Xen
Vendor:
First CVE: Oct 3, 2008 · Active for 17 years
9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Xen over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 3, 2008
17 years ago
Most Recent CVE
Aug 19, 2011
5,454 days ago
CVE Severity & Scoring
Xen9 CVEs
22%
44%
33%
All CVEs352,427 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown9 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown9 (100.0%)
User Interaction
None0 (0.0%)
Unknown9 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown9 (100.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4405HIGH xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM's write access within this tree, whic | Oct 3, 2008 | 7.2 | 27 | NO | YES |
CVE-2011-1898HIGH Xen 4.1 before 4.1.1 and 4.0 before 4.0.2, when using PCI passthrough on Intel VT-d chipsets that do not have interrupt remapping, allows guest OS users to gain host OS privileges | Aug 12, 2011 | 7.4 | 25 | NO | NO |
CVE-2011-1583MEDIUM Multiple integer overflows in tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allow local users to cause a denial of service and possibly execute arbitrary code vi | Aug 12, 2011 | 6.9 | 22 | NO | NO |
CVE-2008-5716HIGH xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service an | Dec 24, 2008 | 7.2 | 20 | NO | NO |
CVE-2010-4255MEDIUM The fixup_page_fault function in arch/x86/traps.c in Xen 4.0.1 and earlier on 64-bit platforms, when paravirtualization is enabled, does not verify that kernel mode is used to call | Jan 25, 2011 | 6.1 | 19 | NO | NO |
CVE-2010-4238MEDIUM The vbd_create function in Xen 3.1.2, when the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 is used, allows guest OS users to cause a denial of service (host OS panic) | Jan 22, 2011 | 5.5 | 19 | NO | NO |
CVE-2010-4247MEDIUM The do_block_io_op function in (1) drivers/xen/blkback/blkback.c and (2) drivers/xen/blktap/blktap.c in Xen before 3.4.0 for the Linux kernel 2.6.18, and possibly other versions, a | Jan 11, 2011 | 5.5 | 17 | NO | NO |
The backend driver in Xen 3.x allows guest OS users to cause a denial of service via a kernel thread leak, which prevents the device and guest OS from being shut down or create a z | Dec 8, 2010 | 2.7 | 14 | NO | NO |
tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allows local users to cause a denial of service (management software infinite loop and management domain resource c | Aug 19, 2011 | 2.1 | 13 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
11.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Xen
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.1.0 | 3 | 5.5 | 0.6% | 0 | 0 |
| 4.0.1 | 1 | 7.4 | 0.9% | 0 | 0 |
| 4.0.0 | 4 | 5.6 | 0.7% | 0 | 0 |
| 3.4.3 | 2 | 4.4 | 0.7% | 0 | 0 |
| 3.4.2 | 2 | 4.4 | 0.7% | 0 | 0 |
| 3.4.1 | 2 | 4.4 | 0.7% | 0 | 0 |
| 3.4.0 | 2 | 4.4 | 0.7% | 0 | 0 |
| 3.3.2 | 2 | 4.4 | 0.7% | 0 | 0 |
| 3.3.1 | 3 | 4.8 | 0.7% | 0 | 0 |
| 3.3.0 | 6 | 5.1 | 0.6% | 0 | 0 |
| 3.2.3 | 3 | 4.8 | 0.7% | 0 | 0 |
| 3.2.2 | 3 | 4.8 | 0.7% | 0 | 0 |
| 3.2.1 | 3 | 4.8 | 0.7% | 0 | 0 |
| 3.2.0 | 5 | 4.7 | 0.7% | 0 | 0 |
| 3.1.4 | 3 | 4.8 | 0.7% | 0 | 0 |
| 3.1.3 | 3 | 4.8 | 0.7% | 0 | 0 |
| 3.1.2 | 2 | 5.8 | 0.9% | 0 | 0 |
| 3.0.4 | 3 | 4.8 | 0.7% | 0 | 0 |
| 3.0.3 | 4 | 5.4 | 0.8% | 0 | 1 |
| 3.0.2 | 3 | 4.8 | 0.7% | 0 | 0 |