Xen kayıtları
xen üreticisine ait 497 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 3 · %0,6
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %94,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation49
- CWE-264 Permissions, Privileges, and Access Controls48
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer32
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')29
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor28
- CWE-399 Resource Management Errors28
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
497 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2015-5165İstismar yok | The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers toxen · xen · CWE-908 | Kritik9,3 | — | %13,3 | 12 Ağu 2015 |
41Planlayın | CVE-2017-10918İstismar yok | Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host xen · xen · CWE-20 | Kritik10,0 | — | %3,7 | 4 Tem 2017 |
41Planlayın | CVE-2017-10912İstismar yok | Xen through 4.8.x mishandles page transfer, which allows guest OS users to obtain privileged host OS access, aka XSA-217.xen · xen | Kritik10,0 | — | %2,7 | 4 Tem 2017 |
41Planlayın | CVE-2017-10921İstismar yok | The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, whixen · xen · CWE-119 | Kritik10,0 | — | %2,5 | 4 Tem 2017 |
41Planlayın | CVE-2017-10920İstismar yok | The grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed by only a GNTMAP_hostxen · xen · CWE-119 | Kritik10,0 | — | %2,5 | 4 Tem 2017 |
41Planlayın | CVE-2015-8104İstismar yok | The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host Oxen · xen · CWE-399 | Kritik10,0 | — | %2,5 | 16 Kas 2015 |
40Planlayın | CVE-2012-0217Silahlaştırılmış | The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracxen · xen · CWE-119 | Yüksek7,2 | — | %39,8 | 12 Haz 2012 |
40Planlayın | CVE-2017-2620İstismar yok | Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue.qemu · qemu · CWE-787 | Kritik9,9 | — | %3,6 | 27 Tem 2018 |
40Planlayın | CVE-2017-10913İstismar yok | The grant-table feature in Xen through 4.8.x provides false mapping information in certain cases of concurrent unmap calls, which allows bacxen · xen | Kritik9,8 | — | %2,8 | 4 Tem 2017 |
40Planlayın | CVE-2019-18425İstismar yok | An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptxen · xen · CWE-269 | Kritik9,8 | — | %2,5 | 31 Eki 2019 |
40Planlayın | CVE-2018-12892İstismar yok | An issue was discovered in Xen 4.7 through 4.10.x.xen · xen · CWE-200 | Kritik9,9 | — | %2,5 | 2 Tem 2018 |
39İzleyin | CVE-2025-58142İstismar yok | Mutiple vulnerabilities in the Viridian interfacexen · xen · CWE-395 | Kritik9,8 | — | %0,5 | 11 Eyl 2025 |
39İzleyin | CVE-2025-27466İstismar yok | Mutiple vulnerabilities in the Viridian interfacexen · xen · CWE-395 | Kritik9,8 | — | %0,5 | 11 Eyl 2025 |
39İzleyin | CVE-2025-58143İstismar yok | Mutiple vulnerabilities in the Viridian interfacexen · xen · CWE-366 | Kritik9,8 | — | %0,4 | 11 Eyl 2025 |
37İzleyin | CVE-2018-8897Silahlaştırılmış | A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the debian · debian linux · CWE-362 | Yüksek7,8 | — | %18,5 | 8 May 2018 |
37İzleyin | CVE-2017-2615İstismar yok | Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue.qemu · qemu · CWE-787 | Kritik9,1 | — | %3,6 | 2 Tem 2018 |
37İzleyin | CVE-2017-15597İstismar yok | An issue was discovered in Xen through 4.9.x.xen · xen · CWE-119 | Kritik9,1 | — | %2,8 | 30 Eki 2017 |
37İzleyin | CVE-2017-10917İstismar yok | Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of servicexen · xen · CWE-476 | Kritik9,1 | — | %2,6 | 4 Tem 2017 |
37İzleyin | CVE-2017-10915İstismar yok | The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest Oxen · xen · CWE-362 | Kritik9,0 | — | %1,7 | 4 Tem 2017 |
36İzleyin | CVE-2022-4949İstismar yok | AdSanity < 1.8.2 - Authenticated Arbitrary File Uploadadsanityplugin · adsanity · CWE-434 | Yüksek8,8 | — | %2,2 | 6 Haz 2023 |
36İzleyin | CVE-2019-18423İstismar yok | An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service via a XENMEM_add_to_physmap hypercallxen · xen · CWE-193 | Yüksek8,8 | — | %2,1 | 31 Eki 2019 |
36İzleyin | CVE-2019-18422İstismar yok | An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the xen · xen · CWE-732 | Yüksek8,8 | — | %1,8 | 31 Eki 2019 |
35İzleyin | CVE-2024-31142İstismar yok | x86: Incorrect logic for BTC/SRSO mitigationsxen · xen · CWE-693 | Yüksek7,5 | — | %17,4 | 16 May 2024 |
35İzleyin | CVE-2015-3456Kavram kanıtı | The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (oqemu · qemu · CWE-119 | Yüksek7,7 | — | %15,3 | 13 May 2015 |
35İzleyin | CVE-2015-8555İstismar yok | Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guestxen · xen · CWE-200 | Yüksek8,6 | — | %2,3 | 13 Nis 2016 |
- CVE-2015-516541Planlayın
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to
KritikCVSS 9,3İstismar yokEPSS %13xen · xen12 Ağu 2015
- CVE-2017-1091841Planlayın
Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host
KritikCVSS 10,0İstismar yokEPSS %4xen · xen4 Tem 2017
- CVE-2017-1091241Planlayın
Xen through 4.8.x mishandles page transfer, which allows guest OS users to obtain privileged host OS access, aka XSA-217.
