Записи Xen
497 опубликованных записей вендора xen.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 3 · 0,6 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 94,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation49
- CWE-264 Permissions, Privileges, and Access Controls48
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer32
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')29
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor28
- CWE-399 Resource Management Errors28
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
497 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2015-5165Эксплойта нет | The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers toxen · xen · CWE-908 | Критическая9,3 | — | 13,3 % | 12 авг. 2015 г. |
41В плане | CVE-2017-10918Эксплойта нет | Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host xen · xen · CWE-20 | Критическая10,0 | — | 3,7 % | 4 июл. 2017 г. |
41В плане | CVE-2017-10912Эксплойта нет | Xen through 4.8.x mishandles page transfer, which allows guest OS users to obtain privileged host OS access, aka XSA-217.xen · xen | Критическая10,0 | — | 2,7 % | 4 июл. 2017 г. |
41В плане | CVE-2017-10921Эксплойта нет | The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, whixen · xen · CWE-119 | Критическая10,0 | — | 2,5 % | 4 июл. 2017 г. |
41В плане | CVE-2017-10920Эксплойта нет | The grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed by only a GNTMAP_hostxen · xen · CWE-119 | Критическая10,0 | — | 2,5 % | 4 июл. 2017 г. |
41В плане | CVE-2015-8104Эксплойта нет | The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host Oxen · xen · CWE-399 | Критическая10,0 | — | 2,5 % | 16 нояб. 2015 г. |
40В плане | CVE-2012-0217Готовый эксплойт | The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracxen · xen · CWE-119 | Высокая7,2 | — | 39,8 % | 12 июн. 2012 г. |
40В плане | CVE-2017-2620Эксплойта нет | Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue.qemu · qemu · CWE-787 | Критическая9,9 | — | 3,6 % | 27 июл. 2018 г. |
40В плане | CVE-2017-10913Эксплойта нет | The grant-table feature in Xen through 4.8.x provides false mapping information in certain cases of concurrent unmap calls, which allows bacxen · xen | Критическая9,8 | — | 2,8 % | 4 июл. 2017 г. |
40В плане | CVE-2019-18425Эксплойта нет | An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptxen · xen · CWE-269 | Критическая9,8 | — | 2,5 % | 31 окт. 2019 г. |
40В плане | CVE-2018-12892Эксплойта нет | An issue was discovered in Xen 4.7 through 4.10.x.xen · xen · CWE-200 | Критическая9,9 | — | 2,5 % | 2 июл. 2018 г. |
39Наблюдать | CVE-2025-58142Эксплойта нет | Mutiple vulnerabilities in the Viridian interfacexen · xen · CWE-395 | Критическая9,8 | — | 0,5 % | 11 сент. 2025 г. |
39Наблюдать | CVE-2025-27466Эксплойта нет | Mutiple vulnerabilities in the Viridian interfacexen · xen · CWE-395 | Критическая9,8 | — | 0,5 % | 11 сент. 2025 г. |
39Наблюдать | CVE-2025-58143Эксплойта нет | Mutiple vulnerabilities in the Viridian interfacexen · xen · CWE-366 | Критическая9,8 | — | 0,4 % | 11 сент. 2025 г. |
37Наблюдать | CVE-2018-8897Готовый эксплойт | A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the debian · debian linux · CWE-362 | Высокая7,8 | — | 18,5 % | 8 мая 2018 г. |
37Наблюдать | CVE-2017-2615Эксплойта нет | Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue.qemu · qemu · CWE-787 | Критическая9,1 | — | 3,6 % | 2 июл. 2018 г. |
37Наблюдать | CVE-2017-15597Эксплойта нет | An issue was discovered in Xen through 4.9.x.xen · xen · CWE-119 | Критическая9,1 | — | 2,8 % | 30 окт. 2017 г. |
37Наблюдать | CVE-2017-10917Эксплойта нет | Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of servicexen · xen · CWE-476 | Критическая9,1 | — | 2,6 % | 4 июл. 2017 г. |
37Наблюдать | CVE-2017-10915Эксплойта нет | The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest Oxen · xen · CWE-362 | Критическая9,0 | — | 1,7 % | 4 июл. 2017 г. |
36Наблюдать | CVE-2022-4949Эксплойта нет | AdSanity < 1.8.2 - Authenticated Arbitrary File Uploadadsanityplugin · adsanity · CWE-434 | Высокая8,8 | — | 2,2 % | 6 июн. 2023 г. |
36Наблюдать | CVE-2019-18423Эксплойта нет | An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service via a XENMEM_add_to_physmap hypercallxen · xen · CWE-193 | Высокая8,8 | — | 2,1 % | 31 окт. 2019 г. |
36Наблюдать | CVE-2019-18422Эксплойта нет | An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the xen · xen · CWE-732 | Высокая8,8 | — | 1,8 % | 31 окт. 2019 г. |
35Наблюдать | CVE-2024-31142Эксплойта нет | x86: Incorrect logic for BTC/SRSO mitigationsxen · xen · CWE-693 | Высокая7,5 | — | 17,4 % | 16 мая 2024 г. |
35Наблюдать | CVE-2015-3456Proof of concept | The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (oqemu · qemu · CWE-119 | Высокая7,7 | — | 15,3 % | 13 мая 2015 г. |
35Наблюдать | CVE-2015-8555Эксплойта нет | Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guestxen · xen · CWE-200 | Высокая8,6 | — | 2,3 % | 13 апр. 2016 г. |
- CVE-2015-516541В плане
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to
КритическаяCVSS 9,3Эксплойта нетEPSS 13 %xen · xen12 авг. 2015 г.
