← Back

Xen

xen

494 CVEs • 5 products

Products (5)

Click to collapse
Toggle
Xen
xen
Xapi
xapi
Qemu
qemu
Xen Unstable
xen-unstable

CVEs (494)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Citrix
Xen
2Xen
Xenserver
Apr 29, 2026
Nov 23, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
The set_debugreg hypercall in include/asm-x86/debugreg.h in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when running on x86-64 systems, allows local OS guest users to cause a denial of service (host cr...Show more
The set_debugreg hypercall in include/asm-x86/debugreg.h in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when running on x86-64 systems, allows local OS guest users to cause a denial of service (host crash) by writing to the reserved bits of the DR7 debug control register.Show less
1Xen
1Xen
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
Xen 4.0 through 4.2, when running 32-bit x86 PV guests on 64-bit hypervisors, allows local guest OS administrators to cause a denial of service (infinite loop and hang or crash) via invalid arguments to GNTTABOP_get_stat...Show more
Xen 4.0 through 4.2, when running 32-bit x86 PV guests on 64-bit hypervisors, allows local guest OS administrators to cause a denial of service (infinite loop and hang or crash) via invalid arguments to GNTTABOP_get_status_frames, aka "Grant table hypercall infinite loop DoS vulnerability."Show less
1Xen
1Xen
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchronize the p2m and m2p tables when the set_p2m_entry function fails, which allows local HVM guest OS administrators to cause a denial of service...Show more
Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchronize the p2m and m2p tables when the set_p2m_entry function fails, which allows local HVM guest OS administrators to cause a denial of service (memory consumption and assertion failure), aka "Memory mapping failure DoS vulnerability."Show less
1Xen
1Xen
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
The (1) domain_pirq_to_emuirq and (2) physdev_unmap_pirq functions in Xen 2.2 allows local guest OS administrators to cause a denial of service (Xen crash) via a crafted pirq value that triggers an out-of-bounds read.
1Xen
1Xen
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
1.9 LOW· v2
Xen 3.4 through 4.2, and possibly earlier versions, allows local guest OS administrators to cause a denial of service (Xen infinite loop and physical CPU consumption) by setting a VCPU with an "inappropriate deadline."
1Xen
1Xen
Apr 29, 2026
Oct 31, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memor...Show more
The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.Show less
1Xen
2Xen
Xen Unstable
Apr 29, 2026
Oct 31, 2012
N/A· v4
N/A· v3
2.7 LOW· v2
The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2.x, and 4.1.x allows local para-virtualized guest users to cause a denial of service (memory consumption) via a large (1) bzip2 or (2) lzma c...Show more
The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2.x, and 4.1.x allows local para-virtualized guest users to cause a denial of service (memory consumption) via a large (1) bzip2 or (2) lzma compressed kernel image.Show less
8Citrix
FreebsdIllumos+5 more
11Freebsd
IllumosNetbsd+8 more
Apr 29, 2026
Jun 12, 2012
N/A· v4
N/A· v3
7.2 HIGH· v2
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614...Show more
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly other operating systems, when running on an Intel processor, incorrectly uses the sysret path in cases where a certain address is not a canonical address, which allows local users to gain privileges via a crafted application. NOTE: because this issue is due to incorrect use of the Intel specification, it should have been split into separate identifiers; however, there was some value in preserving the original mapping of the multi-codebase coordinated-disclosure effort to a single identifier.Show less
1Xen
1Xen
Apr 23, 2026
Oct 5, 2009
N/A· v4
N/A· v3
7.2 HIGH· v2
The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows attackers with access to the para-virtualized guest console to boot th...Show more
The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows attackers with access to the para-virtualized guest console to boot the guest or modify the guest's kernel boot parameters without providing the expected password.Show less
1Xen
1Xen
Apr 23, 2026
May 22, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and probably other versions allows guest user applications to cause a denial of service (kernel oops) of...Show more
The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and probably other versions allows guest user applications to cause a denial of service (kernel oops) of the guest OS by triggering a segmentation fault in "certain address ranges."Show less
1Xen
1Xen
Apr 23, 2026
Nov 7, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
qemu-dm.debug in Xen 3.2.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/args temporary file.
1Xen
2Xen
Xen Flask Module
Apr 23, 2026
Aug 14, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in the flask_security_label function in Xen 3.3, when compiled with the XSM:FLASK module, allows unprivileged domain users (domU) to execute arbitrary code via the flask_op hypercall.
1Xen
1Xen
Apr 23, 2026
Dec 17, 2007
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The copy_to_user function in the PAL emulation functionality for Xen 3.1.2 and earlier, when running on ia64 systems, allows HVM guest users to access arbitrary physical memory by triggering certain mapping operations.
1Xen
1Qemu
Apr 23, 2026
Mar 20, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The VNC server implementation in QEMU, as used by Xen and possibly other environments, allows local users of a guest operating system to read arbitrary files on the host operating system via unspecified vectors related t...Show more
The VNC server implementation in QEMU, as used by Xen and possibly other environments, allows local users of a guest operating system to read arbitrary files on the host operating system via unspecified vectors related to QEMU monitor mode, as demonstrated by mapping files to a CDROM device. NOTE: some of these details are obtained from third party information.Show less