Skip to main content

Vendor archive

xen CVEs

Beta · best-effort

495 CVEs tagged to vendor xen15 Critical, 162 High, 267 Medium, 51 Low, 0 Unrated.

CVE-2017-8904

Published May 11, 2017

Xen through 4.8.x mishandles the "contains segment descriptors" property during GNTTABOP_transfer (aka guest transfer) operations, which might allow PV guest OS users to execute a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8903

Published May 11, 2017

Xen through 4.8.x on 64-bit platforms mishandles page tables after an IRET hypercall, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-213.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7228

Published Apr 4, 2017

An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The earlier XSA-29 fix introduced an insufficient check on XENME…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9818

Published Feb 27, 2017

Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving an asynchronous abort while at HYP.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9817

Published Feb 27, 2017

Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving a (1) data or (2) prefetch abort with the ESR_EL2.EA bit set.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9816

Published Feb 27, 2017

Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving an asynchronous abort while at EL2.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9815

Published Feb 27, 2017

Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host panic) by sending an asynchronous abort.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9384

Published Feb 22, 2017

Xen 4.7 allows local guest OS users to obtain sensitive host information by loading a 32-bit ELF symbol table.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9378

Published Feb 22, 2017

Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial o…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9377

Published Feb 22, 2017

Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial o…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9932

Published Jan 26, 2017

CMPXCHG8B emulation in Xen 3.3.x through 4.7.x on x86 systems allows local HVM guest OS users to obtain sensitive information from host stack memory via a "supposedly-ignored" ope…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-10025

Published Jan 26, 2017

VMFUNC emulation in Xen 4.6.x through 4.8.x on x86 systems using AMD virtualization extensions (aka SVM) allows local HVM guest OS users to cause a denial of service (hypervisor c…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10024

Published Jan 26, 2017

Xen through 4.8.x allows local x86 PV guest OS kernel administrators to cause a denial of service (host hang or crash) by modifying the instruction stream asynchronously while per…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10013

Published Jan 26, 2017

Xen through 4.8.x allows local 64-bit x86 HVM guest OS users to gain privileges by leveraging mishandling of SYSCALL singlestep during emulation.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9386

Published Jan 23, 2017

The x86 emulator in Xen does not properly treat x86 NULL segments as unusable when accessing memory, which might allow local HVM guest users to gain privileges via vectors involvi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9385

Published Jan 23, 2017

The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of service (host crash) by leveraging l…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9383

Published Jan 23, 2017

Xen, when running on a 64-bit hypervisor, allows local x86 guest OS users to modify arbitrary memory and consequently obtain sensitive information, cause a denial of service (host…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9382

Published Jan 23, 2017

Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM guest OS users to gain privileges or cause a denial of service (guest OS crash)…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9380

Published Jan 23, 2017

The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the h…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9379

Published Jan 23, 2017

The pygrub boot loader emulator in Xen, when S-expression output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the ho…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7777

Published Oct 7, 2016

Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7154

Published Sep 21, 2016

Use-after-free vulnerability in the FIFO event channel code in Xen 4.4.x allows local guest OS administrators to cause a denial of service (host crash) and possibly execute arbitr…

CVSS 6.7 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2016-7094

Published Sep 21, 2016

Buffer overflow in Xen 4.7.x and earlier allows local x86 HVM guest OS administrators on guests running with shadow paging to cause a denial of service via a pagetable update.

CVSS 4.1 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2016-7093

Published Sep 21, 2016

Xen 4.5.3, 4.6.3, and 4.7.x allow local HVM guest OS administrators to overwrite hypervisor memory and consequently gain host OS privileges by leveraging mishandling of instructio…

CVSS 8.2 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort
Showing 276-300 of 495 CVEsPage 12 of 20