Citrix Xenserver vulnerabilities
50 known vulnerabilities affecting citrix/xenserver.
Total CVEs
50
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH20MEDIUM20LOW3
Vulnerabilities
Page 3 of 3
CVE-2012-3498P4MEDIUMCVSS 5.6≤ 6.0.22012-11-23
CVE-2012-3498 [MEDIUM] CWE-20 CVE-2012-3498: PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest
PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause a denial of service (host crash) and possibly read hypervisor or guest memory via vectors related to a missing range check of map->index.
nvd
CVE-2016-3712P4MEDIUMCVSS 5.5≤ 7.02016-05-11
CVE-2016-3712 [MEDIUM] CWE-190 CVE-2016-3712: Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service
Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.
nvd
CVE-2016-10025P4MEDIUMCVSS 5.5v6.0.2v6.2.0+2 more2017-01-26
CVE-2016-10025 [MEDIUM] CWE-476 CVE-2016-10025: VMFUNC emulation in Xen 4.6.x through 4.8.x on x86 systems using AMD virtualization extensions (aka
VMFUNC emulation in Xen 4.6.x through 4.8.x on x86 systems using AMD virtualization extensions (aka SVM) allows local HVM guest OS users to cause a denial of service (hypervisor crash) by leveraging a missing NULL pointer check.
nvd
CVE-2008-3253P4MEDIUMCVSS 4.3v4.1.02008-07-22
CVE-2008-3253 [MEDIUM] CWE-79 CVE-2008-3253: Cross-site scripting (XSS) vulnerability in the XenAPI HTTP interfaces in Citrix XenServer Express,
Cross-site scripting (XSS) vulnerability in the XenAPI HTTP interfaces in Citrix XenServer Express, Standard, and Enterprise Edition 4.1.0; Citrix XenServer Dell Edition (Express and Enterprise) 4.1.0; and HP integrated Citrix XenServer (Select and Enterprise) 4.1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2010-0633P4MEDIUMCVSS 4.6≤ 5.0v5.52010-02-12
CVE-2010-0633 [MEDIUM] CVE-2010-0633: Unspecified vulnerability in Citrix XenServer 5.0 Update 3 and earlier, and 5.5, allows local users
Unspecified vulnerability in Citrix XenServer 5.0 Update 3 and earlier, and 5.5, allows local users to bypass authentication and execute unspecified Xen API (XAPI) calls via unknown vectors.
nvd
CVE-2015-4106P4MEDIUMCVSS 4.6v6.0v6.0.2+3 more2015-06-03
CVE-2015-4106 [MEDIUM] CWE-863 CVE-2015-4106: QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through de
QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact via unknown vectors.
nvd
CVE-2012-3496P4MEDIUMCVSS 4.7≤ 6.0.22012-11-23
CVE-2012-3496 [MEDIUM] CWE-16 CVE-2012-3496: XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when trans
XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when translating paging mode is not used, allows local PV OS guest kernels to cause a denial of service (BUG triggered and host crash) via invalid flags such as MEMF_populate_on_demand.
nvd
CVE-2012-5512P4LOWCVSS 3.2v4.1.02012-12-13
CVE-2012-5512 [LOW] CWE-16 CVE-2012-5512: Array index error in the HVMOP_set_mem_access handler in Xen 4.1 allows local HVM guest OS administr
Array index error in the HVMOP_set_mem_access handler in Xen 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) or obtain sensitive information via unspecified vectors.
nvd
CVE-2012-3494P4LOWCVSS 2.1≤ 6.0.22012-11-23
CVE-2012-3494 [LOW] CWE-264 CVE-2012-3494: The set_debugreg hypercall in include/asm-x86/debugreg.h in Xen 4.0, 4.1, and 4.2, and Citrix XenSer
The set_debugreg hypercall in include/asm-x86/debugreg.h in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when running on x86-64 systems, allows local OS guest users to cause a denial of service (host crash) by writing to the reserved bits of the DR7 debug control register.
nvd
CVE-2010-2619P4LOWCVSS 1.9≤ 5.0≤ 5.52010-07-02
CVE-2010-2619 [LOW] CVE-2010-2619: Citrix XenServer 5.0 Update 2 and earlier, and 5.5 Update 1 and earlier, when using a pvops kernel,
Citrix XenServer 5.0 Update 2 and earlier, and 5.5 Update 1 and earlier, when using a pvops kernel, allows guest users to cause a denial of service in the host via unspecified vectors that trigger "incorrectly set flags."
nvd
← Previous3 / 3