Known vulnerabilities in xen (Debian package)
Vendor:
Debian
Software:
xen (Debian package)
Software CPE:
cpe:2.3:o:debian:xen_debian_package:*:*:*:*:*:debian_linux:*:*
Website:
https://www.debian.org/
Total vulnerabilities:
125
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.4
Breakdown by Severity Chart
4.20.2+7-g1badcf5035-0+deb13u1
4.17.5+72-g01140da4e8-1
4.17.5+23-ga4e5191dc0-1
4.14.5+94-ge49571868d-1
4.14.5+86-g1c354767d5-1
4.14.4+74-gd7b22226b5-1
4.14.3-1~deb11u1
4.11.4+107-gef32c7afa2-1
4.11.4+99-g8bce4698f6-1
4.14.5+24-g87d90d511c-1
4.14.3+32-g9de3671772-1~deb11u1
4.11.4+57-g41a822c392-2
4.14.0+88-g1d1d1f5391
4.14.0+88-g1d1d1f5391-2
4.14.0+88-g1d1d1f5391-1
4.11.4-1
4.11.4+57-g41a822c392
4.11.4+57-g41a822c392-1
4.14.0+80-gd101b417b7-1
4.14.0+80-gd101b417b7
4.14.0+80-gd101b417b7-1~exp2
4.11.4+37-g3263f257ca
4.11.4+37-g3263f257ca-1
4.14.0
4.14.0-1~exp1
4.11.4+24-gddaaccbbab
4.11.4+24-gddaaccbbab-1~deb10u1
4.11.4+24-gddaaccbbab-1
4.11.3+24-g14b62ab3e5
4.8.5.final+shim4.10.4
4.4.1
4.8.5.final+shim4.10.4-1+deb9u12
4.11.3+24-g14b62ab3e5-1~deb10u1
4.11.3+24-g14b62ab3e5-1
4.4.4lts5-0+deb8u1
4.11.1+92-g6c33308a8d-2
4.11.1+92-g6c33308a8d-1
4.11.1+26-g87f51bf366-3
4.11.1+26-g87f51bf366-2
4.8.5+shim4.10.2+xsa282-1+deb9u11
4.11.1-1
4.4.4lts4-0+deb8u1
4.0.1-4
4.0.1-5
4.0.1-5.1
4.0.1-5.2
4.0.1-5.3
4.0.1-5.4
4.0.1-5.5
4.0.1-5.6
4.0.1-5.7
4.0.1-5.8
4.0.1-5.9
4.0.1-5.10
4.0.1-5.11
4.1.4-3+deb7u7
4.1.6.1-1+deb7u1
4.1.6.lts1-1
4.1.6.lts1-2
4.1.6.lts1-3
4.1.6.lts1-4
4.1.6.lts1-5
4.1.6.lts1-6
4.1.6.lts1-7
4.1.6.lts1-8
4.1.6.lts1-9
4.1.6.lts1-10
4.1.6.lts1-11
4.1.6.lts1-12
4.1.6.lts1-13
4.1.6.lts1-14
4.4.4lts1-0+deb8u1
4.4.4lts2-0+deb8u1
4.4.4lts3-0+deb8u1
4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6
4.8.3+xsa262+shim4.10.0+comet3-1+deb9u7
4.8.3+xsa267+shim4.10.1+xsa267-1+deb9u8
4.8.3+xsa267+shim4.10.1+xsa267-1+deb9u9
4.8.4+xsa273+shim4.10.1+xsa273-1+deb9u10
4.11.1~pre.20180911.5acdd26fdc+dfsg-2
4.11.1~pre.20180911.5acdd26fdc+dfsg-3
4.11.1~pre.20180911.5acdd26fdc+dfsg-4
4.11.1~pre.20180911.5acdd26fdc+dfsg-5
4.11.1~pre.20180911.5acdd26fdc+dfsg-1~exp1
4.11.1~pre+1.733450b39b-1~exp1
4.8.3+comet2+shim4.10.0+comet3-1+deb9u5
4.8.3+comet2+shim4.10.0+comet3-1+deb9u4.1
4.8.3+comet2+shim4.10.0+comet3-1+deb9u4
4.8.2+xsa245-0+deb9u1
4.8.1-1+deb9u3
4.8.1-1+deb9u2
4.4.1-9+deb8u10
4.8.0~rc3-1
4.8.0~rc5-1
4.8.0-1
4.8.1~pre.2017.01.23-1
4.8.1-1
4.8.1-1+deb9u1
4.4.1-9+deb8u1
4.4.1-9+deb8u2
4.4.1-9+deb8u3
4.4.1-9+deb8u4
4.4.1-9+deb8u5
4.4.1-9+deb8u6
4.4.1-9+deb8u7
4.4.1-9+deb8u8
4.4.1-9+deb8u9
4.4.1-7
4.4.1-8
4.4.1-9
4.1.4-3+deb7u1
