<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1687073.xsl"?>
<?xml-stylesheet type="text/css" href="http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1686935.css"?>
<cvrf:cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
   <DocumentTitle xml:lang="en">Oracle VM Server for x86 Bulletin - October 2016 - Oracle CVRF</DocumentTitle>
   <DocumentType xml:lang="en">Oracle VM Server for x86 Bulletin Advisory</DocumentType>
   <DocumentPublisher Type="Vendor"/>
   <DocumentTracking>
      <Identification>
         <ID>OVMBulletinOct2016</ID>
      </Identification>
      <Status>Final</Status>
      <Version>3.0</Version>
      <RevisionHistory>
         <Revision>
            <Number>1.0</Number>
            <Date>2016-10-18T13:00:00-07:00</Date>
            <Description>Initial Distribution</Description>
         </Revision>
         <Revision>
            <Number>2.0</Number>
            <Date>2016-11-18T13:00:00-07:00</Date>
            <Description>New CVEs added.</Description>
         </Revision>
         <Revision>
            <Number>3.0</Number>
            <Date>2016-12-19T13:00:00-07:00</Date>
            <Description>New CVEs added.</Description>
         </Revision>
      </RevisionHistory>
   </DocumentTracking>
   <DocumentNotes>
      <Note Audience="All" Ordinal="1" Title="Summary" Type="Summary" xml:lang="en">This document contains descriptions of Oracle VM Server for x86 security vulnerabilities which have had fixes released for all supported versions and platforms.</Note>
   </DocumentNotes>
   <DocumentReferences>
      <Reference Type="External">
         <URL>http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html</URL>
         <Description>URL to html version of Advisory</Description>
      </Reference>
   </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
      <Branch Name="Oracle" Type="Vendor">
         <Branch Name="Oracle VM Server for x86" Type="Product Family">
            <Branch Name="Oracle VM Server for x86" Type="Product Name">
               <Branch Name="3.2" Type="Product Version">
                  <FullProductName ProductID="P-4455V-3.2">Oracle VM Server for x86 3.2</FullProductName>
               </Branch>
               <Branch Name="3.3" Type="Product Version">
                  <FullProductName ProductID="P-4455V-3.3">Oracle VM Server for x86 3.3</FullProductName>
               </Branch>
               <Branch Name="3.4" Type="Product Version">
                  <FullProductName ProductID="P-4455V-3.4">Oracle VM Server for x86 3.4</FullProductName>
               </Branch>
            </Branch>
         </Branch>
     </Branch>
  </ProductTree>
<Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9383</Title>
         <Notes>
               <Note Audience="All" Ordinal="1" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 7.5 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9383</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0164.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-5485</Title>
         <Notes>
               <Note Audience="All" Ordinal="2" Title="Details" Type="Details">This is a vulnerability in  ovm-consoled  in Oracle VM Server for x86. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 7.3 CVSS V2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-5485</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.3</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0151.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4997</Title>
         <Notes>
               <Note Audience="All" Ordinal="3" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockoptimplementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root access to provide a crafted offset value that triggers an unintended decrement. CVSS Base Score: 7.2 CVSS V2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4997</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.2</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0158.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4794</Title>
         <Notes>
               <Note Audience="All" Ordinal="4" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. Use-after-free vulnerability in mm/percpu.c in the Linux kernelthrough 4.6 allows local users to cause a denial of service (BUG) or possibly have unspecified other impact via crafted use of the mmap and bpf system calls. CVSS Base Score: 7.2 CVSS V2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4794</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.2</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0162.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4997</Title>
         <Notes>
               <Note Audience="All" Ordinal="5" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockoptimplementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root access to provide a crafted offset value that triggers an unintended decrement. CVSS Base Score: 7.2 CVSS V2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4997</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.2</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0133.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="6" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4997</Title>
         <Notes>
               <Note Audience="All" Ordinal="6" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockoptimplementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root access to provide a crafted offset value that triggers an unintended decrement. CVSS Base Score: 7.2 CVSS V2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4997</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.2</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0134.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="7" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-7039</Title>
         <Notes>
               <Note Audience="All" Ordinal="7" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 7.1 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-7039</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.1</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0140.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="8" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9555</Title>
         <Notes>
               <Note Audience="All" Ordinal="8" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linuxkernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows remote attackers to cause a denial of service (out-of-bounds slab access) or possibly have unspecified other impact via crafted SCTP data. CVSS Base Score: 7.1 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9555</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.1</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0174.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="9" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9555</Title>
         <Notes>
               <Note Audience="All" Ordinal="9" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linuxkernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows remote attackers to cause a denial of service (out-of-bounds slab access) or possibly have unspecified other impact via crafted SCTP data. CVSS Base Score: 7.1 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9555</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.1</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0175.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="10" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4470</Title>
         <Notes>
               <Note Audience="All" Ordinal="10" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The key_reject_and_link function in security/keys/key.c in the Linuxkernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command. CVSS Base Score: 6.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4470</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0158.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="11" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-5195</Title>
