Vulnerabilities > XEN > XEN > 4.8.1

DATE CVE VULNERABILITY TITLE RISK
2017-09-12 CVE-2017-14317 Race Condition vulnerability in XEN
A domain cleanup issue was discovered in the C xenstore daemon (aka cxenstored) in Xen through 4.9.x.
local
xen CWE-362
4.7
2017-09-12 CVE-2017-14316 Out-of-bounds Read vulnerability in XEN
A parameter verification issue was discovered in Xen through 4.9.x.
local
low complexity
xen CWE-125
7.2
2017-08-24 CVE-2017-12136 Race Condition vulnerability in multiple products
Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling.
6.9
2017-08-15 CVE-2017-12855 Information Exposure vulnerability in XEN
Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use.
local
low complexity
xen CWE-200
2.1
2017-07-05 CVE-2017-10923 Improper Input Validation vulnerability in XEN
Xen through 4.8.x does not validate a vCPU array index upon the sending of an SGI, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-225.
network
low complexity
xen CWE-20
5.0
2017-07-05 CVE-2017-10922 Resource Exhaustion vulnerability in XEN
The grant-table feature in Xen through 4.8.x mishandles MMIO region grant references, which allows guest OS users to cause a denial of service (loss of grant trackability), aka XSA-224 bug 3.
network
low complexity
xen CWE-400
5.0
2017-07-05 CVE-2017-10921 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in XEN
The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 2.
network
low complexity
xen CWE-119
critical
10.0
2017-07-05 CVE-2017-10920 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in XEN
The grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed by only a GNTMAP_host_map unmapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 1.
network
low complexity
xen CWE-119
critical
10.0
2017-07-05 CVE-2017-10919 Denial of Service vulnerability in Xen 'xen/arch/arm/gic.c'
Xen through 4.8.x mishandles virtual interrupt injection, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-223.
network
low complexity
xen
5.0
2017-07-05 CVE-2017-10918 Improper Input Validation vulnerability in XEN
Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access, aka XSA-222.
network
low complexity
xen CWE-20
critical
10.0