rpm package
suse/xen&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP1
pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1
Vulnerabilities (234)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-12067 | — | < 4.5.5_28-22.64.1 | 4.5.5_28-22.64.1 | Jun 2, 2021 | The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null. | ||
| CVE-2015-6815 | — | < 4.5.2_02-4.1 | 4.5.2_02-4.1 | Jan 31, 2020 | The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors. | ||
| CVE-2015-5239 | — | < 4.5.2_02-4.1 | 4.5.2_02-4.1 | Jan 23, 2020 | Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop. | ||
| CVE-2015-5278 | — | < 4.5.2_06-7.1 | 4.5.2_06-7.1 | Jan 23, 2020 | The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets. | ||
| CVE-2020-7211 | — | < 4.5.5_28-22.64.1 | 4.5.5_28-22.64.1 | Jan 21, 2020 | tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows. | ||
| CVE-2019-19577 | — | < 4.5.5_28-22.64.1 | 4.5.5_28-22.64.1 | Dec 11, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 AMD HVM guest OS users to cause a denial of service or possibly gain privileges by triggering data-structure access during pagetable-height updates. When running on AMD systems with an IOMMU, Xen attempted to dynamically | ||
| CVE-2019-19578 | — | < 4.5.5_28-22.64.1 | 4.5.5_28-22.64.1 | Dec 11, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via degenerate chains of linear pagetables, because of an incorrect fix for CVE-2017-15595. "Linear pagetables" is a technique which involves either pointing a pagetable at i | ||
| CVE-2019-19580 | — | < 4.5.5_28-22.64.1 | 4.5.5_28-22.64.1 | Dec 11, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations, because of an incomplete fix for CVE-2019-18421. XSA-299 addressed several critical issues in rest | ||
| CVE-2019-19581 | — | < 4.5.5_28-22.64.1 | 4.5.5_28-22.64.1 | Dec 11, 2019 | An issue was discovered in Xen through 4.12.x allowing 32-bit Arm guest OS users to cause a denial of service (out-of-bounds access) because certain bit iteration is mishandled. In a number of places bitmaps are being used by the hypervisor to track certain state. Iteration over | ||
| CVE-2019-19583 | — | < 4.5.5_28-22.64.1 | 4.5.5_28-22.64.1 | Dec 11, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial of service (guest OS crash) because VMX VMEntry checks mishandle a certain case. Please see XSA-260 for background on the MovSS shadow. Please see XSA-156 for background on the nee | ||
| CVE-2019-19579 | — | < 4.5.5_28-22.64.1 | 4.5.5_28-22.64.1 | Dec 4, 2019 | An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device (and assignable-add is not used), because of an incomplete fix for CVE-2019-18424. XSA-302 relies on the us | ||
| CVE-2018-12207 | — | < 4.5.5_28-22.64.1 | 4.5.5_28-22.64.1 | Nov 14, 2019 | Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access. | ||
| CVE-2019-11135 | — | < 4.5.5_28-22.64.1 | 4.5.5_28-22.64.1 | Nov 14, 2019 | TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. | ||
| CVE-2019-18425 | — | < 4.5.5_28-22.64.1 | 4.5.5_28-22.64.1 | Oct 31, 2019 | An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. There is missing descriptor table limit checking in x86 PV emulation. When emulating certain PV guest operations, descriptor table acce | ||
| CVE-2019-18424 | — | < 4.5.5_28-22.64.1 | 4.5.5_28-22.64.1 | Oct 31, 2019 | An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passed through PCI devices may corrupt host memory after deassignment. When a PCI devi | ||
| CVE-2019-18421 | — | < 4.5.5_28-22.64.1 | 4.5.5_28-22.64.1 | Oct 31, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations. There are issues with restartable PV type change operations. To avoid using shadow pagetables for | ||
| CVE-2019-18420 | — | < 4.5.5_28-22.64.1 | 4.5.5_28-22.64.1 | Oct 31, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via a VCPUOP_initialise hypercall. hypercall_create_continuation() is a variadic function which uses a printf-like format string to interpret its parameters. Error handling f | ||
| CVE-2019-17340 | — | < 4.5.5_28-22.64.1 | 4.5.5_28-22.64.1 | Oct 8, 2019 | An issue was discovered in Xen through 4.11.x allowing x86 guest OS users to cause a denial of service or gain privileges because grant-table transfer requests are mishandled. | ||
| CVE-2019-17341 | — | < 4.5.5_28-22.64.1 | 4.5.5_28-22.64.1 | Oct 8, 2019 | An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a page-writability race condition during addition of a passed-through PCI device. | ||
| CVE-2019-17342 | — | < 4.5.5_28-22.64.1 | 4.5.5_28-22.64.1 | Oct 8, 2019 | An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a race condition that arose when XENMEM_exchange was introduced. |
- CVE-2019-12067Jun 2, 2021affected < 4.5.5_28-22.64.1fixed 4.5.5_28-22.64.1
The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null.