- CVE-2017-1091841В плане
Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %xen · xen4 июл. 2017 г.
- CVE-2017-1091241В плане
Xen through 4.8.x mishandles page transfer, which allows guest OS users to obtain privileged host OS access, aka XSA-217.
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %xen · xen4 июл. 2017 г.
- CVE-2017-1092141В плане
The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, whi
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %xen · xen4 июл. 2017 г.
- CVE-2017-1092041В плане
The grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed by only a GNTMAP_host
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %xen · xen4 июл. 2017 г.
- CVE-2015-810441В плане
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host O
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %xen · xen16 нояб. 2015 г.
- CVE-2012-021740В плане
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Orac
ВысокаяCVSS 7,2Готовый эксплойтEPSS 40 %xen · xen12 июн. 2012 г.
- CVE-2017-262040В плане
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue.
КритическаяCVSS 9,9Эксплойта нетEPSS 4 %qemu · qemu27 июл. 2018 г.
- CVE-2017-1091340В плане
The grant-table feature in Xen through 4.8.x provides false mapping information in certain cases of concurrent unmap calls, which allows bac
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %xen · xen4 июл. 2017 г.
- CVE-2019-1842540В плане
An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descript
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %xen · xen31 окт. 2019 г.
- CVE-2018-1289240В плане
An issue was discovered in Xen 4.7 through 4.10.x.
КритическаяCVSS 9,9Эксплойта нетEPSS 3 %xen · xen2 июл. 2018 г.
- CVE-2025-5814239Наблюдать
Mutiple vulnerabilities in the Viridian interface
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %xen · xen11 сент. 2025 г.
- CVE-2025-2746639Наблюдать
Mutiple vulnerabilities in the Viridian interface
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %xen · xen11 сент. 2025 г.
- CVE-2025-5814339Наблюдать
Mutiple vulnerabilities in the Viridian interface
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %xen · xen11 сент. 2025 г.
- CVE-2018-889737Наблюдать
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the
ВысокаяCVSS 7,8Готовый эксплойтEPSS 18 %debian · debian linux8 мая 2018 г.
- CVE-2017-261537Наблюдать
Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue.
КритическаяCVSS 9,1Эксплойта нетEPSS 4 %qemu · qemu2 июл. 2018 г.
- CVE-2017-1559737Наблюдать
An issue was discovered in Xen through 4.9.x.
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %xen · xen30 окт. 2017 г.
- CVE-2017-1091737Наблюдать
Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %xen · xen4 июл. 2017 г.
- CVE-2017-1091537Наблюдать
The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest O
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %xen · xen4 июл. 2017 г.
- CVE-2022-494936Наблюдать
AdSanity < 1.8.2 - Authenticated Arbitrary File Upload
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %adsanityplugin · adsanity6 июн. 2023 г.
- CVE-2019-1842336Наблюдать
An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service via a XENMEM_add_to_physmap hypercall
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %xen · xen31 окт. 2019 г.
- CVE-2019-1842236Наблюдать
An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %xen · xen31 окт. 2019 г.
- CVE-2024-3114235Наблюдать
x86: Incorrect logic for BTC/SRSO mitigations
ВысокаяCVSS 7,5Эксплойта нетEPSS 17 %xen · xen16 мая 2024 г.
- CVE-2015-345635Наблюдать
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (o
ВысокаяCVSS 7,7Proof of conceptEPSS 15 %qemu · qemu13 мая 2015 г.
- CVE-2015-855535Наблюдать
Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest
ВысокаяCVSS 8,6Эксплойта нетEPSS 2 %xen · xen13 апр. 2016 г.