cbcvebase.

Debian Xen vulnerabilities

444 known vulnerabilities affecting debian/xen.

Total CVEs
444
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH137MEDIUM226LOW63

Vulnerabilities

Page 22 of 23
CVE-2015-2152P4LOWCVSS 1.9fixed in xen 4.4.1-9 (bookworm)2015
CVE-2015-2152 [LOW] CVE-2015-2152: xen - Xen 4.5.x and earlier enables certain default backends when emulating a VGA devi... Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access to the VGA console by (1) setting the DISPLAY environment variable, when compiled with SDL support, or connecting to the VNC server on (2) ::1 or (3) 127.0.0.1, when not compi
debian
CVE-2013-1917P4LOWCVSS 1.9fixed in xen 4.1.4-3 (bookworm)2013
CVE-2013-1917 [LOW] CVE-2013-1917: xen - Xen 3.1 through 4.x, when running 64-bit hosts on Intel CPUs, does not clear the... Xen 3.1 through 4.x, when running 64-bit hosts on Intel CPUs, does not clear the NT flag when using an IRET after a SYSENTER instruction, which allows PV guest users to cause a denial of service (hypervisor crash) by triggering a #GP fault, which is not properly handled by another IRET instruction. Scope: local bookworm: resolved (fixed in 4.1.4-3) bullseye: resolved (fixe
debian
CVE-2012-5512P4LOWCVSS 3.2fixed in xen 4.1.3-5 (bookworm)2012
CVE-2012-5512 [LOW] CVE-2012-5512: xen - Array index error in the HVMOP_set_mem_access handler in Xen 4.1 allows local HV... Array index error in the HVMOP_set_mem_access handler in Xen 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) or obtain sensitive information via unspecified vectors. Scope: local bookworm: resolved (fixed in 4.1.3-5) bullseye: resolved (fixed in 4.1.3-5) forky: resolved (fixed in 4.1.3-5) sid: resolved (fixed in 4.1.3-5) trixie: resolved (
debian
CVE-2020-29480P4LOWCVSS 2.3fixed in xen 4.14.0+88-g1d1d1f5391-1 (bookworm)2020
CVE-2020-29480 [LOW] CVE-2020-29480: xen - An issue was discovered in Xen through 4.14.x. Neither xenstore implementation d... An issue was discovered in Xen through 4.14.x. Neither xenstore implementation does any permission checks when reporting a xenstore watch event. A guest administrator can watch the root xenstored node, which will cause notifications for every created, modified, and deleted key. A guest administrator can also use the special watches, which will cause a notification every
debian
CVE-2012-3494P4LOWCVSS 2.1fixed in xen 4.1.3-2 (bookworm)2012
CVE-2012-3494 [LOW] CVE-2012-3494: xen - The set_debugreg hypercall in include/asm-x86/debugreg.h in Xen 4.0, 4.1, and 4.... The set_debugreg hypercall in include/asm-x86/debugreg.h in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when running on x86-64 systems, allows local OS guest users to cause a denial of service (host crash) by writing to the reserved bits of the DR7 debug control register. Scope: local bookworm: resolved (fixed in 4.1.3-2) bullseye: resolved (fixed in 4.1
debian
CVE-2012-4537P4LOWCVSS 2.1fixed in xen 4.1.3-4 (bookworm)2012
CVE-2012-4537 [LOW] CVE-2012-4537: xen - Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchroniz... Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchronize the p2m and m2p tables when the set_p2m_entry function fails, which allows local HVM guest OS administrators to cause a denial of service (memory consumption and assertion failure), aka "Memory mapping failure DoS vulnerability." Scope: local bookworm: resolved (fixed in 4.1.3-4) bullseye: re
debian
CVE-2015-7971P4LOWCVSS 2.1fixed in xen 4.6.0-1 (bookworm)2015
CVE-2015-7971 [LOW] CVE-2015-7971: xen - Xen 3.2.x through 4.6.x does not limit the number of printk console messages whe... Xen 3.2.x through 4.6.x does not limit the number of printk console messages when logging certain pmu and profiling hypercalls, which allows local guests to cause a denial of service via a sequence of crafted (1) HYPERCALL_xenoprof_op hypercalls, which are not properly handled in the do_xenoprof_op function in common/xenoprof.c, or (2) HYPERVISOR_xenpmu_op hypercalls, whic
