NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87730 | CVE-2017-10917 | Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) or possibly obtain sensitive information, aka XSA-221. | 2 | 9.4 | High | 2017-07-18 | 2017-07-10 | View | |
87729 | CVE-2017-10916 | The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (MPX) and Protection Key (PKU) features, which makes it easier for guest OS users to defeat ASLR and other protection mechanisms, aka XSA-220. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
87728 | CVE-2017-10915 | The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
87727 | CVE-2017-10914 | The grant-table feature in Xen through 4.8.x has a race condition leading to a double free, which allows guest OS users to cause a denial of service (memory consumption), or possibly obtain sensitive information or gain privileges, aka XSA-218 bug 2. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
87726 | CVE-2017-10913 | The grant-table feature in Xen through 4.8.x provides false mapping information in certain cases of concurrent unmap calls, which allows backend attackers to obtain sensitive information or gain privileges, aka XSA-218 bug 1. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 127 of 17672, showing 5 records out of 88360 total, starting on record 631, ending on 635