Citrix Xenserver vulnerabilities
50 known vulnerabilities affecting citrix/xenserver.
Total CVEs
50
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH20MEDIUM20LOW3
Vulnerabilities
Page 1 of 3
CVE-2018-8897P2HIGHCVSS 7.8PoCv6.0.2v6.2.0+6 more2018-05-08
CVE-2018-8897 [HIGH] CWE-362 CVE-2018-8897: A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Develop
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferred by MOV SS or POP SS, as demonstrated by (for example) privilege escalation in Windows, macOS
nvd
CVE-2012-0217P3HIGHCVSS 7.2PoC≤ 6.0.2v6.02012-06-12
CVE-2012-0217 [HIGH] CWE-119 CVE-2012-0217: The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold an
nvd
CVE-2018-14007P2CRITICALCVSS 9.8v7.1v7.4+1 more2018-08-15
CVE-2018-14007 [CRITICAL] CWE-22 CVE-2018-14007: Citrix XenServer 7.1 and newer allows Directory Traversal.
Citrix XenServer 7.1 and newer allows Directory Traversal.
nvd
CVE-2017-2620P2CRITICALCVSS 9.9v6.0.2v6.2.0+3 more2018-07-27
CVE-2017-2620 [CRITICAL] CWE-787 CVE-2017-2620: Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of th
nvd
CVE-2016-9603P3CRITICALCVSS 9.9v6.0.2v6.2.0+3 more2018-07-27
CVE-2016-9603 [CRITICAL] CWE-122 CVE-2016-9603: A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver s
A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU process or, potentially, execute a
nvd
CVE-2016-5302P3CRITICALCVSS 9.8≤ 7.02016-06-13
CVE-2016-5302 [CRITICAL] CWE-284 CVE-2016-5302: Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier rel
Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a host by leveraging credentials for an Active Directory account.
nvd
CVE-2015-7705P3CRITICALCVSS 9.8v6.0.2v6.2.0+2 more2017-08-07
CVE-2015-7705 [CRITICAL] CWE-20 CVE-2015-7705: The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers
The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.
nvd
CVE-2017-2615P3CRITICALCVSS 9.1v6.0.2v6.2.0+3 more2018-07-03
CVE-2017-2615 [CRITICAL] CWE-787 CVE-2017-2615: Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-o
Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute arbitrary code on the host with privi
nvd
CVE-2015-7704P3HIGHCVSS 7.5v6.0.2v6.2.0+2 more2017-08-07
CVE-2015-7704 [HIGH] CWE-20 CVE-2015-7704: The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a
The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.
nvd
CVE-2016-3710P3HIGHCVSS 8.8≤ 7.02016-05-11
CVE-2016-3710 [HIGH] CWE-119 CVE-2016-3710: The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which a
The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.
nvd
CVE-2014-4947P3CRITICALCVSS 10.0v6.2.02014-07-22
CVE-2014-4947 [CRITICAL] CWE-119 CVE-2014-4947: Buffer overflow in the HVM graphics console support in Citrix XenServer 6.2 Service Pack 1 and earli
Buffer overflow in the HVM graphics console support in Citrix XenServer 6.2 Service Pack 1 and earlier has unspecified impact and attack vectors.
nvd
CVE-2016-6258P3HIGHCVSS 8.8v6.0v6.0.2+4 more2016-08-02
CVE-2016-6258 [HIGH] CWE-284 CVE-2016-6258: The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS admi
The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.
nvd
CVE-2015-8555P3HIGHCVSS 8.6v6.02016-04-13
CVE-2015-8555 [HIGH] CWE-200 CVE-2015-8555: Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when X
Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows local guest domains to obtain sensitive information from other domains via unspecified vectors.
nvd
CVE-2017-12137P3HIGHCVSS 8.8v6.0.2v6.2.0+4 more2017-08-24
CVE-2017-12137 [HIGH] CWE-120 CVE-2017-12137: arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related t
arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.
nvd
CVE-2017-12134P3HIGHCVSS 8.8v6.0.2v6.2.0+4 more2017-08-24
CVE-2017-12134 [HIGH] CWE-682 CVE-2017-12134: The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest u
The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streams and consequently obtain sensitive memory information, cause a denial of service, or gain host OS privileges by leveraging incorrect block IO merge-ability calculation.
nvd
CVE-2016-9383P3HIGHCVSS 8.8v6.0.2v6.2.0+2 more2017-01-23
CVE-2016-9383 [HIGH] CWE-20 CVE-2016-9383: Xen, when running on a 64-bit hypervisor, allows local x86 guest OS users to modify arbitrary memory
Xen, when running on a 64-bit hypervisor, allows local x86 guest OS users to modify arbitrary memory and consequently obtain sensitive information, cause a denial of service (host crash), or execute arbitrary code on the host by leveraging broken emulation of bit test instructions.
nvd
CVE-2016-9382P3HIGHCVSS 7.8v6.0.2v6.2.0+2 more2017-01-23
CVE-2016-9382 [HIGH] CWE-264 CVE-2016-9382: Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM
Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM guest OS users to gain privileges or cause a denial of service (guest OS crash) by leveraging a guest operating system that uses hardware task switching and allows a new task to start in VM86 mode.
nvd
CVE-2016-9386P3HIGHCVSS 7.8v6.0.2v6.2.0+2 more2017-01-23
CVE-2016-9386 [HIGH] CWE-264 CVE-2016-9386: The x86 emulator in Xen does not properly treat x86 NULL segments as unusable when accessing memory,
The x86 emulator in Xen does not properly treat x86 NULL segments as unusable when accessing memory, which might allow local HVM guest users to gain privileges via vectors involving "unexpected" base/limit values.
nvd
CVE-2018-19962P3HIGHCVSS 7.8v7.0v7.1+2 more2018-12-08
CVE-2018-19962 [HIGH] CWE-200 CVE-2018-19962: An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users
An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.
nvd
CVE-2018-19961P3HIGHCVSS 7.8v7.0v7.1+2 more2018-12-08
CVE-2018-19961 [HIGH] CWE-459 CVE-2018-19961: An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users
An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes.
nvd
1 / 3Next →