rpm package
suse/xen&distro=SUSE Linux Enterprise Desktop 11 SP4
pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP4
Vulnerabilities (65)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2015-6855 | Hig | 7.5 | < 4.4.4_02-32.1 | 4.4.4_02-32.1 | Nov 6, 2015 | hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, | |
| CVE-2015-7972 | — | < 4.4.3_06-29.1 | 4.4.3_06-29.1 | Oct 30, 2015 | The (1) libxl_set_memory_target function in tools/libxl/libxl.c and (2) libxl__build_post function in tools/libxl/libxl_dom.c in Xen 3.4.x through 4.6.x do not properly calculate the balloon size when using the populate-on-demand (PoD) system, which allows local HVM guest users t | ||
| CVE-2015-7971 | — | < 4.4.3_02-26.2 | 4.4.3_02-26.2 | Oct 30, 2015 | Xen 3.2.x through 4.6.x does not limit the number of printk console messages when logging certain pmu and profiling hypercalls, which allows local guests to cause a denial of service via a sequence of crafted (1) HYPERCALL_xenoprof_op hypercalls, which are not properly handled in | ||
| CVE-2015-7970 | — | < 4.4.3_06-29.1 | 4.4.3_06-29.1 | Oct 30, 2015 | The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x, 3.5.x, and 3.6.x is not preemptible, which allows local x86 HVM guest administrators to cause a denial of service (CPU consumption and possibly reboot) via crafted memory contents that triggers a "time-co | ||
| CVE-2015-7969 | — | < 4.4.3_02-26.2 | 4.4.3_02-26.2 | Oct 30, 2015 | Multiple memory leaks in Xen 4.0 through 4.6.x allow local guest administrators or domains with certain permission to cause a denial of service (memory consumption) via a large number of "teardowns" of domains with the vcpu pointer array allocated using the (1) XEN_DOMCTL_max_vcp | ||
| CVE-2015-7835 | — | < 4.4.3_02-26.2 | 4.4.3_02-26.2 | Oct 30, 2015 | The mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not properly validate level 2 page table entries, which allows local PV guest administrators to gain privileges via a crafted superpage mapping. | ||
| CVE-2015-7311 | — | < 4.4.3_02-26.2 | 4.4.3_02-26.2 | Oct 1, 2015 | libxl in Xen 4.1.x through 4.6.x does not properly handle the readonly flag on disks when using the qemu-xen device model, which allows local guest users to write to a read-only disk image. | ||
| CVE-2015-4037 | — | < 4.4.3_02-26.2 | 4.4.3_02-26.2 | Aug 26, 2015 | The slirp_smb function in net/slirp.c in QEMU 2.3.0 and earlier creates temporary files with predictable names, which allows local users to cause a denial of service (instantiation failure) by creating /tmp/qemu-smb.*-* files before the program. | ||
| CVE-2015-5166 | — | < 4.4.2_12-23.1 | 4.4.2_12-23.1 | Aug 12, 2015 | Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completely unplug emulated block devices, which allows local HVM guest users to gain privileges by unplugging a block device twice. | ||
| CVE-2015-5165 | — | < 4.4.2_12-23.1 | 4.4.2_12-23.1 | Aug 12, 2015 | The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors. | ||
| CVE-2015-5154 | — | < 4.4.2_10-5.1 | 4.4.2_10-5.1 | Aug 12, 2015 | Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, allows local guest users to execute arbitrary code on the host via unspecified ATAPI commands. | ||
| CVE-2015-3259 | — | < 4.4.2_10-5.1 | 4.4.2_10-5.1 | Jul 16, 2015 | Stack-based buffer overflow in the xl command line utility in Xen 4.1.x through 4.5.x allows local guest administrators to gain privileges via a long configuration argument. | ||
| CVE-2014-9718 | — | < 4.4.4_02-32.1 | 4.4.4_02-32.1 | Apr 21, 2015 | The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have multiple interpretations of a function's return value, which allows guest OS users to cause a host OS denial of service (memory consumption or infinite loop, and system crash) via a | ||
| CVE-2014-7815 | — | < 4.4.4_02-32.1 | 4.4.4_02-32.1 | Nov 14, 2014 | The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value. | ||
| CVE-2014-3689 | — | < 4.4.4_02-32.1 | 4.4.4_02-32.1 | Nov 14, 2014 | The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecified parameters related to rectangle handling. | ||
| CVE-2014-3640 | — | < 4.4.4_02-32.1 | 4.4.4_02-32.1 | Nov 7, 2014 | The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized socket. | ||
| CVE-2014-0222 | — | < 4.4.3_02-26.2 | 4.4.3_02-26.2 | Nov 4, 2014 | Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service (crash) via a large L2 table in a QCOW version 1 image. | ||
| CVE-2013-4539 | — | < 4.4.4_02-32.1 | 4.4.4_02-32.1 | Nov 4, 2014 | Multiple buffer overflows in the tsc210x_load function in hw/input/tsc210x.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted (1) precision, (2) nextprecision, (3) function, or (4) nextfunction value in a savevm image. | ||
| CVE-2013-4538 | — | < 4.4.4_02-32.1 | 4.4.4_02-32.1 | Nov 4, 2014 | Multiple buffer overflows in the ssd0323_load function in hw/display/ssd0323.c in QEMU before 1.7.2 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted (1) cmd_len, (2) row, or (3) col values; (4) row_start and ro | ||
