Known vulnerabilities in xen-tools - page 2

Vendor: SUSE
Software: xen-tools
Software CPE: cpe:2.3:o:suse:xen-tools:*:*:*:*:*:suse_linux:*:*
Total vulnerabilities: 123
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting xen-tools xen-tools is affected by 123 known vulnerabilities: 5 high, 58 medium, 60 low Critical High Medium Low

Vulnerabilities (123)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU128378 - Reachable Assertion
CVE-2026-23557
CWE-617 Medium
No
No
4.12.4_68-3.142.1, 4.14.6_30-150300.3.97.1, 4.16.7_08-150400.4.81.2, 4.17.6_08-150500.3.65.1, 4.18.5_16-150600.3.45.1, 4.20.3_02-150700.3.33.1, 4.20.3_04-150700.3.36.1 28.04.2026 SB20260428207
SB20260428235
SB2026042901
and 8 more
#VU128376 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-23558
CWE-362 Medium
No
No
4.12.4_68-3.142.1, 4.14.6_30-150300.3.97.1, 4.16.7_08-150400.4.81.2, 4.17.6_08-150500.3.65.1, 4.18.5_16-150600.3.45.1, 4.20.3_02-150700.3.33.1, 4.20.3_04-150700.3.36.1 28.04.2026 SB20260428207
SB20260428235
SB2026042901
and 9 more
#VU126567 - Observable discrepancy
CVE-2025-54505
CWE-203 Low
No
No
4.12.4_68-3.142.1, 4.14.6_30-150300.3.97.1, 4.16.7_08-150400.4.81.2, 4.17.6_08-150500.3.65.1, 4.18.5_16-150600.3.45.1, 4.20.3_02-150700.3.33.1 20.04.2026 SB2026042081
SB20260428235
SB2026042901
and 36 more
#VU124114 - Reachable Assertion
CVE-2026-23555
CWE-617 Low
No
No
4.18.5_12-150600.3.40.1, 4.20.2_08-150700.3.28.1 18.03.2026 SB2026031846
SB2026031847
SB2026031848
and 4 more
#VU124113 - Use After Free
CVE-2026-23554
CWE-416 Medium
No
No
4.17.6_06-150500.3.62.2, 4.18.5_12-150600.3.40.1, 4.20.2_08-150700.3.28.1 18.03.2026 SB2026031846
SB2026031847
SB2026031848
and 6 more
#VU122072 - Permissions, Privileges, and Access Controls
CVE-2026-23553
CWE-264 Low
No
No
4.12.4_64-3.137.1, 4.14.6_28-150300.3.94.1, 4.16.7_06-150400.4.78.1, 4.17.6_04-150500.3.59.1, 4.18.5_10-150600.3.37.1, 4.20.2_04-150700.3.22.1, 4.20.2_06-150700.3.25.1 27.01.2026 SB2026012780
SB2026012786
SB2026012838
and 8 more
#VU122070 - Out-of-bounds read
CVE-2025-58150
CWE-125 Low
No
No
4.12.4_64-3.137.1, 4.14.6_28-150300.3.94.1, 4.16.7_06-150400.4.78.1, 4.17.6_04-150500.3.59.1, 4.18.5_10-150600.3.37.1, 4.20.2_04-150700.3.22.1, 4.20.2_06-150700.3.25.1 27.01.2026 SB2026012780
SB2026012838
SB2026012839
and 7 more
#VU117653 - Permissions, Privileges, and Access Controls
CVE-2025-58149
CWE-264 Low
No
No
4.12.4_64-3.137.1, 4.14.6_28-150300.3.94.1, 4.16.7_06-150400.4.78.1, 4.17.6_02-150500.3.56.1, 4.18.5_08-150600.3.34.2, 4.20.2_02-150700.3.19.1 24.10.2025 SB2025102474
SB20251024128
SB2025102501
and 8 more
#VU117433 - Out-of-bounds read
CVE-2025-58148
CWE-125 Medium
No
No
4.16.7_04-150400.4.75.1, 4.17.5_12-150500.3.53.1, 4.18.5_06-150600.3.31.2, 4.18.5_08-150600.3.34.2, 4.20.1_06-150700.3.14.1 21.10.2025 SB2025102166
SB2025102167
SB2025102242
and 11 more
#VU117432 - Out-of-bounds write
CVE-2025-58147
CWE-787 Medium
No
No
