Vulnerabilities > XEN > XEN > 4.9.0

DATE CVE VULNERABILITY TITLE RISK
2017-09-12 CVE-2017-14316 Out-of-bounds Read vulnerability in XEN
A parameter verification issue was discovered in Xen through 4.9.x.
local
low complexity
xen CWE-125
7.2
2017-08-24 CVE-2017-12136 Race Condition vulnerability in multiple products
Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling.
6.9
2017-08-15 CVE-2017-12855 Information Exposure vulnerability in XEN
Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use.
local
low complexity
xen CWE-200
2.1