Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-14319

Опубликовано: 12 сент. 2017
Источник: nvd
CVSS3: 8.8
CVSS2: 7.2
EPSS Низкий

Описание

A grant unmapping issue was discovered in Xen through 4.9.x. When removing or replacing a grant mapping, the x86 PV specific path needs to make sure page table entries remain in sync with other accounting done. Although the identity of the page frame was validated correctly, neither the presence of the mapping nor page writability were taken into account.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:*
Версия до 4.9.0 (включая)

EPSS

Процентиль: 22%
0.00072
Низкий

8.8 High

CVSS3

7.2 High

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 8 лет назад

A grant unmapping issue was discovered in Xen through 4.9.x. When removing or replacing a grant mapping, the x86 PV specific path needs to make sure page table entries remain in sync with other accounting done. Although the identity of the page frame was validated correctly, neither the presence of the mapping nor page writability were taken into account.

CVSS3: 8.8
redhat
больше 8 лет назад

A grant unmapping issue was discovered in Xen through 4.9.x. When removing or replacing a grant mapping, the x86 PV specific path needs to make sure page table entries remain in sync with other accounting done. Although the identity of the page frame was validated correctly, neither the presence of the mapping nor page writability were taken into account.

CVSS3: 8.8
debian
больше 8 лет назад

A grant unmapping issue was discovered in Xen through 4.9.x. When remo ...

CVSS3: 8.8
github
больше 3 лет назад

A grant unmapping issue was discovered in Xen through 4.9.x. When removing or replacing a grant mapping, the x86 PV specific path needs to make sure page table entries remain in sync with other accounting done. Although the identity of the page frame was validated correctly, neither the presence of the mapping nor page writability were taken into account.

CVSS3: 8.8
fstec
больше 8 лет назад

Уязвимость гипервизора Xen, связанная с ошибками сопоставления прав доступа, позволяющая нарушителю повысить свои привилегии или вызвать отказ в обслуживании

EPSS

Процентиль: 22%
0.00072
Низкий

8.8 High

CVSS3

7.2 High

CVSS2

Дефекты

NVD-CWE-noinfo