cbcvebase.

Debian Xen vulnerabilities

444 known vulnerabilities affecting debian/xen.

Total CVEs
444
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH137MEDIUM226LOW63

Vulnerabilities

Page 1 of 23
CVE-2018-3639P1MEDIUMCVSS 5.5ExploitedPoCRansomwarefixed in intel-microcode 3.20180703.1 (bookworm)2018
CVE-2018-3639 [MEDIUM] CVE-2018-3639: intel-microcode - Systems with microprocessors utilizing speculative execution and speculative exe... Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4. Scope: local bookworm: resolved (fix
debian
CVE-2017-5715P2MEDIUMCVSS 5.6PoCfixed in amd64-microcode 3.20180515.1 (bookworm)2017
CVE-2017-5715 [MEDIUM] CVE-2017-5715: amd64-microcode - Systems with microprocessors utilizing speculative execution and indirect branch... Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. Scope: local bookworm: resolved (fixed in 3.20180515.1) bullseye: resolved (fixed in 3.20180515.1) forky: resolved (fixed in 3.20180515.1) sid: resolved
debian
CVE-2018-8897P2HIGHCVSS 7.8PoCfixed in linux 4.15.17-1 (bookworm)2018
CVE-2018-8897 [HIGH] CVE-2018-8897: linux - A statement in the System Programming Guide of the Intel 64 and IA-32 Architectu... A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferred by MOV SS or POP SS, as demonstrated by (for example) privilege escalation in Windows, macOS, some Xen config
debian
CVE-2012-0217P3HIGHCVSS 7.2PoCfixed in xen 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 (bookworm)2012
CVE-2012-0217 [HIGH] CVE-2012-0217: xen - The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in... The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly
debian
CVE-2015-3456P3HIGHCVSS 7.7PoCfixed in qemu 1:2.3+dfsg-3 (bookworm)2015
CVE-2015-3456 [HIGH] CVE-2015-3456: qemu - The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and K... The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM. Scope: local bookworm: resolved (fixed in 1:2.3+dfsg
debian
CVE-2017-15595P3HIGHCVSS 8.8PoCfixed in xen 4.8.2+xsa245-0+deb9u1 (bookworm)2017
CVE-2017-15595 [HIGH] CVE-2017-15595: xen - An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to c... An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to cause a denial of service (unbounded recursion, stack consumption, and hypervisor crash) or possibly gain privileges via crafted page-table stacking. Scope: local bookworm: resolved (fixed in 4.8.2+xsa245-0+deb9u1) bullseye: resolved (fixed in 4.8.2+xsa245-0+deb9u1) forky: resolved (fixed in
debian
CVE-2017-5754P3MEDIUMCVSS 5.6fixed in linux 4.14.12-1 (bookworm)2017
CVE-2017-5754 [MEDIUM] CVE-2017-5754: linux - Systems with microprocessors utilizing speculative execution and indirect branch... Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache. Scope: local bookworm: resolved (fixed in 4.14.12-1) bullseye: resolved (fixed in 4.14.12-1) forky: resolved (fixed in 4.14.12-1) sid: resolved
debian
CVE-2017-7228P3HIGHCVSS 8.2PoCfixed in xen 4.8.1-1 (bookworm)2017
CVE-2017-7228 [HIGH] CVE-2017-7228: xen - An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.... An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The earlier XSA-29 fix introduced an insufficient check on XENMEM_exchange input, allowing the caller to drive hypervisor memory accesses outside of the guest provided input/output arrays. Scope: local bookworm: resolved (fixed in 4.8.1-1) bullseye: resolved
debian
CVE-2017-2620P2MEDIUMCVSS 5.5fixed in qemu 1:2.8+dfsg-3 (bookworm)2017
CVE-2017-2620 [MEDIUM] CVE-2017-2620: qemu - Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator su... Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process. Sco
debian
CVE-2016-9603P3MEDIUMCVSS 5.5fixed in qemu 1:2.8+dfsg-4 (bookworm)2016
CVE-2016-9603 [MEDIUM] CVE-2016-9603: qemu - A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's ... A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU process or, potentially, execute arbitrary code on the
debian
CVE-2015-3214P3LOWCVSS 6.9PoCfixed in qemu 1:2.4+dfsg-1a (bookworm)2015
CVE-2015-3214 [MEDIUM] CVE-2015-3214: linux - The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before... The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2024-31142P3HIGHCVSS 7.5fixed in xen 4.17.5+23-ga4e5191dc0-1 (bookworm)2024