- CVE-2015-6815Jan 31, 2020affected < 4.5.2_02-4.1fixed 4.5.2_02-4.1
The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors.
- CVE-2015-5239Jan 23, 2020affected < 4.5.2_02-4.1fixed 4.5.2_02-4.1
Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.
- CVE-2015-5278Jan 23, 2020affected < 4.5.2_06-7.1fixed 4.5.2_06-7.1
The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets.
- CVE-2020-7211Jan 21, 2020affected < 4.5.5_28-22.64.1fixed 4.5.5_28-22.64.1
tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows.
- CVE-2019-19577Dec 11, 2019affected < 4.5.5_28-22.64.1fixed 4.5.5_28-22.64.1
An issue was discovered in Xen through 4.12.x allowing x86 AMD HVM guest OS users to cause a denial of service or possibly gain privileges by triggering data-structure access during pagetable-height updates. When running on AMD systems with an IOMMU, Xen attempted to dynamically
- CVE-2019-19578Dec 11, 2019affected < 4.5.5_28-22.64.1fixed 4.5.5_28-22.64.1
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via degenerate chains of linear pagetables, because of an incorrect fix for CVE-2017-15595. "Linear pagetables" is a technique which involves either pointing a pagetable at i
- CVE-2019-19580Dec 11, 2019affected < 4.5.5_28-22.64.1fixed 4.5.5_28-22.64.1
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations, because of an incomplete fix for CVE-2019-18421. XSA-299 addressed several critical issues in rest
- CVE-2019-19581Dec 11, 2019affected < 4.5.5_28-22.64.1fixed 4.5.5_28-22.64.1
An issue was discovered in Xen through 4.12.x allowing 32-bit Arm guest OS users to cause a denial of service (out-of-bounds access) because certain bit iteration is mishandled. In a number of places bitmaps are being used by the hypervisor to track certain state. Iteration over
- CVE-2019-19583Dec 11, 2019affected < 4.5.5_28-22.64.1fixed 4.5.5_28-22.64.1
An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial of service (guest OS crash) because VMX VMEntry checks mishandle a certain case. Please see XSA-260 for background on the MovSS shadow. Please see XSA-156 for background on the nee
- CVE-2019-19579Dec 4, 2019affected < 4.5.5_28-22.64.1fixed 4.5.5_28-22.64.1
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device (and assignable-add is not used), because of an incomplete fix for CVE-2019-18424. XSA-302 relies on the us
- CVE-2018-12207Nov 14, 2019affected < 4.5.5_28-22.64.1fixed 4.5.5_28-22.64.1
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
- CVE-2019-11135Nov 14, 2019affected < 4.5.5_28-22.64.1fixed 4.5.5_28-22.64.1
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
- CVE-2019-18425Oct 31, 2019affected < 4.5.5_28-22.64.1fixed 4.5.5_28-22.64.1
An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. There is missing descriptor table limit checking in x86 PV emulation. When emulating certain PV guest operations, descriptor table acce
- CVE-2019-18424Oct 31, 2019affected < 4.5.5_28-22.64.1fixed 4.5.5_28-22.64.1
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passed through PCI devices may corrupt host memory after deassignment. When a PCI devi
- CVE-2019-18421Oct 31, 2019affected < 4.5.5_28-22.64.1fixed 4.5.5_28-22.64.1
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations. There are issues with restartable PV type change operations. To avoid using shadow pagetables for
- CVE-2019-18420Oct 31, 2019affected < 4.5.5_28-22.64.1fixed 4.5.5_28-22.64.1
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via a VCPUOP_initialise hypercall. hypercall_create_continuation() is a variadic function which uses a printf-like format string to interpret its parameters. Error handling f
- CVE-2019-17340Oct 8, 2019affected < 4.5.5_28-22.64.1fixed 4.5.5_28-22.64.1
An issue was discovered in Xen through 4.11.x allowing x86 guest OS users to cause a denial of service or gain privileges because grant-table transfer requests are mishandled.
- CVE-2019-17341Oct 8, 2019affected < 4.5.5_28-22.64.1fixed 4.5.5_28-22.64.1
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a page-writability race condition during addition of a passed-through PCI device.
- CVE-2019-17342Oct 8, 2019affected < 4.5.5_28-22.64.1fixed 4.5.5_28-22.64.1
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a race condition that arose when XENMEM_exchange was introduced.
Page 1 of 12