CVE List

Id CVE No. Status Description Phase Votes Comments Actions
90780  CVE-2016-3961  Candidate  Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, which allows local PV guest OS users to cause a denial of service (guest OS crash) by attempting to access a hugetlbfs mapped area.  Assigned (20160405)  None (candidate not yet proposed)    View
85830  CVE-2015-8553  Candidate  Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decoding control bits. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0777.  Assigned (20151214)  None (candidate not yet proposed)    View
61899  CVE-2013-1952  Candidate  Xen 4.x, when using Intel VT-d for a bus mastering capable PCI device, does not properly check the source when accessing a bridge device"s interrupt remapping table entries for MSI interrupts, which allows local guest domains to cause a denial of service (interrupt injection) via unspecified vectors.  Assigned (20130219)  None (candidate not yet proposed)    View
58753  CVE-2012-5510  Candidate  Xen 4.x, when downgrading the grant table version, does not properly remove the status page from the tracking list when freeing the page, which allows local guest OS administrators to cause a denial of service (hypervisor crash) via unspecified vectors.  Assigned (20121024)  None (candidate not yet proposed)    View
94597  CVE-2016-7777  Candidate  Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruction while the hypervisor is preparing to emulate it.  Assigned (20160909)  None (candidate not yet proposed)    View

Page 98 of 20943, showing 5 records out of 104715 total, starting on record 486, ending on 490

Actions