CVE-2024-31142 [HIGH] CVE-2024-31142: xen - Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is... Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Speculative Return Stack Overflow) uses the same infrastructure, so is equally impacted. For more details, see: https://xenbits.xen.org/xsa/advisory-407.html https://xenbits.xen.org/xsa/advisory-434.html Scope: local bookworm: re
debian
CVE-2018-12892P3CRITICALCVSS 9.9fixed in xen 4.8.3+xsa267+shim4.10.1+xsa267-1+deb9u9 (bookworm)2018
CVE-2018-12892 [CRITICAL] CVE-2018-12892: xen - An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the reado... An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI disk, due to what was probably an erroneous merge conflict resolution. Malicious guest administrators or (in some situations) users may be able to write to supposedly read-only disk images. Only emulated SCSI disks (specified as "sd" in the libxl d
debian
CVE-2017-10918P3CRITICALCVSS 10.0fixed in xen 4.8.1-1+deb9u3 (bookworm)2017
CVE-2017-10918 [CRITICAL] CVE-2017-10918: xen - Xen through 4.8.x does not validate memory allocations during certain P2M operat... Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access, aka XSA-222. Scope: local bookworm: resolved (fixed in 4.8.1-1+deb9u3) bullseye: resolved (fixed in 4.8.1-1+deb9u3) forky: resolved (fixed in 4.8.1-1+deb9u3) sid: resolved (fixed in 4.8.1-1+deb9u3) trixie: resolved (f
debian
CVE-2017-10912P3CRITICALCVSS 10.0fixed in xen 4.8.1-1+deb9u3 (bookworm)2017
CVE-2017-10912 [CRITICAL] CVE-2017-10912: xen - Xen through 4.8.x mishandles page transfer, which allows guest OS users to obtai... Xen through 4.8.x mishandles page transfer, which allows guest OS users to obtain privileged host OS access, aka XSA-217. Scope: local bookworm: resolved (fixed in 4.8.1-1+deb9u3) bullseye: resolved (fixed in 4.8.1-1+deb9u3) forky: resolved (fixed in 4.8.1-1+deb9u3) sid: resolved (fixed in 4.8.1-1+deb9u3) trixie: resolved (fixed in 4.8.1-1+deb9u3)
debian
CVE-2015-5165P3CRITICALCVSS 9.3fixed in qemu 1:2.4+dfsg-1a (bookworm)2015
CVE-2015-5165 [CRITICAL] CVE-2015-5165: qemu - The C+ mode offload emulation in the RTL8139 network card device model in QEMU, ... The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors. Scope: local bookworm: resolved (fixed in 1:2.4+dfsg-1a) bullseye: resolved (fixed in 1:2.4+dfsg-1a) forky: resolved (fixed in 1:2.4+dfsg-1a) sid: resolved (fixed in 1:2.4+dfsg-1
debian
CVE-2015-3209P3HIGHCVSS 7.5fixed in qemu 1:2.3+dfsg-6 (bookworm)2015
CVE-2015-3209 [HIGH] CVE-2015-3209: qemu - Heap-based buffer overflow in the PCNET controller in QEMU allows remote attacke... Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set. Scope: local bookworm: resolved (fixed in 1:2.3+dfsg-6) bullseye: resolved (fixed in 1:2.3+dfsg-6) forky: resolved (fixed in 1:2.3+dfsg-6) sid: resolved (fixe
debian
CVE-2019-18425P3CRITICALCVSS 9.8fixed in xen 4.11.3+24-g14b62ab3e5-1 (bookworm)2019
CVE-2019-18425 [CRITICAL] CVE-2019-18425: xen - An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users ... An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. There is missing descriptor table limit checking in x86 PV emulation. When emulating certain PV guest operations, descriptor table accesses are performed by the emulating code. Such accesses should respect the guest specifi
debian
CVE-2015-8104P3CRITICALCVSS 10.0fixed in linux 4.2.6-2 (bookworm)2015
CVE-2015-8104 [CRITICAL] CVE-2015-8104: linux - The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x... The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c. Scope: local bookworm: resolved (fixed in 4.2.6-2) bullseye: resolved (fixed in 4.2.6-2) forky: resolved (fixed in 4.2.6-2) sid: resolved (fixed i
debian
CVE-2017-10920P3CRITICALCVSS 10.0fixed in xen 4.8.1-1+deb9u3 (bookworm)2017
CVE-2017-10920 [CRITICAL] CVE-2017-10920: xen - The grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and ... The grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed by only a GNTMAP_host_map unmapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 1. Scope: local bookworm: resolved (fixed in 4.8.1-1+deb9u
debian
1 / 23Next →
Debian Xen vulnerabilities | cvebase