CVE-2018-3665
- EPSS 1.03%
- Veröffentlicht 21.06.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:05:51
System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.
CVE-2018-8897
- EPSS 23.21%
- Veröffentlicht 08.05.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:33
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that ...
CVE-2017-12137
- EPSS 0.1%
- Veröffentlicht 24.08.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.
CVE-2017-12136
- EPSS 0.05%
- Veröffentlicht 24.08.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling...
CVE-2017-12135
- EPSS 0.13%
- Veröffentlicht 24.08.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involving transitive grants.
CVE-2017-12134
- EPSS 0.29%
- Veröffentlicht 24.08.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streams and consequently obtain sensitive memory information, cause a denial of service, or gain host OS privileges ...
CVE-2015-7705
- EPSS 25%
- Veröffentlicht 07.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.
CVE-2015-7704
- EPSS 22.61%
- Veröffentlicht 07.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.
CVE-2016-9637
- EPSS 0.09%
- Veröffentlicht 17.02.2017 02:59:13
- Zuletzt bearbeitet 20.04.2025 01:37:25
The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS administrators to gain qemu process privileges via vectors involving an out-of-range ioport access.
CVE-2017-5573
- EPSS 0.39%
- Veröffentlicht 30.01.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated read-only administrator can cancel tasks of other administrators.