|
208181
|
5.5 |
MEDIUM
Local
|
xen debian fedoraproject opensuse
|
xen debian_linux fedora leap
|
An issue was discovered in Xen through 4.14.x. There is a lack of preemption in evtchn_reset() / evtchn_destroy(). In particular, the FIFO event channel model allows guests to have a large number of …
|
NVD-CWE-noinfo
|
CVE-2020-25601
|
2024-11-21 14:18 |
2020-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208182
|
5.5 |
MEDIUM
Local
|
xen fedoraproject opensuse debian
|
xen fedora leap debian_linux
|
An issue was discovered in Xen through 4.14.x. Out of bounds event channels are available to 32-bit x86 domains. The so called 2-level event channel model imposes different limits on the number of us…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-25600
|
2024-11-21 14:18 |
2020-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208183
|
7.0 |
HIGH
Local
|
xen fedoraproject opensuse debian
|
xen fedora leap debian_linux
|
An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVTCHNOP_reset (potentially by a guest on itself) or XEN_DOMCTL_soft_reset (by itself covered by XSA-7…
|
CWE-119 CWE-362
Incorrect Access of Indexable Resource ('Range Error') Race Condition
|
CVE-2020-25599
|
2024-11-21 14:18 |
2020-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208184
|
5.5 |
MEDIUM
Local
|
xen fedoraproject opensuse
|
xen fedora leap
|
An issue was discovered in Xen 4.14.x. There is a missing unlock in the XENMEM_acquire_resource error path. The RCU (Read, Copy, Update) mechanism is a synchronisation primitive. A buggy error path i…
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2020-25598
|
2024-11-21 14:18 |
2020-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208185
|
6.5 |
MEDIUM
Local
|
xen fedoraproject
|
xen fedora
|
An issue was discovered in Xen through 4.14.x. There is mishandling of the constraint that once-valid event channels may not turn invalid. Logic in the handling of event channel operations in Xen ass…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-25597
|
2024-11-21 14:18 |
2020-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208186
|
5.5 |
MEDIUM
Local
|
xen fedoraproject debian opensuse
|
xen fedora debian_linux leap
|
An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The SYSENTER instruction leaves various state sanitization activities to software. O…
|
CWE-74
Injection
|
CVE-2020-25596
|
2024-11-21 14:18 |
2020-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208187
|
7.8 |
HIGH
Local
|
xen fedoraproject debian opensuse
|
xen fedora debian_linux leap
|
An issue was discovered in Xen through 4.14.x. The PCI passthrough code improperly uses register data. Code paths in Xen's MSI handling have been identified that act on unsanitized values read back f…
|
CWE-269
Improper Privilege Management
|
CVE-2020-25595
|
2024-11-21 14:18 |
2020-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208188
|
6.1 |
MEDIUM
Network
|
gon_project debian canonical
|
gon debian_linux ubuntu_linux
|
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in go…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25739
|
2024-11-21 14:18 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208189
|
7.8 |
HIGH
Local
|
pingidentity
|
pingid_integration_for_windows_login
|
PingID Integration for Windows Login before 2.4.2 allows local users to gain privileges by modifying CefSharp.BrowserSubprocess.exe.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-25826
|
2024-11-21 14:18 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208190
|
7.5 |
HIGH
Network
|
peg-markdown_project
|
peg-markdown
|
peg-markdown 0.4.14 has a NULL pointer dereference in process_raw_blocks in markdown_lib.c. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-25821
|
2024-11-21 14:18 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|