|
199301
|
6.2 |
MEDIUM
Local
|
xen debian fedoraproject
|
xen debian_linux fedora
|
An issue was discovered in Xen through 4.14.x. Recording of the per-vCPU control block mapping maintained by Xen and that of pointers into the control block is reversed. The consumer assumes, seeing …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-29570
|
2024-11-21 14:24 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199302
|
6.0 |
MEDIUM
Local
|
xen debian fedoraproject
|
xen debian_linux fedora
|
An issue was discovered in Xen through 4.14.x. Nodes in xenstore have an ownership. In oxenstored, a owner could give a node away. However, node ownership has quota implications. Any guest can run an…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-29486
|
2024-11-21 14:24 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199303
|
6.0 |
MEDIUM
Local
|
xen debian fedoraproject
|
xen debian_linux fedora
|
An issue was discovered in Xen through 4.14.x. When a Xenstore watch fires, the xenstore client that registered the watch will receive a Xenstore message containing the path of the modified Xenstore …
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-29484
|
2024-11-21 14:24 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199304
|
6.5 |
MEDIUM
Local
|
xen debian fedoraproject
|
xen debian_linux fedora
|
An issue was discovered in Xen through 4.14.x. Xenstored and guests communicate via a shared memory page using a specific protocol. When a guest violates this protocol, xenstored will drop the connec…
|
CWE-416
Use After Free
|
CVE-2020-29483
|
2024-11-21 14:24 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199305
|
6.5 |
MEDIUM
Local
|
xen debian
|
xen debian_linux
|
An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If the events are received faster than the thread is a…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-29568
|
2024-11-21 14:24 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199306
|
6.0 |
MEDIUM
Local
|
xen debian fedoraproject
|
xen debian_linux fedora
|
An issue was discovered in Xen through 4.14.x. A guest may access xenstore paths via absolute paths containing a full pathname, or via a relative path, which implicitly includes /local/domain/$DOMID …
|
CWE-426
Untrusted Search Path
|
CVE-2020-29482
|
2024-11-21 14:24 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199307
|
8.8 |
HIGH
Local
|
xen debian fedoraproject
|
xen debian_linux fedora
|
An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not removed when a domain is being destroyed. This mean…
|
CWE-269
Improper Privilege Management
|
CVE-2020-29481
|
2024-11-21 14:24 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199308
|
2.3 |
LOW
Local
|
xen debian fedoraproject
|
xen debian_linux fedora
|
An issue was discovered in Xen through 4.14.x. Neither xenstore implementation does any permission checks when reporting a xenstore watch event. A guest administrator can watch the root xenstored nod…
|
CWE-862
Missing Authorization
|
CVE-2020-29480
|
2024-11-21 14:24 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199309
|
8.8 |
HIGH
Local
|
xen debian fedoraproject
|
xen debian_linux fedora
|
An issue was discovered in Xen through 4.14.x. In the Ocaml xenstored implementation, the internal representation of the tree has special cases for the root node, because this node has no parent. Unf…
|
CWE-862
Missing Authorization
|
CVE-2020-29479
|
2024-11-21 14:24 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199310
|
6.2 |
MEDIUM
Local
|
xen debian fedoraproject
|
xen debian_linux fedora
|
An issue was discovered in Xen through 4.14.x. A bounds check common to most operation time functions specific to FIFO event channels depends on the CPU observing consistent state. While the producer…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-29571
|
2024-11-21 14:24 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|