Skip to main content

Vendor/product archive

citrix / xenserver CVEs

Beta · best-effort

51 CVEs tagged to citrix / xenserver4 Critical, 20 High, 24 Medium, 3 Low, 0 Unrated.

CVE-2024-5661

Published Jun 13, 2024

An issue has been identified in both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR which may allow a malicious administrator of a guest VM to cause the host to become slow and/or…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4606

Published Jan 23, 2020

Citrix XenServer 4.1, 6.0, 5.6 SP2, 5.6 Feature Pack 1, 5.6 Common Criteria, 5.6, 5.5, 5.0, and 5.0 Update 3 contains a Local Privilege Escalation Vulnerability which could allow…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-3798

Published Jul 11, 2019

The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (guest OS crash) via a crafted Ethernet frame.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19965

Published Dec 8, 2018

An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9603

Published Jul 27, 2018

A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update…

CVSS 5.5 · Medium

CVE-2017-2620

Published Jul 27, 2018

Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data…

CVSS 5.5 · Medium

CVE-2017-2615

Published Jul 3, 2018

Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in…

CVSS 5.5 · Medium

CVE-2018-3665

Published Jun 21, 2018

System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another proces…

CVSS 5.6 · Medium
evidence mentions
7
Buzz score
28.8

CVE-2018-8897

Published May 8, 2018

A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-sy…

CVSS 7.8 · High
evidence mentions
3
Buzz score
20.4

CVE-2017-12134

Published Aug 24, 2017

The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streams and consequently obtain sensitive mem…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7705

Published Aug 7, 2017

The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2016-9637

Published Feb 17, 2017

The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS administrators to gain qemu process p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5573

Published Jan 30, 2017

An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated read-only administrator can cancel tasks of other administrators.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5572

Published Jan 30, 2017

An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated read-only administrator can corrupt the host database.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10025

Published Jan 26, 2017

VMFUNC emulation in Xen 4.6.x through 4.8.x on x86 systems using AMD virtualization extensions (aka SVM) allows local HVM guest OS users to cause a denial of service (hypervisor c…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10024

Published Jan 26, 2017

Xen through 4.8.x allows local x86 PV guest OS kernel administrators to cause a denial of service (host hang or crash) by modifying the instruction stream asynchronously while per…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9386

Published Jan 23, 2017

The x86 emulator in Xen does not properly treat x86 NULL segments as unusable when accessing memory, which might allow local HVM guest users to gain privileges via vectors involvi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 51 CVEsPage 1 of 3