Vulnerabilities > Citrix > Xenserver > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-06-13 CVE-2024-5661 Unspecified vulnerability in Citrix Hypervisor and Xenserver
An issue has been identified in both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR which may allow a malicious administrator of a guest VM to cause the host to become slow and/or unresponsive.
local
low complexity
citrix
6.0
2019-07-11 CVE-2014-3798 Improper Input Validation vulnerability in Citrix Xenserver
The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (guest OS crash) via a crafted Ethernet frame.
low complexity
citrix CWE-20
6.5
2018-12-08 CVE-2018-19965 An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code.
local
high complexity
xen citrix debian
5.6
2018-06-21 CVE-2018-3665 Information Exposure vulnerability in multiple products
System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.
5.6
2017-01-30 CVE-2017-5573 Unspecified vulnerability in Citrix Xenserver
An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0.
network
low complexity
citrix
4.9
2017-01-30 CVE-2017-5572 Improper Privilege Management vulnerability in Citrix Xenserver
An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0.
network
low complexity
citrix CWE-269
6.5
2017-01-26 CVE-2016-10025 NULL Pointer Dereference vulnerability in multiple products
VMFUNC emulation in Xen 4.6.x through 4.8.x on x86 systems using AMD virtualization extensions (aka SVM) allows local HVM guest OS users to cause a denial of service (hypervisor crash) by leveraging a missing NULL pointer check.
local
low complexity
xen citrix CWE-476
5.5
2017-01-26 CVE-2016-10024 Improper Input Validation vulnerability in multiple products
Xen through 4.8.x allows local x86 PV guest OS kernel administrators to cause a denial of service (host hang or crash) by modifying the instruction stream asynchronously while performing certain kernel operations.
local
low complexity
xen citrix CWE-20
6.0
2017-01-23 CVE-2016-9385 Improper Input Validation vulnerability in multiple products
The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of service (host crash) by leveraging lack of canonical address checks.
local
low complexity
xen citrix CWE-20
6.0
2016-08-02 CVE-2016-6259 Improper Input Validation vulnerability in multiple products
Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety check.
local
low complexity
xen citrix CWE-20
6.2