Xensource Inc's vulnerability profile centers on the Xen hypervisor, a foundational virtualization platform that despite its narrow product scope operates across a critical layer of enterprise and cloud infrastructure. The recurring weakness classes—improper input validation, link-following issues, and related parser and filesystem-access flaws—reflect the hypervisor's role in mediation between guest systems and shared hardware resources; these classes have a durable pattern of acquiring public exploit tooling. Defenders should treat Xen advisories as infrastructure-critical and prioritize patching in virtualized environments; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xensource Inc over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4993MEDIUM pygrub (tools/pygrub/src/GrubConf.py) in Xen 3.0.3, when booting a guest domain, allows local users with elevated privileges in the guest domain to execute arbitrary commands in do | Sep 27, 2007 | 6.9 | 26 | NO | YES |
CVE-2008-1944HIGH Buffer overflow in the backend framebuffer of XenSource Xen Para-Virtualized Framebuffer (PVFB) Message 3.0 through 3.0.3 allows local users to cause a denial of service (SDL crash | May 14, 2008 | 7.2 | 18 | NO | NO |
CVE-2010-2070MEDIUM arch/ia64/xen/faults.c in Xen 3.4 and 4.0 in Linux kernel 2.6.18, and possibly other kernel versions, when running on IA-64 architectures, allows local users to cause a denial of s | Jun 16, 2010 | 4.9 | 17 | NO | NO |
CVE-2007-3919MEDIUM (1) xenbaked and (2) xenmon.py in Xen 3.1 and earlier allow local users to truncate arbitrary files via a symlink attack on /tmp/xenq-shm. | Oct 28, 2007 | 6.0 | 16 | NO | NO |
CVE-2008-1619MEDIUM The ssm_i emulation in Xen 5.1 on IA64 architectures allows attackers to cause a denial of service (dom0 panic) via certain traffic, as demonstrated using an FTP stress test tool. | Apr 2, 2008 | 4.3 | 14 | NO | NO |
CVE-2007-5906MEDIUM Xen 3.1.1 allows virtual guest system users to cause a denial of service (hypervisor crash) by using a debug register (DR7) to set certain breakpoints. | Nov 9, 2007 | 4.7 | 14 | NO | NO |
CVE-2007-5907MEDIUM Xen 3.1.1 does not prevent modification of the CR4 TSC from applications, which allows pv guests to cause a denial of service (crash). | Nov 9, 2007 | 4.7 | 14 | NO | NO |
The backend for XenSource Xen Para Virtualized Frame Buffer (PVFB) in Xen ioemu does not properly restrict the frame buffer size, which allows attackers to cause a denial of servic | Jun 23, 2008 | 2.1 | 11 | NO | NO |
Buffer overflow in the backend of XenSource Xen Para Virtualized Frame Buffer (PVFB) 3.0 through 3.1.2 allows local users to cause a denial of service (crash) and possibly execute | May 14, 2008 | 2.1 | 11 | NO | NO |
Xen 3.x, possibly before 3.1.2, when running on IA64 systems, does not check the RID value for mov_to_rr, which allows a VTi domain to read memory of other domains. | Dec 4, 2007 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xensource Inc.
Media articles that mention a CVE ID that affects a product developed by Xensource Inc — matched by CVE ID, not by vendor name.