CVE-2010-0633Citrix Xenserver vulnerability

6 documents5 sources
Severity
4.6MEDIUMNVD
EPSS
0.1%
top 79.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 12
Latest updateMay 2

Description

Unspecified vulnerability in Citrix XenServer 5.0 Update 3 and earlier, and 5.5, allows local users to bypass authentication and execute unspecified Xen API (XAPI) calls via unknown vectors.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages1 packages

NVDcitrix/xenserver5.0+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-w686-r764-pjr6: Unspecified vulnerability in Citrix XenServer 52022-05-02
CVEList
CVE-2010-0633: Unspecified vulnerability in Citrix XenServer 52010-02-12

📋Vendor Advisories

1
Citrix
CVE-2010-0633: Unspecified vulnerability in Citrix XenServer 5.0 Update 3 and earlier, and 5.5, allows local users to bypass authentication and execute unspecified X2010-02-12

💬Community

2
Bugzilla
CVE-2010-0428 libspice: Insufficient guest provided pointers validation2010-02-26
Bugzilla
CVE-2010-0429 libspice: Relying on guest provided data structures to indicate memory allocation2010-02-26
CVE-2010-0633 — Citrix Xenserver vulnerability | cvebase