debian
CVE-2015-7972P4LOWCVSS 2.1fixed in xen 4.6.0-1 (bookworm)2015
CVE-2015-7972 [LOW] CVE-2015-7972: xen - The (1) libxl_set_memory_target function in tools/libxl/libxl.c and (2) libxl__b... The (1) libxl_set_memory_target function in tools/libxl/libxl.c and (2) libxl__build_post function in tools/libxl/libxl_dom.c in Xen 3.4.x through 4.6.x do not properly calculate the balloon size when using the populate-on-demand (PoD) system, which allows local HVM guest users to cause a denial of service (guest crash) via unspecified vectors related to "heavy memory pres
debian
CVE-2012-4544P4LOWCVSS 2.1fixed in xen 4.1.3-4 (bookworm)2012
CVE-2012-4544 [LOW] CVE-2012-4544: xen - The PV domain builder in Xen 4.2 and earlier does not validate the size of the k... The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk. Scope: local bookworm: resolved (fixed in 4.1.3-4) bullseye: resolved (fixed in 4.1.3-4) forky: res
debian
CVE-2013-1952P4LOWCVSS 1.9fixed in xen 4.1.4-4 (bookworm)2013
CVE-2013-1952 [LOW] CVE-2013-1952: xen - Xen 4.x, when using Intel VT-d for a bus mastering capable PCI device, does not ... Xen 4.x, when using Intel VT-d for a bus mastering capable PCI device, does not properly check the source when accessing a bridge device's interrupt remapping table entries for MSI interrupts, which allows local guest domains to cause a denial of service (interrupt injection) via unspecified vectors. Scope: local bookworm: resolved (fixed in 4.1.4-4) bullseye: resolved (fi
debian
CVE-2012-0218P4LOWCVSS 1.9fixed in xen 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 (bookworm)2012
CVE-2012-0218 [LOW] CVE-2012-0218: xen - Xen 3.4, 4.0, and 4.1, when the guest OS has not registered a handler for a sysc... Xen 3.4, 4.0, and 4.1, when the guest OS has not registered a handler for a syscall or sysenter instruction, does not properly clear a flag for exception injection when injecting a General Protection Fault, which allows local PV guest OS users to cause a denial of service (guest crash) by later triggering an exception that would normally be handled within Xen. Scope: local
debian
CVE-2012-4535P4LOWCVSS 1.9fixed in xen 4.1.3-4 (bookworm)2012
CVE-2012-4535 [LOW] CVE-2012-4535: xen - Xen 3.4 through 4.2, and possibly earlier versions, allows local guest OS admini... Xen 3.4 through 4.2, and possibly earlier versions, allows local guest OS administrators to cause a denial of service (Xen infinite loop and physical CPU consumption) by setting a VCPU with an "inappropriate deadline." Scope: local bookworm: resolved (fixed in 4.1.3-4) bullseye: resolved (fixed in 4.1.3-4) forky: resolved (fixed in 4.1.3-4) sid: resolved (fixed in 4.1.3-4)
debian
CVE-2013-4368P4LOWCVSS 1.9fixed in xen 4.4.0-1 (bookworm)2013
CVE-2013-4368 [LOW] CVE-2013-4368: xen - The outs instruction emulation in Xen 3.1.x, 4.2.x, 4.3.x, and earlier, when usi... The outs instruction emulation in Xen 3.1.x, 4.2.x, 4.3.x, and earlier, when using FS: or GS: segment override, uses an uninitialized variable as a segment base, which allows local 64-bit PV guests to obtain sensitive information (hypervisor stack content) via unspecified vectors related to stale data in a segment register. Scope: local bookworm: resolved (fixed in 4.4.0-1
debian
CVE-2013-1442P4LOWCVSS 1.2fixed in xen 4.4.0-1 (bookworm)2013
