Skip to main content

Vendor archive

xen CVEs

Beta · best-effort

495 CVEs tagged to vendor xen15 Critical, 162 High, 267 Medium, 51 Low, 0 Unrated.

CVE-2021-28694

Published Aug 27, 2021

IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Inte…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-28693

Published Jun 30, 2021

xen/arm: Boot modules are not scrubbed The bootloader will load boot modules (e.g. kernel, initramfs...) in a temporary area before they are copied by Xen to each domain memory. T…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28692

Published Jun 30, 2021

inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands. In the current impl…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-28690

Published Jun 29, 2021

x86: TSX Async Abort protections not restored after S3 This issue relates to the TSX Async Abort speculative security vulnerability. Please see https://xenbits.xen.org/xsa/advisor…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28689

Published Jun 11, 2021

x86: Speculative vulnerabilities with bare (non-shim) 32-bit PV guests 32-bit x86 PV guest kernels run in ring 1. At the time when Xen was developed, this area of the i386 archite…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28687

Published Jun 11, 2021

HVM soft-reset crashes toolstack libxl requires all data structures passed across its public interface to be initialized before use and disposed of afterwards by calling a specifi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26314

Published Jun 9, 2021

Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating poin…

CVSS 5.5 · Medium

CVE-2021-26313

Published Jun 9, 2021

Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions,…

CVSS 5.5 · Medium

CVE-2021-27379

Published Feb 18, 2021

An issue was discovered in Xen through 4.11.x, allowing x86 Intel HVM guest OS users to achieve unintended read/write DMA access, and possibly cause a denial of service (host OS c…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3308

Published Jan 26, 2021

An issue was discovered in Xen 4.12.3 through 4.12.4 and 4.13.1 through 4.14.x. An x86 HVM guest with PCI pass through devices can force the allocation of all IDT vectors on the s…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29487

Published Dec 15, 2020

An issue was discovered in Xen XAPI before 2020-12-15. Certain xenstore keys provide feedback from the guest, and are therefore watched by toolstack. Specifically, keys are watche…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 126-150 of 495 CVEsPage 6 of 20