rpm package
opensuse/xen&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/xen&distro=openSUSE%20Tumbleweed
Vulnerabilities (291)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2012-4537 | — | < 4.7.0_12-1.3 | 4.7.0_12-1.3 | Nov 21, 2012 | Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchronize the p2m and m2p tables when the set_p2m_entry function fails, which allows local HVM guest OS administrators to cause a denial of service (memory consumption and assertion failure), aka "Memory mapp | ||
| CVE-2012-4536 | — | < 4.7.0_12-1.3 | 4.7.0_12-1.3 | Nov 21, 2012 | The (1) domain_pirq_to_emuirq and (2) physdev_unmap_pirq functions in Xen 2.2 allows local guest OS administrators to cause a denial of service (Xen crash) via a crafted pirq value that triggers an out-of-bounds read. | ||
| CVE-2012-4535 | — | < 4.7.0_12-1.3 | 4.7.0_12-1.3 | Nov 21, 2012 | Xen 3.4 through 4.2, and possibly earlier versions, allows local guest OS administrators to cause a denial of service (Xen infinite loop and physical CPU consumption) by setting a VCPU with an "inappropriate deadline." | ||
| CVE-2012-4544 | — | < 4.7.0_12-1.3 | 4.7.0_12-1.3 | Oct 31, 2012 | The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk. | ||
| CVE-2012-2625 | — | < 4.7.0_12-1.3 | 4.7.0_12-1.3 | Oct 31, 2012 | The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2.x, and 4.1.x allows local para-virtualized guest users to cause a denial of service (memory consumption) via a large (1) bzip2 or (2) lzma compressed kernel image. | ||
| CVE-2012-0217 | — | < 4.7.0_12-1.3 | 4.7.0_12-1.3 | Jun 12, 2012 | The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and | ||
| CVE-2012-0029 | — | < 4.7.0_12-1.3 | 4.7.0_12-1.3 | Jan 27, 2012 | Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000.c) in qemu-kvm 0.12, and possibly other versions, allows guest OS users to cause a denial of service (QEMU crash) and possibly execute arbitrary code via crafted legacy mode packets. | ||
| CVE-2011-1898 | — | < 4.7.0_12-1.3 | 4.7.0_12-1.3 | Aug 12, 2011 | Xen 4.1 before 4.1.1 and 4.0 before 4.0.2, when using PCI passthrough on Intel VT-d chipsets that do not have interrupt remapping, allows guest OS users to gain host OS privileges by "using DMA to generate MSI interrupts by writing to the interrupt injection registers." | ||
| CVE-2007-3919 | — | < 4.15.1_01-1.2 | 4.15.1_01-1.2 | Oct 28, 2007 | (1) xenbaked and (2) xenmon.py in Xen 3.1 and earlier allow local users to truncate arbitrary files via a symlink attack on /tmp/xenq-shm. | ||
| CVE-2007-1366 | — | < 4.15.1_01-1.2 | 4.15.1_01-1.2 | May 2, 2007 | QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand to the aam instruction, as demonstrated by "aam 0x0," which triggers a divide-by-zero error. | ||
| CVE-2007-1320 | — | < 4.15.1_01-1.2 | 4.15.1_01-1.2 | May 2, 2007 | Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark non-existe |
- CVE-2012-4537Nov 21, 2012affected < 4.7.0_12-1.3fixed 4.7.0_12-1.3
Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchronize the p2m and m2p tables when the set_p2m_entry function fails, which allows local HVM guest OS administrators to cause a denial of service (memory consumption and assertion failure), aka "Memory mapp
- CVE-2012-4536Nov 21, 2012affected < 4.7.0_12-1.3fixed 4.7.0_12-1.3
The (1) domain_pirq_to_emuirq and (2) physdev_unmap_pirq functions in Xen 2.2 allows local guest OS administrators to cause a denial of service (Xen crash) via a crafted pirq value that triggers an out-of-bounds read.
- CVE-2012-4535Nov 21, 2012affected < 4.7.0_12-1.3fixed 4.7.0_12-1.3
Xen 3.4 through 4.2, and possibly earlier versions, allows local guest OS administrators to cause a denial of service (Xen infinite loop and physical CPU consumption) by setting a VCPU with an "inappropriate deadline."
- CVE-2012-4544Oct 31, 2012affected < 4.7.0_12-1.3fixed 4.7.0_12-1.3
The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.
- CVE-2012-2625Oct 31, 2012affected < 4.7.0_12-1.3fixed 4.7.0_12-1.3
The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2.x, and 4.1.x allows local para-virtualized guest users to cause a denial of service (memory consumption) via a large (1) bzip2 or (2) lzma compressed kernel image.
- CVE-2012-0217Jun 12, 2012affected < 4.7.0_12-1.3fixed 4.7.0_12-1.3
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and
- CVE-2012-0029Jan 27, 2012affected < 4.7.0_12-1.3fixed 4.7.0_12-1.3
Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000.c) in qemu-kvm 0.12, and possibly other versions, allows guest OS users to cause a denial of service (QEMU crash) and possibly execute arbitrary code via crafted legacy mode packets.
- CVE-2011-1898Aug 12, 2011affected < 4.7.0_12-1.3fixed 4.7.0_12-1.3
Xen 4.1 before 4.1.1 and 4.0 before 4.0.2, when using PCI passthrough on Intel VT-d chipsets that do not have interrupt remapping, allows guest OS users to gain host OS privileges by "using DMA to generate MSI interrupts by writing to the interrupt injection registers."
- CVE-2007-3919Oct 28, 2007affected < 4.15.1_01-1.2fixed 4.15.1_01-1.2
(1) xenbaked and (2) xenmon.py in Xen 3.1 and earlier allow local users to truncate arbitrary files via a symlink attack on /tmp/xenq-shm.
- CVE-2007-1366May 2, 2007affected < 4.15.1_01-1.2fixed 4.15.1_01-1.2
QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand to the aam instruction, as demonstrated by "aam 0x0," which triggers a divide-by-zero error.
- CVE-2007-1320May 2, 2007affected < 4.15.1_01-1.2fixed 4.15.1_01-1.2
Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark non-existe
Page 15 of 15