| CVE-2013-4537 | — | < 4.4.4_02-32.1 | 4.4.4_02-32.1 | Nov 4, 2014 | The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a savevm image. |
- affected < 4.4.4_02-32.1fixed 4.4.4_02-32.1
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive,
- CVE-2015-7972Oct 30, 2015affected < 4.4.3_06-29.1fixed 4.4.3_06-29.1
The (1) libxl_set_memory_target function in tools/libxl/libxl.c and (2) libxl__build_post function in tools/libxl/libxl_dom.c in Xen 3.4.x through 4.6.x do not properly calculate the balloon size when using the populate-on-demand (PoD) system, which allows local HVM guest users t
- CVE-2015-7971Oct 30, 2015affected < 4.4.3_02-26.2fixed 4.4.3_02-26.2
Xen 3.2.x through 4.6.x does not limit the number of printk console messages when logging certain pmu and profiling hypercalls, which allows local guests to cause a denial of service via a sequence of crafted (1) HYPERCALL_xenoprof_op hypercalls, which are not properly handled in
- CVE-2015-7970Oct 30, 2015affected < 4.4.3_06-29.1fixed 4.4.3_06-29.1
The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x, 3.5.x, and 3.6.x is not preemptible, which allows local x86 HVM guest administrators to cause a denial of service (CPU consumption and possibly reboot) via crafted memory contents that triggers a "time-co
- CVE-2015-7969Oct 30, 2015affected < 4.4.3_02-26.2fixed 4.4.3_02-26.2
Multiple memory leaks in Xen 4.0 through 4.6.x allow local guest administrators or domains with certain permission to cause a denial of service (memory consumption) via a large number of "teardowns" of domains with the vcpu pointer array allocated using the (1) XEN_DOMCTL_max_vcp
- CVE-2015-7835Oct 30, 2015affected < 4.4.3_02-26.2fixed 4.4.3_02-26.2
The mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not properly validate level 2 page table entries, which allows local PV guest administrators to gain privileges via a crafted superpage mapping.
- CVE-2015-7311Oct 1, 2015affected < 4.4.3_02-26.2fixed 4.4.3_02-26.2
libxl in Xen 4.1.x through 4.6.x does not properly handle the readonly flag on disks when using the qemu-xen device model, which allows local guest users to write to a read-only disk image.
- CVE-2015-4037Aug 26, 2015affected < 4.4.3_02-26.2fixed 4.4.3_02-26.2
The slirp_smb function in net/slirp.c in QEMU 2.3.0 and earlier creates temporary files with predictable names, which allows local users to cause a denial of service (instantiation failure) by creating /tmp/qemu-smb.*-* files before the program.
- CVE-2015-5166Aug 12, 2015affected < 4.4.2_12-23.1fixed 4.4.2_12-23.1
Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completely unplug emulated block devices, which allows local HVM guest users to gain privileges by unplugging a block device twice.
- CVE-2015-5165Aug 12, 2015affected < 4.4.2_12-23.1fixed 4.4.2_12-23.1
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
- CVE-2015-5154Aug 12, 2015affected < 4.4.2_10-5.1fixed 4.4.2_10-5.1
Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, allows local guest users to execute arbitrary code on the host via unspecified ATAPI commands.
- CVE-2015-3259Jul 16, 2015affected < 4.4.2_10-5.1fixed 4.4.2_10-5.1
Stack-based buffer overflow in the xl command line utility in Xen 4.1.x through 4.5.x allows local guest administrators to gain privileges via a long configuration argument.
- CVE-2014-9718Apr 21, 2015affected < 4.4.4_02-32.1fixed 4.4.4_02-32.1
The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have multiple interpretations of a function's return value, which allows guest OS users to cause a host OS denial of service (memory consumption or infinite loop, and system crash) via a
- CVE-2014-7815Nov 14, 2014affected < 4.4.4_02-32.1fixed 4.4.4_02-32.1
The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value.
- CVE-2014-3689Nov 14, 2014affected < 4.4.4_02-32.1fixed 4.4.4_02-32.1
The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecified parameters related to rectangle handling.
- CVE-2014-3640Nov 7, 2014affected < 4.4.4_02-32.1fixed 4.4.4_02-32.1
The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized socket.
- CVE-2014-0222Nov 4, 2014affected < 4.4.3_02-26.2fixed 4.4.3_02-26.2
Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service (crash) via a large L2 table in a QCOW version 1 image.
- CVE-2013-4539Nov 4, 2014affected < 4.4.4_02-32.1fixed 4.4.4_02-32.1
Multiple buffer overflows in the tsc210x_load function in hw/input/tsc210x.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted (1) precision, (2) nextprecision, (3) function, or (4) nextfunction value in a savevm image.
- CVE-2013-4538Nov 4, 2014affected < 4.4.4_02-32.1fixed 4.4.4_02-32.1
Multiple buffer overflows in the ssd0323_load function in hw/display/ssd0323.c in QEMU before 1.7.2 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted (1) cmd_len, (2) row, or (3) col values; (4) row_start and ro
- CVE-2013-4537Nov 4, 2014affected < 4.4.4_02-32.1fixed 4.4.4_02-32.1
The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a savevm image.
Page 3 of 4