4.1.4-3+deb7u2
4.1.4-3+deb7u3
4.1.4-3+deb7u4
4.1.4-3+deb7u5
4.1.4-3+deb7u6
4.1.4-3+deb7u8
4.1.4-3+deb7u9
1.2-1
1.2-2
1.2-3
1.2-4
1.2-4.1
2.0.3-0
2.0.3-0.1
2.0.4-1
2.0.4-2
2.0.4-3
2.0.4-4
2.0.5-1
2.0.5-2
2.0.5-3
2.0.6-1
4.0.0-1~experimental.1
4.0.0-1~experimental.2
4.0.0-1
4.0.0-2
4.0.1~rc3-1
4.0.1~rc5-1
4.0.1~rc6-1
4.0.1-1
4.0.1-2
4.1.0~rc6-1
4.1.0-1
4.1.0-2
4.1.0-3
4.1.1-1
4.1.1-2
4.1.1-3
4.1.2-1
4.1.2-2
4.1.2-3
4.1.2-4
4.1.2-5
4.1.2-6
4.1.2-7
4.1.3~rc1+hg-20120614.a9c0a89c08f2-1
4.1.3~rc1+hg-20120614.a9c0a89c08f2-2
4.1.3~rc1+hg-20120614.a9c0a89c08f2-3
4.1.3~rc1+hg-20120614.a9c0a89c08f2-4
4.1.3~rc1+hg-20120614.a9c0a89c08f2-5
4.1.3-1
4.1.3-2
4.1.3-3
4.1.3-4
4.1.3-5
4.1.3-6
4.1.3-7
4.1.3-8
4.1.4-1
4.1.4-2
4.1.4-3
4.1.4-4
4.2.0~rc2-1
4.2.0~rc3-1
4.2.0-1
4.2.0-2
4.2.1-1
4.2.1-2
4.2.2-1
4.3.0-1
4.3.0-2
4.3.0-3
4.4.0-1
4.4.0-2
4.4.0-3
4.4.0-4
4.4.0-5
4.4.1-1
4.4.1-2
4.4.1-3
4.4.1-4
4.4.1-5
4.4.1-6
4.5.0~rc3-1
4.5.0-1
4.5.1~rc1-1
4.6.0-1
4.6.0-1+nmu1
4.6.0-1+nmu2
4.8.0~rc3-0exp1
4.8.0~rc3-0exp2
Vulnerabilities (125)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU117653 - Permissions, Privileges, and Access Controls CVE-2025-58149 |
CWE-264 | Low | 4.17.5+72-g01140da4e8-1, 4.20.2+7-g1badcf5035-0+deb13u1 | 24.10.2025 |
SB2025102474 SB20251024128 SB2025102501 and 8 more |
||
| #VU117433 - Out-of-bounds read CVE-2025-58148 |
CWE-125 | Medium | 4.17.5+72-g01140da4e8-1, 4.20.2+7-g1badcf5035-0+deb13u1 | 21.10.2025 |
SB2025102166 SB2025102167 SB2025102242 and 11 more |
||
| #VU117432 - Out-of-bounds write CVE-2025-58147 |
CWE-787 | Medium | 4.17.5+72-g01140da4e8-1, 4.20.2+7-g1badcf5035-0+deb13u1 | 21.10.2025 |
SB2025102166 SB2025102167 SB2025102242 and 11 more |
||
| #VU115008 - Permissions, Privileges, and Access Controls CVE-2025-58145 |
CWE-264 | Medium | 4.17.5+72-g01140da4e8-1, 4.20.2+7-g1badcf5035-0+deb13u1 | 09.09.2025 |
SB2025090953 SB2025091618 SB2025091619 and 3 more |
||
| #VU115007 - NULL Pointer Dereference CVE-2025-58144 |
CWE-476 | Medium | 4.17.5+72-g01140da4e8-1, 4.20.2+7-g1badcf5035-0+deb13u1 | 09.09.2025 |
SB2025090953 SB2025091618 SB2025091619 and 3 more |
||
| #VU115006 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2025-58143 |
CWE-362 | Medium | 4.17.5+72-g01140da4e8-1, 4.20.2+7-g1badcf5035-0+deb13u1 | 09.09.2025 |
SB2025090952 SB2025090955 SB2025091143 and 10 more |
||
| #VU115005 - NULL Pointer Dereference CVE-2025-58142 |
CWE-476 | Medium | 4.17.5+72-g01140da4e8-1, 4.20.2+7-g1badcf5035-0+deb13u1 | 09.09.2025 |
SB2025090952 SB2025090955 SB2025091143 and 10 more |
||
