VDB
DEBIAN-CVE-2018-10472
DEBIAN-CVE-2018-10472
PUBLISHED
CVSS 5.599999904632568 MEDIUM
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.
Risk Scores
CVSS v3.0
5.599999904632568
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:14 | xen | 0, 0, 0 |
| Debian:12 | xen | 0, 0, 0 |
| Debian:11 | xen | 0, 0, 0 |
| Debian:13 | xen | 0, 0, 0 |
Timeline
- Apr 27, 2018 CVE Published
- Apr 28, 2026 CVE Updated