Search CVE reports


Toggle filters

1 – 10 of 21 results


CVE-2009-1758

Medium priority
Ignored

The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and probably other versions allows guest user applications to cause a denial of service (kernel oops) of the guest...

5 affected packages

xen, xen-3.0, xen-3.1, xen-3.2, xen-3.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
xen
xen-3.0
xen-3.1
xen-3.2
xen-3.3
Show less packages

CVE-2008-5716

Medium priority
Not affected

xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by...

6 affected packages

xen, xen-3.0, xen-3.1, xen-3.2, xen-3.3, xen-unstable

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
xen
xen-3.0
xen-3.1
xen-3.2
xen-3.3
xen-unstable
Show less packages

CVE-2008-5714

Medium priority

Some fixes available 2 of 19

Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote attackers to guess the VNC password, which is limited to seven characters where eight was intended.

8 affected packages

kvm, qemu, qemu-kvm, xen-3.0, xen-3.1...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
kvm
qemu
qemu-kvm
xen-3.0
xen-3.1
xen-3.2
xen-3.3
xen-unstable
Show all 8 packages Show less packages

CVE-2008-2382

Low priority

Some fixes available 2 of 8

The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote attackers to cause a denial of service (infinite loop) via a certain message.

8 affected packages

kvm, qemu, qemu-kvm, xen-3.0, xen-3.1...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
kvm
qemu
qemu-kvm
xen-3.0
xen-3.1
xen-3.2
xen-3.3
xen-unstable
Show all 8 packages Show less packages

CVE-2008-4993

Low priority
Ignored

qemu-dm.debug in Xen 3.2.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/args temporary file.

5 affected packages

xen, xen-3.0, xen-3.1, xen-3.2, xen-3.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
xen
xen-3.0
xen-3.1
xen-3.2
xen-3.3
Show less packages

CVE-2008-4405

Low priority
Ignored

xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM's write access within this tree, which allows guest OS users to cause a denial...

5 affected packages

xen, xen-3.0, xen-3.1, xen-3.2, xen-3.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
xen
xen-3.0
xen-3.1
xen-3.2
xen-3.3
Show less packages

CVE-2008-3687

Low priority
Not affected

Heap-based buffer overflow in the flask_security_label function in Xen 3.3, when compiled with the XSM:FLASK module, allows unprivileged domain users (domU) to execute arbitrary code via the flask_op hypercall.

4 affected packages

xen, xen-3.0, xen-3.1, xen-3.2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
xen
xen-3.0
xen-3.1
xen-3.2
Show less packages

CVE-2008-1945

Medium priority

Some fixes available 2 of 15

QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to...

7 affected packages

kvm, qemu, qemu-kvm, xen-3.0, xen-3.1...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
kvm
qemu
qemu-kvm
xen-3.0
xen-3.1
xen-3.2
xen-3.3
Show all 7 packages Show less packages

CVE-2008-1952

Medium priority
Ignored

The backend for XenSource Xen Para Virtualized Frame Buffer (PVFB) in Xen ioemu does not properly restrict the frame buffer size, which allows attackers to cause a denial of service (crash) by mapping an arbitrary amount of guest memory.

5 affected packages

xen, xen-3.0, xen-3.1, xen-3.2, xen-3.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
xen
xen-3.0
xen-3.1
xen-3.2
xen-3.3
Show less packages

CVE-2008-1944

Low priority
Ignored

Buffer overflow in the backend framebuffer of XenSource Xen Para-Virtualized Framebuffer (PVFB) Message 3.0 through 3.0.3 allows local users to cause a denial of service (SDL crash) and possibly execute arbitrary code via "bogus...

7 affected packages

kvm, qemu, qemu-kvm, xen-3.0, xen-3.1...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
kvm
qemu
qemu-kvm
xen-3.0
xen-3.1
xen-3.2
xen-3.3
Show all 7 packages Show less packages