NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
82866 | CVE-2016-9817 | Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving a (1) data or (2) prefetch abort with the ESR_EL2.EA bit set. | 2 | 4.9 | Medium | 2017-02-28 | 2017-02-28 | View | |
86124 | CVE-2017-8905 | Xen through 4.6.x on 64-bit platforms mishandles a failsafe callback, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-215. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
85500 | CVE-2017-7995 | Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function. NOTE: the upstream Xen Project considers versions before 4.5.x to be EOL. | 2 | 1.7 | Low | 2017-05-27 | 2017-05-15 | View | |
9294 | CVE-2011-2519 | Xen in the Linux kernel, when running a guest on a host without hardware assisted paging (HAP), allows guest users to cause a denial of service (invalid pointer dereference and hypervisor crash) via the SAHF instruction. | 2 | 5.2 | Medium | 2017-01-07 | 2013-12-27 | View | |
40092 | CVE-2013-4494 | Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlock) via unspecified vectors. | 2 | 5.2 | Medium | 2017-01-18 | 2017-01-06 | View |
Page 116 of 17672, showing 5 records out of 88360 total, starting on record 576, ending on 580