Перейти к содержимому
Noroxi

Записи Xen

497 опубликованных записей вендора xen.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
3 · 0,6 %
Pre-auth RCE
1
С записью об исправлении
94,8 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

497 записей
  • CVE-2015-5165
    41В плане

    The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to

    КритическаяCVSS 9,3Эксплойта нетEPSS 13 %

    xen · xen12 авг. 2015 г.

  • CVE-2017-10918
    41В плане

    Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host

    КритическаяCVSS 10,0Эксплойта нетEPSS 4 %

    xen · xen4 июл. 2017 г.

  • CVE-2017-10912
    41В плане

    Xen through 4.8.x mishandles page transfer, which allows guest OS users to obtain privileged host OS access, aka XSA-217.

    КритическаяCVSS 10,0Эксплойта нетEPSS 3 %

    xen · xen4 июл. 2017 г.

  • CVE-2017-10921
    41В плане

    The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, whi

    КритическаяCVSS 10,0Эксплойта нетEPSS 3 %

    xen · xen4 июл. 2017 г.

  • CVE-2017-10920
    41В плане

    The grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed by only a GNTMAP_host

    КритическаяCVSS 10,0Эксплойта нетEPSS 3 %

    xen · xen4 июл. 2017 г.

  • CVE-2015-8104
    41В плане

    The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host O

    КритическаяCVSS 10,0Эксплойта нетEPSS 3 %

    xen · xen16 нояб. 2015 г.

  • CVE-2012-0217
    40В плане

    The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Orac

    ВысокаяCVSS 7,2Готовый эксплойтEPSS 40 %

    xen · xen12 июн. 2012 г.

  • CVE-2017-2620
    40В плане

    Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue.

    КритическаяCVSS 9,9Эксплойта нетEPSS 4 %

    qemu · qemu27 июл. 2018 г.

  • CVE-2017-10913
    40В плане

    The grant-table feature in Xen through 4.8.x provides false mapping information in certain cases of concurrent unmap calls, which allows bac

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    xen · xen4 июл. 2017 г.

  • CVE-2019-18425
    40В плане

    An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descript

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    xen · xen31 окт. 2019 г.

  • CVE-2018-12892
    40В плане

    An issue was discovered in Xen 4.7 through 4.10.x.

    КритическаяCVSS 9,9Эксплойта нетEPSS 3 %

    xen · xen2 июл. 2018 г.

  • CVE-2025-58142
    39Наблюдать

    Mutiple vulnerabilities in the Viridian interface

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    xen · xen11 сент. 2025 г.

  • CVE-2025-27466
    39Наблюдать

    Mutiple vulnerabilities in the Viridian interface

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    xen · xen11 сент. 2025 г.

  • CVE-2025-58143
    39Наблюдать

    Mutiple vulnerabilities in the Viridian interface

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    xen · xen11 сент. 2025 г.

  • CVE-2018-8897
    37Наблюдать

    A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the

    ВысокаяCVSS 7,8Готовый эксплойтEPSS 18 %

    debian · debian linux8 мая 2018 г.

  • CVE-2017-2615
    37Наблюдать

    Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue.

    КритическаяCVSS 9,1Эксплойта нетEPSS 4 %

    qemu · qemu2 июл. 2018 г.

  • CVE-2017-15597
    37Наблюдать

    An issue was discovered in Xen through 4.9.x.

    КритическаяCVSS 9,1Эксплойта нетEPSS 3 %

    xen · xen30 окт. 2017 г.

  • CVE-2017-10917
    37Наблюдать

    Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service

    КритическаяCVSS 9,1Эксплойта нетEPSS 3 %

    xen · xen4 июл. 2017 г.

  • CVE-2017-10915
    37Наблюдать

    The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest O

    КритическаяCVSS 9,0Эксплойта нетEPSS 2 %

    xen · xen4 июл. 2017 г.

  • CVE-2022-4949
    36Наблюдать

    AdSanity < 1.8.2 - Authenticated Arbitrary File Upload

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    adsanityplugin · adsanity6 июн. 2023 г.

  • CVE-2019-18423
    36Наблюдать

    An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service via a XENMEM_add_to_physmap hypercall

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    xen · xen31 окт. 2019 г.

  • CVE-2019-18422
    36Наблюдать

    An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    xen · xen31 окт. 2019 г.

  • CVE-2024-31142
    35Наблюдать

    x86: Incorrect logic for BTC/SRSO mitigations

    ВысокаяCVSS 7,5Эксплойта нетEPSS 17 %

    xen · xen16 мая 2024 г.

  • CVE-2015-3456
    35Наблюдать

    The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (o

    ВысокаяCVSS 7,7Proof of conceptEPSS 15 %

    qemu · qemu13 мая 2015 г.

  • CVE-2015-8555
    35Наблюдать

    Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest

    ВысокаяCVSS 8,6Эксплойта нетEPSS 2 %

    xen · xen13 апр. 2016 г.