Citrix Xen vulnerabilities
9 known vulnerabilities affecting citrix/xen.
Total CVEs
9
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM4LOW2
Vulnerabilities
Page 1 of 1
CVE-2011-3262LOWCVSS 2.1v3.2.0v3.3.0+2 more2011-08-19
CVE-2011-3262 [LOW] CWE-399 CVE-2011-3262: tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allows local users to cause a denia
tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allows local users to cause a denial of service (management software infinite loop and management domain resource consumption) via unspecified vectors related to "Lack of error checking in the decompression loop."
nvd
CVE-2011-1898HIGHCVSS 7.4v4.0.0v4.0.1+1 more2011-08-12
CVE-2011-1898 [HIGH] CWE-264 CVE-2011-1898: Xen 4.1 before 4.1.1 and 4.0 before 4.0.2, when using PCI passthrough on Intel VT-d chipsets that do
Xen 4.1 before 4.1.1 and 4.0 before 4.0.2, when using PCI passthrough on Intel VT-d chipsets that do not have interrupt remapping, allows guest OS users to gain host OS privileges by "using DMA to generate MSI interrupts by writing to the interrupt injection registers."
nvd
CVE-2011-1583MEDIUMCVSS 6.9v3.2.0v3.3.0+2 more2011-08-12
CVE-2011-1583 [MEDIUM] CWE-189 CVE-2011-1583: Multiple integer overflows in tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allow
Multiple integer overflows in tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allow local users to cause a denial of service and possibly execute arbitrary code via a crafted paravirtualised guest kernel image that triggers (1) a buffer overflow during a decompression loop or (2) an out-of-bounds read in the loader involving unspecifi
nvd
CVE-2010-4255MEDIUMCVSS 6.1≤ 4.0.1v3.0.2+17 more2011-01-25
CVE-2010-4255 [MEDIUM] CVE-2010-4255: The fixup_page_fault function in arch/x86/traps.c in Xen 4.0.1 and earlier on 64-bit platforms, when
The fixup_page_fault function in arch/x86/traps.c in Xen 4.0.1 and earlier on 64-bit platforms, when paravirtualization is enabled, does not verify that kernel mode is used to call the handle_gdt_ldt_mapping_fault function, which allows guest OS users to cause a denial of service (host OS BUG_ON) via a crafted memory access.
nvd
CVE-2010-4238MEDIUMCVSS 5.5v3.1.22011-01-22
CVE-2010-4238 [MEDIUM] CWE-264 CVE-2010-4238: The vbd_create function in Xen 3.1.2, when the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL
The vbd_create function in Xen 3.1.2, when the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 is used, allows guest OS users to cause a denial of service (host OS panic) via an attempted access to a virtual CD-ROM device through the blkback driver. NOTE: some of these details are obtained from third party information.
nvd
CVE-2010-4247MEDIUMCVSS 5.5≤ 3.3.2v3.0.2+10 more2011-01-11
CVE-2010-4247 [MEDIUM] CWE-20 CVE-2010-4247: The do_block_io_op function in (1) drivers/xen/blkback/blkback.c and (2) drivers/xen/blktap/blktap.c
The do_block_io_op function in (1) drivers/xen/blkback/blkback.c and (2) drivers/xen/blktap/blktap.c in Xen before 3.4.0 for the Linux kernel 2.6.18, and possibly other versions, allows guest OS users to cause a denial of service (infinite loop and CPU consumption) via a large production request index to the blkback or blktap back-end drivers. NOTE: so
nvd
CVE-2010-3699LOWCVSS 2.7v3.0.2v3.0.3+14 more2010-12-08
CVE-2010-3699 [LOW] CWE-399 CVE-2010-3699: The backend driver in Xen 3.x allows guest OS users to cause a denial of service via a kernel thread
The backend driver in Xen 3.x allows guest OS users to cause a denial of service via a kernel thread leak, which prevents the device and guest OS from being shut down or create a zombie domain, causes a hang in zenwatch, or prevents unspecified xm commands from working properly, related to (1) netback, (2) blkback, or (3) blktap.
nvd
CVE-2008-5716HIGHCVSS 7.2v3.3.02008-12-24
CVE-2008-5716 [HIGH] CVE-2008-5716: xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xens
xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue exists because of erroneous set_permissions
nvd
CVE-2008-4405HIGHCVSS 7.2PoCv3.0.32008-10-03
CVE-2008-4405 [HIGH] CWE-264 CVE-2008-4405: xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree,
xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM's write access within this tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid
nvd