-2013-4356

Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more than 5TB of RAM, which allows l…

Mitigation only
Fix from $1,600 2013-10-09
Xen HIGH 7.4
CVE-2013-2211

The libxenlight (libxl) toolstack library in Xen 4.0.x, 4.1.x, and 4.2.x uses weak permissions for xenstore keys for paravirtualised and emulated ser…

Mitigation only
Fix from $1,950 2013-08-28
Xen MEDIUM 5.7
CVE-2013-2212

The vmx_set_uc_mode function in Xen 3.3 through 4.3, when disabling caches, allows local HVM guests with access to memory mapped I/O regions to cause…

Mitigation only
Fix from $1,600 2013-08-28
Xen MEDIUM 5.2
CVE-2013-2077

Xen 4.0.x, 4.1.x, and 4.2.x does not properly restrict the contents of a XRSTOR, which allows local PV guest users to cause a denial of service (unha…

Mitigation only
Fix from $1,600 2013-08-28
Xen MEDIUM 6.9
CVE-2013-1964

Xen 4.0.x and 4.1.x incorrectly releases a grant reference when releasing a non-v1, non-transitive grant, which allows local guest administrators to …

Mitigation only
Fix from $1,600 2013-05-21
Xen MEDIUM 6.1
CVE-2012-5634

Xen 4.2.x, 4.1.x, and 4.0, when using Intel VT-d for PCI passthrough, does not properly configure VT-d when supporting a device that is behind a lega…

Mitigation only
Fix from $1,600 2013-02-14
Xen HIGH 7.2
CVE-2012-6030

The do_tmem_op function in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 allow local guest OS users to cause a denial of service (host cras…

Mitigation only
Fix from $1,950 2012-11-23