CVE-2016-4962

MEDIUM

Oracle VM Server - Access Control

Title source: rule

Description

The libxl device-handling in Xen 4.6.x and earlier allows local OS guest administrators to cause a denial of service (resource consumption or management facility confusion) or gain host OS privileges by manipulating information in guest controlled areas of xenstore.

Scores

CVSS v3 6.7
EPSS 0.0009
EPSS Percentile 25.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-264
Status draft

Affected Products (19)

oracle/vm_server
oracle/vm_server
xen/xen
xen/xen
xen/xen
xen/xen
xen/xen
xen/xen
xen/xen
xen/xen
xen/xen
xen/xen
xen/xen
xen/xen
xen/xen
... and 4 more

Timeline

Published Jun 07, 2016
Tracked Since Feb 18, 2026