NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
40092  CVE-2013-4494  Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlock) via unspecified vectors.    5.2  Medium  2017-01-18  2017-01-06  View
9294  CVE-2011-2519  Xen in the Linux kernel, when running a guest on a host without hardware assisted paging (HAP), allows guest users to cause a denial of service (invalid pointer dereference and hypervisor crash) via the SAHF instruction.    5.2  Medium  2017-01-07  2013-12-27  View
85500  CVE-2017-7995  Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function. NOTE: the upstream Xen Project considers versions before 4.5.x to be EOL.    1.7  Low  2017-05-27  2017-05-15  View
86124  CVE-2017-8905  Xen through 4.6.x on 64-bit platforms mishandles a failsafe callback, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-215.    6.8  Medium  2017-07-18  2017-07-10  View
82866  CVE-2016-9817  Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving a (1) data or (2) prefetch abort with the ESR_EL2.EA bit set.    4.9  Medium  2017-02-28  2017-02-28  View

Page 17557 of 17672, showing 5 records out of 88360 total, starting on record 87781, ending on 87785

Actions