Vulnerabilities > Citrix > XEN > Medium

DATE CVE VULNERABILITY TITLE RISK
2011-08-12 CVE-2011-1583 Numeric Errors vulnerability in Citrix XEN
Multiple integer overflows in tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allow local users to cause a denial of service and possibly execute arbitrary code via a crafted paravirtualised guest kernel image that triggers (1) a buffer overflow during a decompression loop or (2) an out-of-bounds read in the loader involving unspecified length fields.
local
citrix CWE-189
6.9
2011-01-25 CVE-2010-4255 Unspecified vulnerability in Citrix XEN
The fixup_page_fault function in arch/x86/traps.c in Xen 4.0.1 and earlier on 64-bit platforms, when paravirtualization is enabled, does not verify that kernel mode is used to call the handle_gdt_ldt_mapping_fault function, which allows guest OS users to cause a denial of service (host OS BUG_ON) via a crafted memory access.
low complexity
citrix
6.1