XSA Classified by Consequences
View more
XSA Classified by Target
View more
XSA Classified by Attack Path
View more
XSA Classified by Consequences
View more
XSA (Not)Exploiting Hypervisor
View more
XSA Classified by Attack Path
View more
To understand the security threat to the Xen hypervisor, we systematically studied all 175 security vulnerabilities published on Xen Security Advisories (XSA), of which 131 (74.86%) are directly related to the core hypervisor. (See 'XSAs Classified by Exploiting Hypervisor or Not' to learn about those not directly attacking hypervisor)
The analysed data includes all XSAs before XSA-185. (XSA-185 is released on 2016-09-08, which is not avaliable at that time)
XSA-79, XSA-81, XSA-115, XSA-143, XSA-144, XSA-177 are unused XSA numbers. (Those XSA numbers were at some point allocated by the Xen Project Security Team. But are proved that the issue does not require advisories, and reserved to avoid confusion)
XSA-166 is too vague to be counted in our study
XSA-161 is withdrawn
XSA-99 is about test/example program and irrelevant to hypervisor