Vulnerabilities > Citrix > XEN > High

DATE CVE VULNERABILITY TITLE RISK
2011-08-12 CVE-2011-1898 Permissions, Privileges, and Access Controls vulnerability in Citrix XEN 4.0.0/4.0.1/4.1.0
Xen 4.1 before 4.1.1 and 4.0 before 4.0.2, when using PCI passthrough on Intel VT-d chipsets that do not have interrupt remapping, allows guest OS users to gain host OS privileges by "using DMA to generate MSI interrupts by writing to the interrupt injection registers."
7.4
2008-12-24 CVE-2008-5716 Permissions, Privileges, and Access Controls vulnerability in Citrix XEN 3.3.0
xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid.
local
low complexity
citrix CWE-264
7.2
2008-10-03 CVE-2008-4405 Permissions, Privileges, and Access Controls vulnerability in Citrix XEN 3.0.3
xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM's write access within this tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid.
local
low complexity
citrix CWE-264
7.2