Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-7228

Опубликовано: 04 апр. 2017
Источник: nvd
CVSS3: 8.2
CVSS2: 7.2
EPSS Низкий

Описание

An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The earlier XSA-29 fix introduced an insufficient check on XENMEM_exchange input, allowing the caller to drive hypervisor memory accesses outside of the guest provided input/output arrays.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:xen:xen:-:*:*:*:*:*:*:*

EPSS

Процентиль: 81%
0.01535
Низкий

8.2 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-129

Связанные уязвимости

CVSS3: 8.2
ubuntu
почти 9 лет назад

An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The earlier XSA-29 fix introduced an insufficient check on XENMEM_exchange input, allowing the caller to drive hypervisor memory accesses outside of the guest provided input/output arrays.

CVSS3: 8
redhat
почти 9 лет назад

An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The earlier XSA-29 fix introduced an insufficient check on XENMEM_exchange input, allowing the caller to drive hypervisor memory accesses outside of the guest provided input/output arrays.

CVSS3: 8.2
debian
почти 9 лет назад

An issue (known as XSA-212) was discovered in Xen, with fixes availabl ...

CVSS3: 8.2
github
больше 3 лет назад

An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The earlier XSA-29 fix introduced an insufficient check on XENMEM_exchange input, allowing the caller to drive hypervisor memory accesses outside of the guest provided input/output arrays.

fstec
почти 9 лет назад

Уязвимость гипервизора Xen, позволяющая нарушителю получить доступ к памяти гипервизора

EPSS

Процентиль: 81%
0.01535
Низкий

8.2 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-129