Vulnerabilities > XEN > XEN > 4.9.0

DATE CVE VULNERABILITY TITLE RISK
2017-10-18 CVE-2017-15594 Unspecified vulnerability in XEN
An issue was discovered in Xen through 4.9.x allowing x86 SVM PV guest OS users to cause a denial of service (hypervisor crash) or gain privileges because IDT settings are mishandled during CPU hotplugging.
local
low complexity
xen
4.6
2017-10-18 CVE-2017-15593 Missing Release of Resource after Effective Lifetime vulnerability in XEN
An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to cause a denial of service (memory leak) because reference counts are mishandled.
local
low complexity
xen CWE-772
4.9
2017-10-18 CVE-2017-15592 Exposure of Resource to Wrong Sphere vulnerability in XEN
An issue was discovered in Xen through 4.9.x allowing x86 HVM guest OS users to cause a denial of service (hypervisor crash) or possibly gain privileges because self-linear shadow mappings are mishandled for translated guests.
local
low complexity
xen CWE-668
7.2
2017-10-18 CVE-2017-15591 Improper Input Validation vulnerability in XEN
An issue was discovered in Xen 4.5.x through 4.9.x allowing attackers (who control a stub domain kernel or tool stack) to cause a denial of service (host OS crash) because of a missing comparison (of range start to range end) within the DMOP map/unmap implementation.
local
low complexity
xen CWE-20
4.9
2017-10-18 CVE-2017-15590 Unspecified vulnerability in XEN 4.9.0
An issue was discovered in Xen through 4.9.x allowing x86 guest OS users to cause a denial of service (hypervisor crash) or possibly gain privileges because MSI mapping was mishandled.
local
low complexity
xen
4.6
2017-10-18 CVE-2017-15589 Information Exposure vulnerability in XEN 4.9.0
An issue was discovered in Xen through 4.9.x allowing x86 HVM guest OS users to obtain sensitive information from the host OS (or an arbitrary guest OS) because intercepted I/O operations can cause a write of data from uninitialized hypervisor stack memory.
local
low complexity
xen CWE-200
2.1
2017-10-18 CVE-2017-15588 Race Condition vulnerability in XEN 4.9.0
An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to execute arbitrary code on the host OS because of a race condition that can cause a stale TLB entry.
local
xen CWE-362
6.9
2017-09-12 CVE-2017-14319 Unspecified vulnerability in XEN
A grant unmapping issue was discovered in Xen through 4.9.x.
local
low complexity
xen
7.2
2017-09-12 CVE-2017-14318 NULL Pointer Dereference vulnerability in XEN
An issue was discovered in Xen 4.5.x through 4.9.x.
local
low complexity
xen CWE-476
4.9
2017-09-12 CVE-2017-14317 Race Condition vulnerability in XEN
A domain cleanup issue was discovered in the C xenstore daemon (aka cxenstored) in Xen through 4.9.x.
local
xen CWE-362
4.7