| #VU115004 - NULL Pointer Dereference CVE-2025-27466 |
CWE-476 | Medium | 4.17.5+72-g01140da4e8-1, 4.20.2+7-g1badcf5035-0+deb13u1 | 09.09.2025 |
SB2025090952 SB2025090955 SB2025091143 and 10 more |
||
| #VU112552 - Information Exposure through Microarchitectural State after Transient Execution CVE-2024-36357 |
CWE-1342 | Low | 4.17.5+72-g01140da4e8-1, 4.20.2+7-g1badcf5035-0+deb13u1 | 08.07.2025 |
SB2025070882 SB2025070903 SB2025070904 and 43 more |
||
| #VU112549 - Information Exposure through Microarchitectural State after Transient Execution CVE-2024-36350 |
CWE-1342 | Low | 4.17.5+72-g01140da4e8-1, 4.20.2+7-g1badcf5035-0+deb13u1 | 08.07.2025 |
SB2025070882 SB2025070903 SB2025070904 and 40 more |
||
| #VU112090 - Error Handling CVE-2025-27465 |
CWE-388 | Medium | 4.17.5+72-g01140da4e8-1, 4.20.2+7-g1badcf5035-0+deb13u1 | 01.07.2025 |
SB2025070176 SB2025070285 SB2025080601 and 2 more |
||
| #VU109000 - Resource Management Errors CVE-2024-28956 |
CWE-399 | High | 4.17.5+72-g01140da4e8-1, 4.20.2+7-g1badcf5035-0+deb13u1 | 13.05.2025 |
SB2025051308 SB2025051309 SB2025051320 and 46 more |
||
| #VU105104 - Deadlock CVE-2025-1713 |
CWE-833 | Medium | 4.17.5+72-g01140da4e8-1, 4.20.2+7-g1badcf5035-0+deb13u1 | 27.02.2025 |
SB20250227233 SB2025022801 SB2025022802 and 7 more |
||
| #VU94499 - Improper Locking CVE-2024-31143 |
CWE-667 | Medium | 4.17.5+23-ga4e5191dc0-1 | 17.07.2024 |
SB20240717125 SB2024073049 SB2024080547 and 5 more |
||
| #VU88374 - Processor optimization removal or modification of security-critical code CVE-2024-2201 |
CWE-1037 | Medium | 4.17.5+23-ga4e5191dc0-1 | 10.04.2024 |
SB2024041029 SB2024041044 SB2024041045 and 67 more |
||
| #VU88372 - Type confusion CVE-2024-31142 |
CWE-843 | Low | 4.17.5+23-ga4e5191dc0-1 | 10.04.2024 |
SB2024041027 SB2024041044 SB2024041045 and 11 more |
||
| #VU88228 - Improper input validation CVE-2023-46842 |
CWE-20 | Medium | 4.17.5+23-ga4e5191dc0-1 | 09.04.2024 |
SB2024040941 SB2024041044 SB2024041045 and 13 more |
||
| #VU87457 - Exposure of sensitive information to an unauthorized actor CVE-2023-28746 |
CWE-200 | Low | 4.17.5+23-ga4e5191dc0-1 | 12.03.2024 |
SB20240312343 SB20240312345 SB20240312357 and 51 more |
||
| #VU87374 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2024-2193 |
CWE-362 | Low | 4.17.5+23-ga4e5191dc0-1 | 12.03.2024 |
SB20240312315 SB2024031401 SB2024031501 and 13 more |
||
| #VU86860 - Resource Management Errors CVE-2023-46841 |
CWE-399 | Medium | 4.17.5+23-ga4e5191dc0-1 | 27.02.2024 |
SB2024022774 SB2024022776 SB2024022801 and 4 more |
Showing elements 1 - 20 out of 125