Vulnerabilities > XEN > Low
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-01-31 | CVE-2015-6815 | Infinite Loop vulnerability in multiple products The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors. | 3.5 |
2018-07-02 | CVE-2018-12893 | An issue was discovered in Xen through 4.10.x. | 2.1 |
2018-04-27 | CVE-2018-10472 | Information Exposure vulnerability in multiple products An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot. | 1.9 |
2017-11-28 | CVE-2017-17046 | Information Exposure vulnerability in XEN An issue was discovered in Xen through 4.9.x on the ARM platform allowing guest OS users to obtain sensitive information from DRAM after a reboot, because disjoint blocks, and physical addresses that do not start at zero, are mishandled. | 2.1 |
2017-10-18 | CVE-2017-15589 | Information Exposure vulnerability in XEN 4.9.0 An issue was discovered in Xen through 4.9.x allowing x86 HVM guest OS users to obtain sensitive information from the host OS (or an arbitrary guest OS) because intercepted I/O operations can cause a write of data from uninitialized hypervisor stack memory. | 2.1 |
2017-08-15 | CVE-2017-12855 | Information Exposure vulnerability in XEN Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use. | 2.1 |
2017-05-03 | CVE-2017-7995 | Information Exposure vulnerability in multiple products Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. | 1.7 |
2017-02-22 | CVE-2016-9377 | Incorrect Calculation vulnerability in XEN Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging IDT entry miscalculation. | 2.1 |
2017-02-22 | CVE-2016-9378 | Improper Access Control vulnerability in XEN Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging an incorrect choice for software interrupt delivery. | 2.1 |
2017-02-22 | CVE-2016-9384 | Information Exposure vulnerability in XEN 4.7.0/4.7.1 Xen 4.7 allows local guest OS users to obtain sensitive host information by loading a 32-bit ELF symbol table. | 2.1 |