CVE-2013-1442 [LOW] CVE-2013-1442: xen - Xen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly cle... Xen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly clear previous data from registers when using an XSAVE or XRSTOR to extend the state components of a saved or restored vCPU after touching other restored extended registers, which allows local guest OSes to obtain sensitive information by reading the registers. Scope: local bookworm: resolved (fix
debian
CVE-2014-4021P4LOWCVSS 2.7fixed in xen 4.4.1-1 (bookworm)2014
CVE-2014-4021 [LOW] CVE-2014-4021: xen - Xen 3.2.x through 4.4.x does not properly clean memory pages recovered from gues... Xen 3.2.x through 4.4.x does not properly clean memory pages recovered from guests, which allows local guest OS users to obtain sensitive information via unspecified vectors. Scope: local bookworm: resolved (fixed in 4.4.1-1) bullseye: resolved (fixed in 4.4.1-1) forky: resolved (fixed in 4.4.1-1) sid: resolved (fixed in 4.4.1-1) trixie: resolved (fixed in 4.4.1-1)
debian
CVE-2013-4375P4LOWCVSS 2.7fixed in qemu 1.7.0+dfsg-1 (bookworm)2013
CVE-2013-4375 [LOW] CVE-2013-4375: qemu - The qdisk PV disk backend in qemu-xen in Xen 4.2.x and 4.3.x before 4.3.1, and q... The qdisk PV disk backend in qemu-xen in Xen 4.2.x and 4.3.x before 4.3.1, and qemu 1.1 and other versions, allows local HVM guests to cause a denial of service (domain grant reference consumption) via unspecified vectors. Scope: local bookworm: resolved (fixed in 1.7.0+dfsg-1) bullseye: resolved (fixed in 1.7.0+dfsg-1) forky: resolved (fixed in 1.7.0+dfsg-1) sid: resolve
debian
CVE-2015-7813P4LOWCVSS 2.1fixed in xen 4.6.0-1 (bookworm)2015
CVE-2015-7813 [LOW] CVE-2015-7813: xen - Xen 4.4.x, 4.5.x, and 4.6.x does not limit the number of printk console messages... Xen 4.4.x, 4.5.x, and 4.6.x does not limit the number of printk console messages when reporting unimplemented hypercalls, which allows local guests to cause a denial of service via a sequence of (1) HYPERVISOR_physdev_op hypercalls, which are not properly handled in the do_physdev_op function in arch/arm/physdev.c, or (2) HYPERVISOR_hvm_op hypercalls, which are not properl
debian
CVE-2013-4369P4LOWCVSS 1.9fixed in xen 4.4.0-1 (bookworm)2013
CVE-2013-4369 [LOW] CVE-2013-4369: xen - The xlu_vif_parse_rate function in the libxlu library in Xen 4.2.x and 4.3.x all... The xlu_vif_parse_rate function in the libxlu library in Xen 4.2.x and 4.3.x allows local users to cause a denial of service (NULL pointer dereference) by using the "@" character as the VIF rate configuration. Scope: local bookworm: resolved (fixed in 4.4.0-1) bullseye: resolved (fixed in 4.4.0-1) forky: resolved (fixed in 4.4.0-1) sid: resolved (fixed in 4.4.0-1) trixie:
debian
CVE-2012-4539P4LOWCVSS 2.1fixed in xen 4.1.3-4 (bookworm)2012
CVE-2012-4539 [LOW] CVE-2012-4539: xen - Xen 4.0 through 4.2, when running 32-bit x86 PV guests on 64-bit hypervisors, al... Xen 4.0 through 4.2, when running 32-bit x86 PV guests on 64-bit hypervisors, allows local guest OS administrators to cause a denial of service (infinite loop and hang or crash) via invalid arguments to GNTTABOP_get_status_frames, aka "Grant table hypercall infinite loop DoS vulnerability." Scope: local bookworm: resolved (fixed in 4.1.3-4) bullseye: resolved (fixed in 4.1
debian
CVE-2015-2044P4LOWCVSS 2.1fixed in xen 4.4.1-8 (bookworm)2015
CVE-2015-2044 [LOW] CVE-2015-2044: xen - The emulation routines for unspecified X86 devices in Xen 3.2.x through 4.5.x do... The emulation routines for unspecified X86 devices in Xen 3.2.x through 4.5.x does not properly initialize data, which allow local HVM guest users to obtain sensitive information via vectors involving an unsupported access size. Scope: local bookworm: resolved (fixed in 4.4.1-8) bullseye: resolved (fixed in 4.4.1-8) forky: resolved (fixed in 4.4.1-8) sid: resolved (fixed i
debian
Debian Xen vulnerabilities | cvebase