XenSource develops the Xen hypervisor and related virtualization infrastructure, with a narrow product scope centered on the Xen para-virtualized frame buffer and core hypervisor platform. The observed vulnerability pattern reflects the low-level memory-management demands of virtualization code, concentrating on buffer-boundary handling and related memory-safety issues.
The number and severity of CVEs published that impact products developed by Xensource over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4993MEDIUM pygrub (tools/pygrub/src/GrubConf.py) in Xen 3.0.3, when booting a guest domain, allows local users with elevated privileges in the guest domain to execute arbitrary commands in do | Sep 27, 2007 | 6.9 | 26 | NO | YES |
CVE-2008-1944HIGH Buffer overflow in the backend framebuffer of XenSource Xen Para-Virtualized Framebuffer (PVFB) Message 3.0 through 3.0.3 allows local users to cause a denial of service (SDL crash | May 14, 2008 | 7.2 | 18 | NO | NO |
CVE-2010-2070MEDIUM arch/ia64/xen/faults.c in Xen 3.4 and 4.0 in Linux kernel 2.6.18, and possibly other kernel versions, when running on IA-64 architectures, allows local users to cause a denial of s | Jun 16, 2010 | 4.9 | 17 | NO | NO |
CVE-2007-3919MEDIUM (1) xenbaked and (2) xenmon.py in Xen 3.1 and earlier allow local users to truncate arbitrary files via a symlink attack on /tmp/xenq-shm. | Oct 28, 2007 | 6.0 | 16 | NO | NO |
CVE-2008-1619MEDIUM The ssm_i emulation in Xen 5.1 on IA64 architectures allows attackers to cause a denial of service (dom0 panic) via certain traffic, as demonstrated using an FTP stress test tool. | Apr 2, 2008 | 4.3 | 14 | NO | NO |
CVE-2007-5906MEDIUM Xen 3.1.1 allows virtual guest system users to cause a denial of service (hypervisor crash) by using a debug register (DR7) to set certain breakpoints. | Nov 9, 2007 | 4.7 | 14 | NO | NO |
CVE-2007-5907MEDIUM Xen 3.1.1 does not prevent modification of the CR4 TSC from applications, which allows pv guests to cause a denial of service (crash). | Nov 9, 2007 | 4.7 | 14 | NO | NO |
The backend for XenSource Xen Para Virtualized Frame Buffer (PVFB) in Xen ioemu does not properly restrict the frame buffer size, which allows attackers to cause a denial of servic | Jun 23, 2008 | 2.1 | 11 | NO | NO |
Buffer overflow in the backend of XenSource Xen Para Virtualized Frame Buffer (PVFB) 3.0 through 3.1.2 allows local users to cause a denial of service (crash) and possibly execute | May 14, 2008 | 2.1 | 11 | NO | NO |
Xen 3.x, possibly before 3.1.2, when running on IA64 systems, does not check the RID value for mov_to_rr, which allows a VTi domain to read memory of other domains. | Dec 4, 2007 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xensource.
Media articles that mention a CVE ID that affects a product developed by Xensource — matched by CVE ID, not by vendor name.