cbcvebase.

Citrix Xenserver vulnerabilities

50 known vulnerabilities affecting citrix/xenserver.

Total CVEs
50
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH20MEDIUM20LOW3

Vulnerabilities

Page 2 of 3
CVE-2012-4606P3HIGHCVSS 7.8v4.1v5.0+3 more2020-01-23
CVE-2012-4606 [HIGH] CWE-269 CVE-2012-4606: Citrix XenServer 4.1, 6.0, 5.6 SP2, 5.6 Feature Pack 1, 5.6 Common Criteria, 5.6, 5.5, 5.0, and 5.0 Citrix XenServer 4.1, 6.0, 5.6 SP2, 5.6 Feature Pack 1, 5.6 Common Criteria, 5.6, 5.5, 5.0, and 5.0 Update 3 contains a Local Privilege Escalation Vulnerability which could allow local users with access to a guest operating system to gain elevated privileges.
nvd
CVE-2016-9380P3HIGHCVSS 7.5v6.0.2v6.2.0+2 more2017-01-23
CVE-2016-9380 [HIGH] CWE-20 CVE-2016-9380: The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via NUL bytes in the bootloader configuration file.
nvd
CVE-2017-12136P3HIGHCVSS 7.8v6.0.2v6.2.0+4 more2017-08-24
CVE-2017-12136 [HIGH] CWE-362 CVE-2017-12136: Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrato Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling.
nvd
CVE-2017-12135P3HIGHCVSS 8.8v6.0.2v6.2.0+4 more2017-08-24
CVE-2017-12135 [HIGH] CWE-682 CVE-2017-12135: Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive in Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involving transitive grants.
nvd
CVE-2016-9379P3HIGHCVSS 7.9v6.0.2v6.2.0+2 more2017-01-23
CVE-2016-9379 [HIGH] CWE-20 CVE-2016-9379: The pygrub boot loader emulator in Xen, when S-expression output format is requested, allows local p The pygrub boot loader emulator in Xen, when S-expression output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via string quotes and S-expressions in the bootloader configuration file.
nvd
CVE-2016-9381P3HIGHCVSS 7.5v6.0.2v6.2.0+2 more2017-01-23
CVE-2016-9381 [HIGH] CWE-362 CVE-2016-9381: Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by cha Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double fetch" vulnerability.
nvd
CVE-2016-9637P4HIGHCVSS 7.5v6.0.2v6.2.0+2 more2017-02-17
CVE-2016-9637 [HIGH] CWE-264 CVE-2016-9637: The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model withi The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS administrators to gain qemu process privileges via vectors involving an out-of-range ioport access.
nvd
CVE-2016-1571P4MEDIUMCVSS 6.3≤ 6.52016-01-22
CVE-2016-1571 [MEDIUM] CWE-17 CVE-2016-1571: The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address in an INVVPID instruction, which triggers a hypervisor bug check.
nvd
CVE-2017-5572P4MEDIUMCVSS 6.5v6.0.2v6.2.0+2 more2017-01-30
CVE-2017-5572 [MEDIUM] CWE-269 CVE-2017-5572: An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated r An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated read-only administrator can corrupt the host database.
nvd
CVE-2014-3798P4MEDIUMCVSS 6.5v6.0v6.0.2+2 more2019-07-11
CVE-2014-3798 [MEDIUM] CWE-20 CVE-2014-3798: The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a d The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (guest OS crash) via a crafted Ethernet frame.
nvd
CVE-2014-4948P4MEDIUMCVSS 6.4v6.2.02014-07-22
CVE-2014-4948 [MEDIUM] CVE-2014-4948: Unspecified vulnerability in Citrix XenServer 6.2 Service Pack 1 and earlier allows attackers to cau Unspecified vulnerability in Citrix XenServer 6.2 Service Pack 1 and earlier allows attackers to cause a denial of service and obtain sensitive information by modifying the guest virtual hard disk (VHD).
nvd
CVE-2012-3516P4MEDIUMCVSS 6.9≤ 6.0.22012-11-23
CVE-2012-3516 [MEDIUM] CWE-264 CVE-2012-3516: The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4.2 and Citrix XenServ The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4.2 and Citrix XenServer 6.0.2 allows local guest kernels or administrators to cause a denial of service (host crash) and possibly gain privileges via a crafted grant reference that triggers a write to an arbitrary hypervisor memory location.
nvd
CVE-2018-3665P4MEDIUMCVSS 5.6v7.0v7.1+3 more2018-06-21
CVE-2018-3665 [MEDIUM] CWE-200 CVE-2018-3665: System software utilizing Lazy FP state restore technique on systems using Intel Core-based micropro System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.
nvd
CVE-2017-5573P4MEDIUMCVSS 4.9v6.0.2v6.2.0+2 more2017-01-30
CVE-2017-5573 [MEDIUM] CVE-2017-5573: An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated r An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated read-only administrator can cancel tasks of other administrators.
nvd
CVE-2024-5661P4MEDIUMCVSS 6.0v8.0≥ 8, ≤ 0+1 more2024-06-13
CVE-2024-5661 [MEDIUM] CVE-2024-5661: An issue has been identified in both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR which may allow An issue has been identified in both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR which may allow a malicious administrator of a guest VM to cause the host to become slow and/or unresponsive.
nvd
CVE-2018-19965P4MEDIUMCVSS 5.6v7.0v7.1+2 more2018-12-08
CVE-2018-19965 [MEDIUM] CVE-2018-19965: An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorrect CVE-2017-5754 (aka Meltdown) mitigation.
nvd
CVE-2016-6259P4MEDIUMCVSS 6.2v6.0v6.0.2+4 more2016-08-02
CVE-2016-6259 [MEDIUM] CWE-20 CVE-2016-6259: Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32 Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety check.
nvd
CVE-2012-3495P4MEDIUMCVSS 6.1≤ 6.0.2v5.0+3 more2012-11-23
CVE-2012-3495 [MEDIUM] CWE-20 CVE-2012-3495: The physdev_get_free_pirq hypercall in arch/x86/physdev.c in Xen 4.1.x and Citrix XenServer 6.0.2 an The physdev_get_free_pirq hypercall in arch/x86/physdev.c in Xen 4.1.x and Citrix XenServer 6.0.2 and earlier uses the return value of the get_free_pirq function as an array index without checking that the return value indicates an error, which allows guest OS users to cause a denial of service (invalid memory write and host crash) and possibly gain pr
nvd
CVE-2016-9385P4MEDIUMCVSS 6.0v6.0.2v6.2.0+2 more2017-01-23
CVE-2016-9385 [MEDIUM] CWE-20 CVE-2016-9385: The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV gu The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of service (host crash) by leveraging lack of canonical address checks.
nvd
CVE-2016-10024P4MEDIUMCVSS 6.0v6.0.2v6.2.0+2 more2017-01-26
CVE-2016-10024 [MEDIUM] CWE-20 CVE-2016-10024: Xen through 4.8.x allows local x86 PV guest OS kernel administrators to cause a denial of service (h Xen through 4.8.x allows local x86 PV guest OS kernel administrators to cause a denial of service (host hang or crash) by modifying the instruction stream asynchronously while performing certain kernel operations.
nvd
Citrix Xenserver vulnerabilities | cvebase