Xen是英国剑桥大学开发的一款开源的虚拟机监视器产品。该产品能够使不同和不兼容的操作系统运行在同一台计算机上,并支持在运行时进行迁移,保证正常运行并且避免宕机。 Xen 4.2和较早版本中的PV domain builder中存在漏洞,该漏洞源于程序没有验证解压缩之前或之后的内核或内存虚拟磁盘的大小。本地(具备Guest管理员权限的)攻击者利用该漏洞通过特制的内核或内存虚拟磁盘导致拒绝服务(domain 0内存消耗)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2012-4491 | Drupal Monthly Archive by Node Type模块安全漏洞 | |
| CVE-2012-4940 | Axigen Free Mail Server ‘View Log Files’组件多个目录遍历漏洞 | |
| CVE-2012-4939 | SolarWinds Orion Network Performance Monitor IPAM网络接口跨站脚本漏洞 | |
| CVE-2012-5671 | Exim DKIM DNS解码拒绝服务漏洞 | |
| CVE-2012-4532 | Joomla! Language Switcher模块跨站脚本漏洞 | |
| CVE-2012-4531 | Joomla! 跨站脚本漏洞 | |
| CVE-2012-4500 | Drupal Announcements模块安全漏洞 | |
| CVE-2012-4499 | Drupal Email Field模块联系格式化页面安全漏洞 | |
| CVE-2012-4496 | Drupal Custom Publishing Options模块跨站脚本漏洞 | |
| CVE-2012-4495 | Drupal Mime Mail模块安全漏洞 | |
| CVE-2012-4494 | Drupal Shibboleth认证模块安全漏洞 | |
| CVE-2012-4492 | Drupal Shorten URLs模块多个跨站脚本漏洞 | |
| CVE-2012-4547 | AWStats ‘awredir.pl’未明安全漏洞 | |
| CVE-2012-4490 | Drupal Excluded Users模块多个跨站脚本漏洞 | |
| CVE-2012-4489 | Drupal Secure Login模块‘securelogin_secure_redirect’函数开放重定向漏洞 | |
| CVE-2012-4488 | Drupal Location模块安全漏洞 | |
| CVE-2012-4485 | Drupal Gallery格式化模块‘galleryformatter_field_formatter_view’函数多个跨站脚本漏洞 | |
| CVE-2012-4484 | Drupal Campaign Monitor模块跨站脚本漏洞 | |
| CVE-2012-4483 | Drupal Commons模块‘commons_discussion_views_default_views’函数安全漏洞 | |
| CVE-2012-4482 | Drupal Ubercart SecureTrading Payment Method模块安全漏洞 |
Showing top 20 of 25 CVEs. View all on vendor page → →
No comments yet