Show filters
555 Total Results
Displaying 261-270 of 555
Sort by:
Attacker Value
Unknown
CVE-2017-17564
Disclosure Date: December 12, 2017 (last updated November 26, 2024)
An issue was discovered in Xen through 4.9.x allowing guest OS users to cause a denial of service (host OS crash) or gain host OS privileges by leveraging incorrect error handling for reference counting in shadow mode.
0
Attacker Value
Unknown
CVE-2017-17563
Disclosure Date: December 12, 2017 (last updated November 26, 2024)
An issue was discovered in Xen through 4.9.x allowing guest OS users to cause a denial of service (host OS crash) or gain host OS privileges by leveraging an incorrect mask for reference-count overflow checking in shadow mode.
0
Attacker Value
Unknown
CVE-2017-17099
Disclosure Date: December 03, 2017 (last updated November 26, 2024)
There exists an unauthenticated SEH based Buffer Overflow vulnerability in the HTTP server of Flexense SyncBreeze Enterprise v10.1.16. When sending a GET request with an excessive length, it is possible for a malicious user to overwrite the SEH record and execute a payload that would run under the Windows SYSTEM account.
0
Attacker Value
Unknown
CVE-2017-17045
Disclosure Date: November 28, 2017 (last updated November 26, 2024)
An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to gain privileges on the host OS, obtain sensitive information, or cause a denial of service (BUG and host OS crash) by leveraging the mishandling of Populate on Demand (PoD) Physical-to-Machine (P2M) errors.
0
Attacker Value
Unknown
CVE-2017-17044
Disclosure Date: November 28, 2017 (last updated November 26, 2024)
An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to cause a denial of service (infinite loop and host OS hang) by leveraging the mishandling of Populate on Demand (PoD) errors.
0
Attacker Value
Unknown
CVE-2017-17046
Disclosure Date: November 28, 2017 (last updated November 26, 2024)
An issue was discovered in Xen through 4.9.x on the ARM platform allowing guest OS users to obtain sensitive information from DRAM after a reboot, because disjoint blocks, and physical addresses that do not start at zero, are mishandled.
0
Attacker Value
Unknown
CVE-2017-15950
Disclosure Date: October 31, 2017 (last updated November 26, 2024)
Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary code execution. The flaw is triggered by providing a long input into the "Destination directory" field, either within an XML document or through use of passive mode.
0
Attacker Value
Unknown
CVE-2017-15597
Disclosure Date: October 30, 2017 (last updated November 26, 2024)
An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference. Other portions of code, however, did not match up with that assumption. When such a grant copy operation is being done on a grant of a dying domain, the assumption turns out wrong. A malicious guest administrator can cause hypervisor memory corruption, most likely resulting in host crash and a Denial of Service. Privilege escalation and information leaks cannot be ruled out.
0
Attacker Value
Unknown
CVE-2017-15596
Disclosure Date: October 18, 2017 (last updated November 26, 2024)
An issue was discovered in Xen 4.4.x through 4.9.x allowing ARM guest OS users to cause a denial of service (prevent physical CPU usage) because of lock mishandling upon detection of an add-to-physmap error.
0
Attacker Value
Unknown
CVE-2017-15589
Disclosure Date: October 18, 2017 (last updated November 26, 2024)
An issue was discovered in Xen through 4.9.x allowing x86 HVM guest OS users to obtain sensitive information from the host OS (or an arbitrary guest OS) because intercepted I/O operations can cause a write of data from uninitialized hypervisor stack memory.
0