Show filters
605 Total Results
Displaying 161-170 of 605
Sort by:
Attacker Value
Unknown
CVE-2020-29568
Disclosure Date: December 15, 2020 (last updated February 22, 2025)
An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If the events are received faster than the thread is able to handle, they will get queued. As the queue is unbounded, a guest may be able to trigger an OOM in the backend. All systems with a FreeBSD, Linux, or NetBSD (any version) dom0 are vulnerable.
0
Attacker Value
Unknown
CVE-2020-29567
Disclosure Date: December 15, 2020 (last updated February 22, 2025)
An issue was discovered in Xen 4.14.x. When moving IRQs between CPUs to distribute the load of IRQ handling, IRQ vectors are dynamically allocated and de-allocated on the relevant CPUs. De-allocation has to happen when certain constraints are met. If these conditions are not met when first checked, the checking CPU may send an interrupt to itself, in the expectation that this IRQ will be delivered only after the condition preventing the cleanup has cleared. For two specific IRQ vectors, this expectation was violated, resulting in a continuous stream of self-interrupts, which renders the CPU effectively unusable. A domain with a passed through PCI device can cause lockup of a physical CPU, resulting in a Denial of Service (DoS) to the entire host. Only x86 systems are vulnerable. Arm systems are not vulnerable. Only guests with physical PCI devices passed through to them can exploit the vulnerability.
0
Attacker Value
Unknown
CVE-2020-8283
Disclosure Date: December 14, 2020 (last updated February 22, 2025)
An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9.
0
Attacker Value
Unknown
CVE-2020-29040
Disclosure Date: November 24, 2020 (last updated February 22, 2025)
An issue was discovered in Xen through 4.14.x allowing x86 HVM guest OS users to cause a denial of service (stack corruption), cause a data leak, or possibly gain privileges because of an off-by-one error. NOTE: this issue is caused by an incorrect fix for CVE-2020-27671.
0
Attacker Value
Unknown
CVE-2020-8269
Disclosure Date: November 16, 2020 (last updated February 22, 2025)
An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9
0
Attacker Value
Unknown
CVE-2020-28368
Disclosure Date: November 10, 2020 (last updated February 22, 2025)
Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the access control for each such interface in Xen.
0
Attacker Value
Unknown
CVE-2020-27673
Disclosure Date: October 22, 2020 (last updated November 28, 2024)
An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. Guest OS users can cause a denial of service (host OS hang) via a high rate of events to dom0, aka CID-e99502f76271.
0
Attacker Value
Unknown
CVE-2020-27671
Disclosure Date: October 22, 2020 (last updated November 08, 2023)
An issue was discovered in Xen through 4.14.x allowing x86 HVM and PVH guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because coalescing of per-page IOMMU TLB flushes is mishandled.
0
Attacker Value
Unknown
CVE-2020-27674
Disclosure Date: October 22, 2020 (last updated February 22, 2025)
An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents, because invalidation of TLB entries is mishandled during use of an INVLPG-like attack technique.
0
Attacker Value
Unknown
CVE-2020-27670
Disclosure Date: October 22, 2020 (last updated February 22, 2025)
An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because an AMD IOMMU page-table entry can be half-updated.
0