Vulnerabilities > XEN > Low
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2015-03-12 | CVE-2015-2045 | Information Exposure vulnerability in multiple products The HYPERVISOR_xen_version hypercall in Xen 3.2.x through 4.5.x does not properly initialize data structures, which allows local guest users to obtain sensitive information via unspecified vectors. | 2.1 |
2015-02-09 | CVE-2015-1563 | Resource Management Errors vulnerability in multiple products The ARM GIC distributor virtualization in Xen 4.4.x and 4.5.x allows local guests to cause a denial of service by causing a large number messages to be logged. | 2.1 |
2014-11-19 | CVE-2014-8595 | Code vulnerability in multiple products arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a crafted (1) CALL, (2) JMP, (3) RETF, (4) LCALL, (5) LJMP, or (6) LRET far branch instruction. | 1.9 |
2014-10-02 | CVE-2014-7156 | Permissions, Privileges, and Access Controls vulnerability in XEN The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 3.3.x through 4.4.x does not check the supervisor mode permissions for instructions that generate software interrupts, which allows local HVM guest users to cause a denial of service (guest crash) via unspecified vectors. | 3.3 |
2014-07-09 | CVE-2014-4022 | Information Exposure vulnerability in XEN 4.4.0 The alloc_domain_struct function in arch/arm/domain.c in Xen 4.4.x, when running on an ARM platform, does not properly initialize the structure containing the grant table pages for a domain, which allows local guest administrators to obtain sensitive information via the GNTTABOP_setup_table subhypercall. | 2.7 |
2014-06-18 | CVE-2014-4021 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in XEN Xen 3.2.x through 4.4.x does not properly clean memory pages recovered from guests, which allows local guest OS users to obtain sensitive information via unspecified vectors. | 2.7 |
2014-05-19 | CVE-2014-3714 | Improper Input Validation vulnerability in XEN 4.4.0 The ARM image loading functionality in Xen 4.4.x does not properly validate kernel length, which allows local users to read system memory or cause a denial of service (crash) via a crafted 32-bit ARM guest kernel in an image, which triggers a buffer overflow. | 3.3 |
2014-05-19 | CVE-2014-3715 | Buffer Errors vulnerability in XEN 4.4.0 Buffer overflow in Xen 4.4.x allows local users to read system memory or cause a denial of service (crash) via a crafted 32-bit guest kernel, related to searching for an appended DTB. | 3.3 |
2014-05-19 | CVE-2014-3716 | Improper Input Validation vulnerability in XEN 4.4.0 Xen 4.4.x does not properly check alignment, which allows local users to cause a denial of service (crash) via an unspecified field in a DTB header in a 32-bit guest kernel. | 1.9 |
2014-05-19 | CVE-2014-3717 | Improper Input Validation vulnerability in XEN 4.4.0 Xen 4.4.x does not properly validate the load address for 64-bit ARM guest kernels, which allows local users to read system memory or cause a denial of service (crash) via a crafted kernel, which triggers a buffer overflow. | 3.3 |