Known vulnerabilities in xen-tools

Vendor: SUSE
Software: xen-tools
Software CPE: cpe:2.3:o:suse:xen-tools:*:*:*:*:*:suse_linux:*:*
Total vulnerabilities: 126
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting xen-tools xen-tools is affected by 126 known vulnerabilities: 5 high, 58 medium, 63 low Critical High Medium Low

Vulnerabilities (126)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU147399 - Missing release of memory after effective lifetime
CVE-2026-62437
CWE-401 Low
No
No
4.12.4_74-3.151.1, 4.16.7_14-150400.4.92.1, 4.17.6_16-150500.3.79.1, 4.20.4_04-150700.3.46.1 08.09.2026 SB2026090845
SB2026090870
SB2026090871
and 3 more
#VU147398 - Improper Check for Unusual or Exceptional Conditions
CVE-2026-79602
CWE-754 Low
No
No
4.12.4_74-3.151.1, 4.16.7_14-150400.4.92.1, 4.17.6_16-150500.3.79.1, 4.20.4_04-150700.3.46.1 08.09.2026 SB2026090845
SB2026090870
SB2026090871
and 3 more
#VU147397 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-79603
CWE-362 Low
No
No
4.16.7_14-150400.4.92.1, 4.17.6_16-150500.3.79.1, 4.20.4_04-150700.3.46.1 08.09.2026 SB2026090845
SB2026090870
SB2026090871
and 2 more
#VU140027 - Improper input validation
CVE-2026-42494
CWE-20 Medium
No
No
4.12.4_72-3.148.4, 4.16.7_12-150400.4.89.3, 4.17.6_14-150500.3.76.3, 4.18.5_20-150600.3.53.3, 4.20.4_04-150700.3.46.1 29.07.2026 SB2026072966
SB2026073008
SB2026073052
and 7 more
#VU140028 - Integer underflow
CVE-2026-42495
CWE-191 Medium
No
No
4.12.4_72-3.148.4, 4.16.7_12-150400.4.89.3, 4.17.6_14-150500.3.76.3, 4.18.5_20-150600.3.53.3, 4.20.4_04-150700.3.46.1 29.07.2026 SB2026072966
SB2026073008
SB2026073052
and 7 more
#VU140029 - Improper input validation
CVE-2026-62423
CWE-20 Medium
No
No
4.12.4_72-3.148.4, 4.16.7_12-150400.4.89.3, 4.17.6_14-150500.3.76.3, 4.18.5_20-150600.3.53.3, 4.20.4_04-150700.3.46.1 29.07.2026 SB2026072966
SB2026073008
SB2026073052
and 7 more
#VU140030 - Improper input validation
CVE-2026-62424
CWE-20 Medium
No
No
4.12.4_72-3.148.4, 4.16.7_12-150400.4.89.3, 4.17.6_14-150500.3.76.3, 4.18.5_20-150600.3.53.3, 4.20.4_04-150700.3.46.1 29.07.2026 SB2026072966
SB2026073008
SB2026073052
and 7 more
#VU140031 - Improper input validation
CVE-2026-62425
CWE-20 Medium
No
No
4.12.4_72-3.148.4, 4.16.7_12-150400.4.89.3, 4.17.6_14-150500.3.76.3, 4.18.5_20-150600.3.53.3, 4.20.4_04-150700.3.46.1 29.07.2026 SB2026072966
SB2026073008
SB2026073052
and 7 more
#VU140025 - Improper Locking
CVE-2026-62426
CWE-667 Low
No
No
4.12.4_72-3.148.4, 4.16.7_12-150400.4.89.3, 4.17.6_14-150500.3.76.3, 4.18.5_20-150600.3.53.3, 4.20.4_04-150700.3.46.1 29.07.2026 SB2026072966
SB2026073008
SB2026073052
and 7 more
#VU140026 - Improper Locking
CVE-2026-62427
CWE-667 Low
No
No
