CVE-2012-5510
Last modified
CVE-2012-5510 is a vulnerability of currently unknown severity. Xen 4.x, when downgrading the grant table version, does not properly remove the status page from the tracking list when freeing the page, which allows local guest OS administrators to cause a denial of service (hypervisor crash) via unspecified vectors.. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
Xen 4.x, when downgrading the grant table version, does not properly remove the status page from the tracking list when freeing the page, which allows local guest OS administrators to cause a denial of service (hypervisor crash) via unspecified vectors.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xen | Xen | 4.0.0 |
| Xen | Xen | 4.0.1 |
| Xen | Xen | 4.0.2 |
| Xen | Xen | 4.0.3 |
| Xen | Xen | 4.0.4 |
| Xen | Xen | 4.1.0 |
| Xen | Xen | 4.1.1 |
| Xen | Xen | 4.1.2 |
| Xen | Xen | 4.1.3 |
| Xen | Xen | 4.2.0 |
References
- http://secunia.com/advisories/51397Vendor Advisory
- http://secunia.com/advisories/51468Vendor Advisory
- http://secunia.com/advisories/51486Vendor Advisory
- http://secunia.com/advisories/51487Vendor Advisory
- http://secunia.com/advisories/51397Vendor Advisory
- http://secunia.com/advisories/51468Vendor Advisory
- http://secunia.com/advisories/51486Vendor Advisory
- http://secunia.com/advisories/51487Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-5510?
How severe is CVE-2012-5510?
How do I fix CVE-2012-5510?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-5504Cross-site scripting (XSS) vulnerability in widget_traversal…
- CVE-2012-5505atat.py in Plone before 4.2.3 and 4.3 before beta 1 allows r…
- CVE-2012-5506python_scripts.py in Plone before 4.2.3 and 4.3 before beta …
- CVE-2012-5507AccessControl/AuthEncoding.py in Zope before 2.13.19, as use…
- CVE-2012-5508The error pages in Plone before 4.2.3 and 4.3 before beta 1 …
- CVE-2012-5509aeolus-configserver-setup in the Aeolas Configuration Server…
- CVE-2012-5511Stack-based buffer overflow in the dirty video RAM tracking …
- CVE-2012-5512Array index error in the HVMOP_set_mem_access handler in Xen…
- CVE-2012-5513The XENMEM_exchange handler in Xen 4.2 and earlier does not …
- CVE-2012-5514The guest_physmap_mark_populate_on_demand function in Xen 4.…
- CVE-2012-5515The (1) XENMEM_decrease_reservation, (2) XENMEM_populate_phy…
- CVE-2012-5516Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.…
Are you affected by CVE-2012-5510?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
