Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2011-1898

EPSS 0.62% · P70
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2011-1898

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Xen 4.1 before 4.1.1 and 4.0 before 4.0.2, when using PCI passthrough on Intel VT-d chipsets that do not have interrupt remapping, allows guest OS users to gain host OS privileges by "using DMA to generate MSI interrupts by writing to the interrupt injection registers."
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Citrix Xen权限许可和访问控制漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Xen是英国剑桥大学开发的一款开源的虚拟机监视器产品。该产品能够使不同和不兼容的操作系统运行在同一台计算机上,并支持在运行时进行迁移,保证正常运行并且避免宕机。 Xen 4.1.1之前的4.1版本和4.0.2之前的4.0版本在使用PCI转移到不能中断重映射的Intel VT-d芯片组时存在权限许可和访问控制漏洞。本地用户可通过“使用DMA写入中断注入寄存器来生成MSI中断”,获得主机操作系统权限。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2011-1898

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2011-1898

Please Login to view more intelligence information

Same Patch Batch · n/a · 2011-08-12 · 11 CVEs total

CVE-2011-1583Citrix Xen PV内核解压多个整数溢出漏洞
CVE-2011-2357Android浏览器沙箱安全绕过漏洞
CVE-2008-7299IBM Tivoli Federated Identity Manager输入验证漏洞
CVE-2009-5083IBM Tivoli Federated Identity Manager认证绕过漏洞
CVE-2009-5084IBM Tivoli Federated Identity Manager敏感信息泄露漏洞
CVE-2009-5085IBM Tivoli Federated Identity Manager信任限制绕过漏洞
CVE-2011-3135IBM Tivoli Federated Identity Manager和Tivoli Federated Identity Manager Business Gateway未明
CVE-2011-3136IBM Tivoli Federated Identity Manager和Tivoli Federated Identity Manager Business Gateway未明
CVE-2011-3137IBM Tivoli Federated Identity Manager和Tivoli Federated Identity Manager Business Gateway未明
CVE-2011-3138IBM Tivoli Federated Identity Manager和Tivoli Federated Identity Manager Business Gateway安全

IV. Related Vulnerabilities

V. Comments for CVE-2011-1898

No comments yet


Leave a comment