4.12.4_72-3.148.4, 4.16.7_12-150400.4.89.3, 4.17.6_14-150500.3.76.3, 4.18.5_20-150600.3.53.3, 4.20.4_04-150700.3.46.1 29.07.2026 SB2026072966
SB2026073008
SB2026073052
and 7 more
#VU140022 - Out-of-bounds read
CVE-2026-62430
CWE-125 Low
No
No
4.12.4_72-3.148.4, 4.16.7_12-150400.4.89.3, 4.17.6_14-150500.3.76.3, 4.18.5_20-150600.3.53.3, 4.20.4_04-150700.3.46.1 29.07.2026 SB2026072966
SB2026073008
SB2026073052
and 7 more
#VU140021 - Improper input validation
CVE-2026-62433
CWE-20 Low
No
No
4.12.4_72-3.148.4, 4.16.7_12-150400.4.89.3, 4.17.6_14-150500.3.76.3, 4.18.5_20-150600.3.53.3, 4.20.4_04-150700.3.46.1 29.07.2026 SB2026072966
SB2026073008
SB2026073052
and 7 more
#VU140020 - Resource exhaustion
CVE-2026-42493
CWE-400 Low
No
No
4.12.4_72-3.148.4, 4.16.7_12-150400.4.89.3, 4.17.6_14-150500.3.76.3, 4.18.5_20-150600.3.53.3, 4.20.4_04-150700.3.46.1 29.07.2026 SB2026072966
SB2026073008
SB2026073052
and 7 more
#VU140018 - Type confusion
CVE-2026-62428
CWE-843 Low
No
No
4.12.4_72-3.148.4, 4.16.7_12-150400.4.89.3, 4.17.6_14-150500.3.76.3, 4.18.5_20-150600.3.53.3, 4.20.4_04-150700.3.46.1 29.07.2026 SB2026072966
SB2026073008
SB2026073052
and 8 more
#VU140017 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-62429
CWE-362 Low
No
No
4.12.4_72-3.148.4, 4.16.7_12-150400.4.89.3, 4.17.6_14-150500.3.76.3, 4.18.5_20-150600.3.53.3, 4.20.4_04-150700.3.46.1 29.07.2026 SB2026072966
SB2026073008
SB2026073052
and 7 more
#VU140016 - Divide By Zero
CVE-2026-62431
CWE-369 Low
No
No
4.16.7_12-150400.4.89.3, 4.17.6_14-150500.3.76.3, 4.18.5_20-150600.3.53.3, 4.20.4_04-150700.3.46.1 29.07.2026 SB2026072966
SB2026073008
SB2026073052
and 7 more
#VU140015 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-62432
CWE-362 Low
No
No
4.12.4_72-3.148.4, 4.16.7_12-150400.4.89.3, 4.17.6_14-150500.3.76.3, 4.18.5_20-150600.3.53.3, 4.20.4_04-150700.3.46.1 29.07.2026 SB2026072966
SB2026073008
SB2026073052
and 8 more
#VU140014 - Out-of-bounds write
CVE-2026-62434
CWE-787 Low
No
No
4.12.4_72-3.148.4, 4.16.7_12-150400.4.89.3, 4.17.6_14-150500.3.76.3, 4.18.5_20-150600.3.53.3, 4.20.4_04-150700.3.46.1 29.07.2026 SB2026072966
SB2026073008
SB2026073052
and 8 more
#VU134010 - Improper control of a resource through its lifetime
CVE-2026-42488
CWE-664 Low
No
No
4.12.4_70-3.145.1, 4.16.7_10-150400.4.86.2, 4.17.6_12-150500.3.73.1, 4.18.5_18-150600.3.50.1, 4.20.3_06-150700.3.41.1 09.06.2026 SB2026060946
SB20260610106
SB20260610107
and 6 more
#VU134006 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-42487
CWE-362 Low
No
No
4.12.4_70-3.145.1, 4.16.7_10-150400.4.86.2, 4.17.6_12-150500.3.73.1, 4.18.5_18-150600.3.50.1, 4.20.3_06-150700.3.41.1 09.06.2026 SB2026060946
SB20260610106
SB20260610107
and 6 more


Showing elements 1 - 20 out of 126