CVE-2014-3717 — Improper Input Validation in XEN
Severity
3.3LOWNVD
EPSS
0.2%
top 60.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 19
Latest updateMay 14
Description
Xen 4.4.x does not properly validate the load address for 64-bit ARM guest kernels, which allows local users to read system memory or cause a denial of service (crash) via a crafted kernel, which triggers a buffer overflow.
CVSS vector
AV:L/AC:M/C:P/I:N/A:PExploitability: 3.4 | Impact: 4.9