cbcvebase.

Citrix Xenserver vulnerabilities

50 known vulnerabilities affecting citrix/xenserver.

Total CVEs
50
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH20MEDIUM20LOW3

Vulnerabilities

Page 3 of 3
CVE-2012-3498P4MEDIUMCVSS 5.6≤ 6.0.22012-11-23
CVE-2012-3498 [MEDIUM] CWE-20 CVE-2012-3498: PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause a denial of service (host crash) and possibly read hypervisor or guest memory via vectors related to a missing range check of map->index.
nvd
CVE-2016-3712P4MEDIUMCVSS 5.5≤ 7.02016-05-11
CVE-2016-3712 [MEDIUM] CWE-190 CVE-2016-3712: Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.
nvd
CVE-2016-10025P4MEDIUMCVSS 5.5v6.0.2v6.2.0+2 more2017-01-26
CVE-2016-10025 [MEDIUM] CWE-476 CVE-2016-10025: VMFUNC emulation in Xen 4.6.x through 4.8.x on x86 systems using AMD virtualization extensions (aka VMFUNC emulation in Xen 4.6.x through 4.8.x on x86 systems using AMD virtualization extensions (aka SVM) allows local HVM guest OS users to cause a denial of service (hypervisor crash) by leveraging a missing NULL pointer check.
nvd
CVE-2008-3253P4MEDIUMCVSS 4.3v4.1.02008-07-22
CVE-2008-3253 [MEDIUM] CWE-79 CVE-2008-3253: Cross-site scripting (XSS) vulnerability in the XenAPI HTTP interfaces in Citrix XenServer Express, Cross-site scripting (XSS) vulnerability in the XenAPI HTTP interfaces in Citrix XenServer Express, Standard, and Enterprise Edition 4.1.0; Citrix XenServer Dell Edition (Express and Enterprise) 4.1.0; and HP integrated Citrix XenServer (Select and Enterprise) 4.1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2010-0633P4MEDIUMCVSS 4.6≤ 5.0v5.52010-02-12
CVE-2010-0633 [MEDIUM] CVE-2010-0633: Unspecified vulnerability in Citrix XenServer 5.0 Update 3 and earlier, and 5.5, allows local users Unspecified vulnerability in Citrix XenServer 5.0 Update 3 and earlier, and 5.5, allows local users to bypass authentication and execute unspecified Xen API (XAPI) calls via unknown vectors.
nvd
CVE-2015-4106P4MEDIUMCVSS 4.6v6.0v6.0.2+3 more2015-06-03
CVE-2015-4106 [MEDIUM] CWE-863 CVE-2015-4106: QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through de QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact via unknown vectors.
nvd
CVE-2012-3496P4MEDIUMCVSS 4.7≤ 6.0.22012-11-23
CVE-2012-3496 [MEDIUM] CWE-16 CVE-2012-3496: XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when trans XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when translating paging mode is not used, allows local PV OS guest kernels to cause a denial of service (BUG triggered and host crash) via invalid flags such as MEMF_populate_on_demand.
nvd
CVE-2012-5512P4LOWCVSS 3.2v4.1.02012-12-13
CVE-2012-5512 [LOW] CWE-16 CVE-2012-5512: Array index error in the HVMOP_set_mem_access handler in Xen 4.1 allows local HVM guest OS administr Array index error in the HVMOP_set_mem_access handler in Xen 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) or obtain sensitive information via unspecified vectors.
nvd
CVE-2012-3494P4LOWCVSS 2.1≤ 6.0.22012-11-23
CVE-2012-3494 [LOW] CWE-264 CVE-2012-3494: The set_debugreg hypercall in include/asm-x86/debugreg.h in Xen 4.0, 4.1, and 4.2, and Citrix XenSer The set_debugreg hypercall in include/asm-x86/debugreg.h in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when running on x86-64 systems, allows local OS guest users to cause a denial of service (host crash) by writing to the reserved bits of the DR7 debug control register.
nvd
CVE-2010-2619P4LOWCVSS 1.9≤ 5.0≤ 5.52010-07-02
CVE-2010-2619 [LOW] CVE-2010-2619: Citrix XenServer 5.0 Update 2 and earlier, and 5.5 Update 1 and earlier, when using a pvops kernel, Citrix XenServer 5.0 Update 2 and earlier, and 5.5 Update 1 and earlier, when using a pvops kernel, allows guest users to cause a denial of service in the host via unspecified vectors that trigger "incorrectly set flags."
nvd
Citrix Xenserver vulnerabilities | cvebase