KritikCVSS 10,0İstismar yokEPSS %3xen · xen4 Tem 2017
- CVE-2017-1092141Planlayın
The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, whi
KritikCVSS 10,0İstismar yokEPSS %3xen · xen4 Tem 2017
- CVE-2017-1092041Planlayın
The grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed by only a GNTMAP_host
KritikCVSS 10,0İstismar yokEPSS %3xen · xen4 Tem 2017
- CVE-2015-810441Planlayın
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host O
KritikCVSS 10,0İstismar yokEPSS %3xen · xen16 Kas 2015
- CVE-2012-021740Planlayın
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Orac
YüksekCVSS 7,2SilahlaştırılmışEPSS %40xen · xen12 Haz 2012
- CVE-2017-262040Planlayın
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue.
KritikCVSS 9,9İstismar yokEPSS %4qemu · qemu27 Tem 2018
- CVE-2017-1091340Planlayın
The grant-table feature in Xen through 4.8.x provides false mapping information in certain cases of concurrent unmap calls, which allows bac
KritikCVSS 9,8İstismar yokEPSS %3xen · xen4 Tem 2017
- CVE-2019-1842540Planlayın
An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descript
KritikCVSS 9,8İstismar yokEPSS %3xen · xen31 Eki 2019
- CVE-2018-1289240Planlayın
An issue was discovered in Xen 4.7 through 4.10.x.
KritikCVSS 9,9İstismar yokEPSS %3xen · xen2 Tem 2018
- CVE-2025-5814239İzleyin
Mutiple vulnerabilities in the Viridian interface
KritikCVSS 9,8İstismar yokEPSS %0xen · xen11 Eyl 2025
- CVE-2025-2746639İzleyin
Mutiple vulnerabilities in the Viridian interface
KritikCVSS 9,8İstismar yokEPSS %0xen · xen11 Eyl 2025
- CVE-2025-5814339İzleyin
Mutiple vulnerabilities in the Viridian interface
KritikCVSS 9,8İstismar yokEPSS %0xen · xen11 Eyl 2025
- CVE-2018-889737İzleyin
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the
YüksekCVSS 7,8SilahlaştırılmışEPSS %18debian · debian linux8 May 2018
- CVE-2017-261537İzleyin
Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue.
KritikCVSS 9,1İstismar yokEPSS %4qemu · qemu2 Tem 2018
- CVE-2017-1559737İzleyin
An issue was discovered in Xen through 4.9.x.
KritikCVSS 9,1İstismar yokEPSS %3xen · xen30 Eki 2017
- CVE-2017-1091737İzleyin
Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service
KritikCVSS 9,1İstismar yokEPSS %3xen · xen4 Tem 2017
- CVE-2017-1091537İzleyin
The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest O
KritikCVSS 9,0İstismar yokEPSS %2xen · xen4 Tem 2017
- CVE-2022-494936İzleyin
AdSanity < 1.8.2 - Authenticated Arbitrary File Upload
YüksekCVSS 8,8İstismar yokEPSS %2adsanityplugin · adsanity6 Haz 2023
- CVE-2019-1842336İzleyin
An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service via a XENMEM_add_to_physmap hypercall
YüksekCVSS 8,8İstismar yokEPSS %2xen · xen31 Eki 2019
- CVE-2019-1842236İzleyin
An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the
YüksekCVSS 8,8İstismar yokEPSS %2xen · xen31 Eki 2019
- CVE-2024-3114235İzleyin
x86: Incorrect logic for BTC/SRSO mitigations
YüksekCVSS 7,5İstismar yokEPSS %17xen · xen16 May 2024
- CVE-2015-345635İzleyin
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (o
YüksekCVSS 7,7Kavram kanıtıEPSS %15qemu · qemu13 May 2015
- CVE-2015-855535İzleyin
Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest
YüksekCVSS 8,6İstismar yokEPSS %2xen · xen13 Nis 2016