4.16.7_04-150400.4.75.1, 4.17.5_12-150500.3.53.1, 4.18.5_06-150600.3.31.2, 4.18.5_08-150600.3.34.2, 4.20.1_06-150700.3.14.1 21.10.2025 SB2025102166
SB2025102167
SB2025102242
and 11 more
#VU115006 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-58143
CWE-362 Medium
No
No
4.14.6_28-150300.3.94.1, 4.16.7_04-150400.4.75.1, 4.17.5_12-150500.3.53.1, 4.18.5_06-150600.3.31.2, 4.18.5_08-150600.3.34.2, 4.20.1_04-150700.3.11.1 09.09.2025 SB2025090952
SB2025090955
SB2025091143
and 10 more
#VU115005 - NULL Pointer Dereference
CVE-2025-58142
CWE-476 Medium
No
No
4.14.6_28-150300.3.94.1, 4.16.7_04-150400.4.75.1, 4.17.5_12-150500.3.53.1, 4.18.5_06-150600.3.31.2, 4.18.5_08-150600.3.34.2, 4.20.1_04-150700.3.11.1 09.09.2025 SB2025090952
SB2025090955
SB2025091143
and 10 more
#VU115004 - NULL Pointer Dereference
CVE-2025-27466
CWE-476 Medium
No
No
4.14.6_28-150300.3.94.1, 4.16.7_04-150400.4.75.1, 4.17.5_12-150500.3.53.1, 4.18.5_06-150600.3.31.2, 4.18.5_08-150600.3.34.2, 4.20.1_04-150700.3.11.1 09.09.2025 SB2025090952
SB2025090955
SB2025091143
and 10 more
#VU109000 - Resource Management Errors
CVE-2024-28956
CWE-399 High
No
No
4.14.6_24-150300.3.87.1, 4.17.5_08-150500.3.45.1, 4.18.5_02-150600.3.23.1, 4.20.0_12-150700.3.3.1 13.05.2025 SB2025051308
SB2025051309
SB2025051320
and 46 more
#VU105104 - Deadlock
CVE-2025-1713
CWE-833 Medium
No
No
4.14.6_24-150300.3.87.1, 4.17.5_08-150500.3.45.1, 4.18.4_06-150600.3.20.1 27.02.2025 SB20250227233
SB2025022801
SB2025022802
and 7 more
#VU101817 - Processor optimization removal or modification of security-critical code
CVE-2024-53241
CWE-1037 Low
No
No
4.14.6_24-150300.3.87.1, 4.17.5_08-150500.3.45.1, 4.18.4_02-150600.3.15.2 18.12.2024 SB2024121807
SB20250115100
SB2025011663
and 23 more
#VU100327 - Missing release of memory after effective lifetime
CVE-2024-45819
CWE-401 Medium
No
No
4.12.4_58-3.124.1, 4.13.5_16-150200.3.99.1, 4.14.6_22-150300.3.84.1, 4.16.6_06-150400.4.65.1, 4.17.5_06-150500.3.42.1, 4.18.3_06-150600.3.12.1 12.11.2024 SB20241112120
SB20241112131
SB2024111303
and 11 more
#VU100325 - Improper Locking
CVE-2024-45818
CWE-667 Medium
No
No
4.12.4_58-3.124.1, 4.13.5_16-150200.3.99.1, 4.14.6_22-150300.3.84.1, 4.16.6_06-150400.4.65.1, 4.17.5_06-150500.3.42.1, 4.18.3_06-150600.3.12.1 12.11.2024 SB20241112118
SB20241112131
SB2024111303
and 12 more
#VU97680 - Deadlock
CVE-2024-45817
CWE-833 Low
No
No
4.12.4_54-3.118.1, 4.12.4_56-3.121.1, 4.13.5_16-150200.3.99.1, 4.14.6_20-150300.3.81.1, 4.16.6_04-150400.4.62.1, 4.17.5_04-150500.3.39.1, 4.17.5_06-150500.3.42.1, 4.18.3_04-150600.3.9.1, 4.18.3_06-150600.3.12.1 24.09.2024 SB2024092463
SB2024092464
SB2024092466
and 16 more
#VU96006 - Error Handling
CVE-2024-31145
CWE-388 Medium
No
No
4.12.4_52-3.115.1, 4.12.4_56-3.121.1, 4.13.5_14-150200.3.96.1, 4.14.6_18-150300.3.78.1, 4.16.6_04-150400.4.62.1, 4.17.5_02-150500.3.36.1, 4.18.3_02-150600.3.6.1 14.08.2024 SB2024081461
SB2024081602
SB2024081603
and 11 more


Showing elements 21 - 40 out of 123