CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
85827 | CVE-2015-8550 | Candidate | Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability. | Assigned (20151214) | None (candidate not yet proposed) | View | |
49848 | CVE-2011-1936 | Candidate | Xen, when using x86 Intel processors and the VMX virtualization extension is enabled, does not properly handle cpuid instruction emulation when exiting the VM, which allows local guest users to cause a denial of service (guest crash) via unspecified vectors. | Assigned (20110509) | None (candidate not yet proposed) | View | |
34522 | CVE-2008-4405 | Candidate | xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM"s write access within this tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue was originally reported as an issue in libvirt 0.3.3 and xenstore, but CVE is considering the core issue to be related to Xen. | Assigned (20081003) | None (candidate not yet proposed) | View | |
35833 | CVE-2008-5716 | Candidate | xend in Xen 3.3.0 does not properly restrict a guest VM"s write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue exists because of erroneous set_permissions calls in the fix for CVE-2008-4405. | Assigned (20081224) | None (candidate not yet proposed) | View | |
18352 | CVE-2006-2248 | Candidate | Xeneo Web Server 2.2.22.0 allows remote attackers to obtain the source code of script files via crafted requests containing dot, space, and slash characters in the file extension. | Assigned (20060508) | None (candidate not yet proposed) | View |
Page 20849 of 20943, showing 5 records out of 104715 total, starting on record 104241, ending on 104245