|
200601
|
6.5 |
MEDIUM
Local
|
xen debian
|
xen debian_linux
|
An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If the events are received faster than the thread is a…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-29568
|
2024-11-21 14:24 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200602
|
6.0 |
MEDIUM
Local
|
xen debian fedoraproject
|
xen debian_linux fedora
|
An issue was discovered in Xen through 4.14.x. A guest may access xenstore paths via absolute paths containing a full pathname, or via a relative path, which implicitly includes /local/domain/$DOMID …
|
CWE-426
Untrusted Search Path
|
CVE-2020-29482
|
2024-11-21 14:24 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200603
|
8.8 |
HIGH
Local
|
xen debian fedoraproject
|
xen debian_linux fedora
|
An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not removed when a domain is being destroyed. This mean…
|
CWE-269
Improper Privilege Management
|
CVE-2020-29481
|
2024-11-21 14:24 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200604
|
2.3 |
LOW
Local
|
xen debian fedoraproject
|
xen debian_linux fedora
|
An issue was discovered in Xen through 4.14.x. Neither xenstore implementation does any permission checks when reporting a xenstore watch event. A guest administrator can watch the root xenstored nod…
|
CWE-862
Missing Authorization
|
CVE-2020-29480
|
2024-11-21 14:24 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200605
|
8.8 |
HIGH
Local
|
xen debian fedoraproject
|
xen debian_linux fedora
|
An issue was discovered in Xen through 4.14.x. In the Ocaml xenstored implementation, the internal representation of the tree has special cases for the root node, because this node has no parent. Unf…
|
CWE-862
Missing Authorization
|
CVE-2020-29479
|
2024-11-21 14:24 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200606
|
6.2 |
MEDIUM
Local
|
xen debian fedoraproject
|
xen debian_linux fedora
|
An issue was discovered in Xen through 4.14.x. A bounds check common to most operation time functions specific to FIFO event channels depends on the CPU observing consistent state. While the producer…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-29571
|
2024-11-21 14:24 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200607
|
8.8 |
HIGH
Local
|
xen linux netapp debian
|
xen linux_kernel hci_compute_node_bios solidfire_\&_hci_management_node solidfire_\&_hci_storage_node debian_linux
|
An issue was discovered in the Linux kernel through 5.10.1, as used with Xen through 4.14.x. The Linux kernel PV block backend expects the kernel thread handler to reset ring->xenblkd to NULL when st…
|
CWE-416
Use After Free
|
CVE-2020-29569
|
2024-11-21 14:24 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200608
|
6.2 |
MEDIUM
Local
|
xen fedoraproject
|
xen fedora
|
An issue was discovered in Xen 4.14.x. When moving IRQs between CPUs to distribute the load of IRQ handling, IRQ vectors are dynamically allocated and de-allocated on the relevant CPUs. De-allocation…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-29567
|
2024-11-21 14:24 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200609
|
5.5 |
MEDIUM
Local
|
xen debian fedoraproject
|
xen debian_linux fedora
|
An issue was discovered in Xen through 4.14.x. When they require assistance from the device model, x86 HVM guests must be temporarily de-scheduled. The device model will signal Xen when it has comple…
|
CWE-674
Uncontrolled Recursion
|
CVE-2020-29566
|
2024-11-21 14:24 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200610
|
5.6 |
MEDIUM
Network
|
golang netapp
|
go trident
|
The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that be…
|
NVD-CWE-Other
|
CVE-2020-29511
|
2024-11-21 14:24 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|