CVE List

Id CVE No. Status Description Phase Votes Comments Actions
18352  CVE-2006-2248  Candidate  Xeneo Web Server 2.2.22.0 allows remote attackers to obtain the source code of script files via crafted requests containing dot, space, and slash characters in the file extension.  Assigned (20060508)  None (candidate not yet proposed)    View
35833  CVE-2008-5716  Candidate  xend in Xen 3.3.0 does not properly restrict a guest VM"s write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue exists because of erroneous set_permissions calls in the fix for CVE-2008-4405.  Assigned (20081224)  None (candidate not yet proposed)    View
34522  CVE-2008-4405  Candidate  xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM"s write access within this tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue was originally reported as an issue in libvirt 0.3.3 and xenstore, but CVE is considering the core issue to be related to Xen.  Assigned (20081003)  None (candidate not yet proposed)    View
49848  CVE-2011-1936  Candidate  Xen, when using x86 Intel processors and the VMX virtualization extension is enabled, does not properly handle cpuid instruction emulation when exiting the VM, which allows local guest users to cause a denial of service (guest crash) via unspecified vectors.  Assigned (20110509)  None (candidate not yet proposed)    View
85827  CVE-2015-8550  Candidate  Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability.  Assigned (20151214)  None (candidate not yet proposed)    View

Page 95 of 20943, showing 5 records out of 104715 total, starting on record 471, ending on 475

Actions