2.1
CVE-2007-6207
- EPSS 0.35%
- Veröffentlicht 04.12.2007 00:46:00
- Zuletzt bearbeitet 16.06.2026 22:47:36
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Xen 3.x, possibly before 3.1.2, when running on IA64 systems, does not check the RID value for mov_to_rr, which allows a VTi domain to read memory of other domains.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xensource Inc ≫ Xen Version <= 3.1.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.35% | 0.263 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://secunia.com/advisories/29236
http://www.redhat.com/support/errata/RHSA-2008-0154.html
http://lists.xensource.com/archives/html/xen-announce/2007-11/msg00000.html
http://lists.xensource.com/archives/html/xen-ia64-devel/2007-10/msg00189.html
http://osvdb.org/41341
http://secunia.com/advisories/27915
http://www.securityfocus.com/bid/26716
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9471