cbcvebase.

Oracle Vm Server vulnerabilities

38 known vulnerabilities affecting oracle/vm_server.

Total CVEs
38
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH13MEDIUM19LOW3

Vulnerabilities

Page 2 of 2
CVE-2016-4962P4MEDIUMCVSS 6.7v3.3v3.42016-06-07
CVE-2016-4962 [MEDIUM] CWE-264 CVE-2016-4962: The libxl device-handling in Xen 4.6.x and earlier allows local OS guest administrators to cause a d The libxl device-handling in Xen 4.6.x and earlier allows local OS guest administrators to cause a denial of service (resource consumption or management facility confusion) or gain host OS privileges by manipulating information in guest controlled areas of xenstore.
nvd
CVE-2013-0791P4MEDIUMCVSS 5.0v3.22013-04-03
CVE-2013-0791 [MEDIUM] CWE-119 CVE-2013-0791: The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla F The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption)
nvd
CVE-2014-1491P4MEDIUMCVSS 4.3v3.22014-02-06
CVE-2014-1491 [MEDIUM] CWE-326 CVE-2014-1491: Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firef Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanis
nvd
CVE-2013-1620P4MEDIUMCVSS 4.3v3.22013-02-08
CVE-2013-1620 [MEDIUM] CVE-2013-1620: The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets,
nvd
CVE-2016-2270P4MEDIUMCVSS 6.8v3.42016-02-19
CVE-2016-2270 [MEDIUM] CWE-20 CVE-2016-2270: Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) v Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.
nvd
CVE-2015-0452P4MEDIUMCVSS 4.3v3.1v3.22015-04-16
CVE-2015-0452 [MEDIUM] CVE-2015-0452: Unspecified vulnerability in the Oracle VM Server for SPARC component in Oracle Sun Systems Products Unspecified vulnerability in the Oracle VM Server for SPARC component in Oracle Sun Systems Products Suite 3.1 and 3.2 allows remote attackers to affect confidentiality via unknown vectors related to Ldom Manager.
nvd
CVE-2015-2730P4MEDIUMCVSS 4.3v3.22015-07-06
CVE-2015-2730 [MEDIUM] CWE-310 CVE-2015-2730: Mozilla Network Security Services (NSS) before 3.19.1, as used in Mozilla Firefox before 39.0, Firef Mozilla Network Security Services (NSS) before 3.19.1, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and other products, does not properly perform Elliptical Curve Cryptography (ECC) multiplications, which makes it easier for remote attackers to spoof ECDSA signatures via unspecified vectors.
nvd
CVE-2015-2721P4MEDIUMCVSS 4.3v3.22015-07-06
CVE-2015-2721 [MEDIUM] CWE-310 CVE-2015-2721: Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS state machine, which allows man-in-the-middle attackers to defeat cryptographic protection mechanisms by b
nvd
CVE-2017-3242P4MEDIUMCVSS 5.9v3.2v3.42017-01-27
CVE-2017-3242 [MEDIUM] CWE-20 CVE-2017-3242: Vulnerability in the Oracle VM Server for Sparc component of Oracle Sun Systems Products Suite (subc Vulnerability in the Oracle VM Server for Sparc component of Oracle Sun Systems Products Suite (subcomponent: LDOM Manager). Supported versions that are affected are 3.2 and 3.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM Server for Sparc executes to compromise Oracle VM Server for S
nvd
CVE-2016-5403P4MEDIUMCVSS 5.5v3.42016-08-02
CVE-2016-5403 [MEDIUM] CWE-400 CVE-2016-5403: The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cau The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.
nvd
CVE-2023-22024P4MEDIUMCVSS 5.5v3.02023-09-20
CVE-2023-22024 [MEDIUM] CVE-2023-22024: In the Unbreakable Enterprise Kernel (UEK), the RDS module in UEK has two setsockopt(2) options, RDS In the Unbreakable Enterprise Kernel (UEK), the RDS module in UEK has two setsockopt(2) options, RDS_CONN_RESET and RDS6_CONN_RESET, that are not re-entrant. A malicious local user with CAP_NET_ADMIN can use this to crash the kernel. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
nvd
CVE-2016-6197P4MEDIUMCVSS 5.5v3.42016-08-06
CVE-2016-6197 [MEDIUM] CWE-20 CVE-2016-6197: fs/overlayfs/dir.c in the OverlayFS filesystem implementation in the Linux kernel before 4.6 does no fs/overlayfs/dir.c in the OverlayFS filesystem implementation in the Linux kernel before 4.6 does not properly verify the upper dentry before proceeding with unlink and rename system-call processing, which allows local users to cause a denial of service (system crash) via a rename system call that specifies a self-hardlink.
nvd
CVE-2016-6198P4MEDIUMCVSS 5.5v3.42016-08-06
CVE-2016-6198 [MEDIUM] CWE-284 CVE-2016-6198: The filesystem layer in the Linux kernel before 4.5.5 proceeds with post-rename operations after an The filesystem layer in the Linux kernel before 4.5.5 proceeds with post-rename operations after an OverlayFS file is renamed to a self-hardlink, which allows local users to cause a denial of service (system crash) via a rename system call, related to fs/namei.c and fs/open.c.
nvd
CVE-2016-4470P4MEDIUMCVSS 5.5v3.3v3.42016-06-27
CVE-2016-4470 [MEDIUM] CVE-2016-4470: The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not e The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command.
nvd
CVE-2016-3712P4MEDIUMCVSS 5.5v3.3v3.42016-05-11
CVE-2016-3712 [MEDIUM] CWE-190 CVE-2016-3712: Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.
nvd
CVE-2016-3158P4LOWCVSS 3.8v3.3v3.42016-04-13
CVE-2016-3158 [LOW] CVE-2016-3158: The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-201
nvd
CVE-2016-3159P4LOWCVSS 3.8v3.3v3.42016-04-13
CVE-2016-3159 [LOW] CVE-2016-3159: The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardwa The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE
nvd
CVE-2020-2571P4LOWCVSS 3.3v3.62020-01-15
CVE-2020-2571 [LOW] CVE-2020-2571: Vulnerability in the Oracle VM Server for SPARC product of Oracle Systems (component: Templates). Th Vulnerability in the Oracle VM Server for SPARC product of Oracle Systems (component: Templates). The supported version that is affected is 3.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM Server for SPARC executes to compromise Oracle VM Server for SPARC. Successful attacks require human inte
nvd
Oracle Vm Server vulnerabilities | cvebase