Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

1 – 10 of 21 results


CVE-2009-1758

Medium priority
Ignored

The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and probably other versions allows guest user applications to cause a denial of service (kernel oops) of the guest...

5 affected packages

xen, xen-3.0, xen-3.1, xen-3.2, xen-3.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
xen
xen-3.0
xen-3.1
xen-3.2
xen-3.3
Show less packages

CVE-2008-5716

Medium priority
Not affected

xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by...

6 affected packages

xen, xen-3.0, xen-3.1, xen-3.2, xen-3.3, xen-unstable

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
xen
xen-3.0
xen-3.1
xen-3.2
xen-3.3
xen-unstable
Show less packages

CVE-2008-5714

Medium priority

Some fixes available 2 of 19

Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote attackers to guess the VNC password, which is limited to seven characters where eight was intended.

8 affected packages

kvm, qemu, qemu-kvm, xen-3.0, xen-3.1...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
kvm
qemu
qemu-kvm
xen-3.0
xen-3.1
xen-3.2
xen-3.3
xen-unstable
Show all 8 packages Show less packages

CVE-2008-2382

Low priority

Some fixes available 2 of 8

The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote attackers to cause a denial of service (infinite loop) via a certain message.

8 affected packages

kvm, qemu, qemu-kvm, xen-3.0, xen-3.1...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
kvm
qemu
qemu-kvm
xen-3.0
xen-3.1
xen-3.2
xen-3.3
xen-unstable
Show all 8 packages Show less packages

CVE-2008-4993

Low priority
Ignored

qemu-dm.debug in Xen 3.2.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/args temporary file.

5 affected packages

xen, xen-3.0, xen-3.1, xen-3.2, xen-3.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
xen
xen-3.0
xen-3.1
xen-3.2
xen-3.3
Show less packages

CVE-2008-4405

Low priority
Ignored

xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM's write access within this tree, which allows guest OS users to cause a denial...

5 affected packages

xen, xen-3.0, xen-3.1, xen-3.2, xen-3.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
xen
xen-3.0
xen-3.1
xen-3.2
xen-3.3
Show less packages

CVE-2008-3687

Low priority
Not affected

Heap-based buffer overflow in the flask_security_label function in Xen 3.3, when compiled with the XSM:FLASK module, allows unprivileged domain users (domU) to execute arbitrary code via the flask_op hypercall.

4 affected packages

xen, xen-3.0, xen-3.1, xen-3.2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
xen
xen-3.0
xen-3.1
xen-3.2
Show less packages

CVE-2008-1945

Medium priority

Some fixes available 2 of 15

QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to...

7 affected packages

kvm, qemu, qemu-kvm, xen-3.0, xen-3.1...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
kvm
qemu
qemu-kvm
xen-3.0
xen-3.1
xen-3.2
xen-3.3
Show all 7 packages Show less packages

CVE-2008-1952

Medium priority
Ignored

The backend for XenSource Xen Para Virtualized Frame Buffer (PVFB) in Xen ioemu does not properly restrict the frame buffer size, which allows attackers to cause a denial of service (crash) by mapping an arbitrary amount of guest memory.

5 affected packages

xen, xen-3.0, xen-3.1, xen-3.2, xen-3.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
xen
xen-3.0
xen-3.1
xen-3.2
xen-3.3
Show less packages

CVE-2008-1944

Low priority
Ignored

Buffer overflow in the backend framebuffer of XenSource Xen Para-Virtualized Framebuffer (PVFB) Message 3.0 through 3.0.3 allows local users to cause a denial of service (SDL crash) and possibly execute arbitrary code via "bogus...

7 affected packages

kvm, qemu, qemu-kvm, xen-3.0, xen-3.1...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
kvm
qemu
qemu-kvm
xen-3.0
xen-3.1
xen-3.2
xen-3.3
Show all 7 packages Show less packages