Oracle

Vm Server

27 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 27.06.2016 10:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a craft...

  • EPSS 1.2%
  • Veröffentlicht 09.06.2016 16:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.

Exploit
  • EPSS 3.33%
  • Veröffentlicht 09.06.2016 16:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName.

  • EPSS 0.09%
  • Veröffentlicht 07.06.2016 14:06:15
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The libxl device-handling in Xen 4.6.x and earlier allows local OS guest administrators to cause a denial of service (resource consumption or management facility confusion) or gain host OS privileges by manipulating information in guest controlled ar...

  • EPSS 0.17%
  • Veröffentlicht 18.05.2016 14:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS users to gain privileges via a c...

  • EPSS 0.12%
  • Veröffentlicht 11.05.2016 21:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.

  • EPSS 0.77%
  • Veröffentlicht 02.05.2016 10:59:27
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c in the Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which allows remote attackers to obtain sensitive information from kernel memory by reading packet data.

  • EPSS 0.08%
  • Veröffentlicht 19.04.2016 14:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the x86 shadow pagetable code in Xen allows local guest OS users to cause a denial of service (host crash) or possibly gain privileges by shadowing a superpage mapping.

  • EPSS 0.04%
  • Veröffentlicht 13.04.2016 16:59:19
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest ...

  • EPSS 0.04%
  • Veröffentlicht 13.04.2016 16:59:18
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by ...