← back
CVE-2008-4405

CVE-2008-4405

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 1.0%
from disclosure to weapon0 days
Published on NVDOct 3
1st PoCSep 30
exploitation probability
1.0%top 39% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM's write access within this tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue was originally reported as an issue in libvirt 0.3.3 and xenstore, but CVE is considering the core issue to be related to Xen.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.