         <Notes>
               <Note Audience="All" Ordinal="11" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka Dirty CVSS Base Score: 6.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-5195</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0158.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="12" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-5829</Title>
         <Notes>
               <Note Audience="All" Ordinal="12" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. Multiple heap-based buffer overflows in the hiddev_ioctl_usagefunction in drivers/hid/usbhid/hiddev.c in the Linux kernel through 4.6.3 allow local users to cause a denial of service or possibly have unspecified other impact via a crafted (1) HIDIOCGUSAGES or (2) HIDIOCSUSAGES ioctl call. CVSS Base Score: 6.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-5829</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0158.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="13" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-5829</Title>
         <Notes>
               <Note Audience="All" Ordinal="13" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. Multiple heap-based buffer overflows in the hiddev_ioctl_usagefunction in drivers/hid/usbhid/hiddev.c in the Linux kernel through 4.6.3 allow local users to cause a denial of service or possibly have unspecified other impact via a crafted (1) HIDIOCGUSAGES or (2) HIDIOCSUSAGES ioctl call. CVSS Base Score: 6.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-5829</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0138.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="14" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-5829</Title>
         <Notes>
               <Note Audience="All" Ordinal="14" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. Multiple heap-based buffer overflows in the hiddev_ioctl_usagefunction in drivers/hid/usbhid/hiddev.c in the Linux kernel through 4.6.3 allow local users to cause a denial of service or possibly have unspecified other impact via a crafted (1) HIDIOCGUSAGES or (2) HIDIOCSUSAGES ioctl call. CVSS Base Score: 6.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-5829</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0139.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="15" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1583</Title>
         <Notes>
               <Note Audience="All" Ordinal="15" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in theLinux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted mmap calls for /proc pathnames, leading to recursive pagefault handling. CVSS Base Score: 6.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1583</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0154.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="16" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1583</Title>
         <Notes>
               <Note Audience="All" Ordinal="16" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in theLinux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted mmap calls for /proc pathnames, leading to recursive pagefault handling. CVSS Base Score: 6.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1583</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0155.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="17" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1583</Title>
         <Notes>
               <Note Audience="All" Ordinal="17" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in theLinux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted mmap calls for /proc pathnames, leading to recursive pagefault handling. CVSS Base Score: 6.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1583</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0162.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="18" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1583</Title>
         <Notes>
               <Note Audience="All" Ordinal="18" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in theLinux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted mmap calls for /proc pathnames, leading to recursive pagefault handling. CVSS Base Score: 6.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1583</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0167.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="19" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-5195</Title>
         <Notes>
               <Note Audience="All" Ordinal="19" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka Dirty CVSS Base Score: 6.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-5195</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0149.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="20" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-5195</Title>
         <Notes>
               <Note Audience="All" Ordinal="20" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka Dirty CVSS Base Score: 6.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-5195</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0150.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="21" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0718</Title>
         <Notes>
               <Note Audience="All" Ordinal="21" Title="Details" Type="Details">This is a vulnerability in  expat  in Oracle VM Server for x86. Expat allows context-dependent attackers to cause a denial of service(crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0718</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0168.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="22" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-7545</Title>
         <Notes>
               <Note Audience="All" Ordinal="22" Title="Details" Type="Details">This is a vulnerability in  policycoreutils  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-7545</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0157.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="23" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-7032</Title>
         <Notes>
               <Note Audience="All" Ordinal="23" Title="Details" Type="Details">This is a vulnerability in  sudo  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.6 CVSS V2 Vector: AV:L/AC:M/Au:S/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-7032</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.6</BaseScore>
               <Vector>AV:L/AC:M/Au:S/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0170.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="24" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-7076</Title>
         <Notes>
               <Note Audience="All" Ordinal="24" Title="Details" Type="Details">This is a vulnerability in  sudo  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.6 CVSS V2 Vector: AV:L/AC:M/Au:S/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-7076</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.6</BaseScore>
               <Vector>AV:L/AC:M/Au:S/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0170.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="25" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9637</Title>
         <Notes>
               <Note Audience="All" Ordinal="25" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.5 CVSS V2 Vector: AV:A/AC:H/Au:S/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9637</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>AV:A/AC:H/Au:S/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0171.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="26" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9637</Title>
         <Notes>
               <Note Audience="All" Ordinal="26" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.5 CVSS V2 Vector: AV:A/AC:H/Au:S/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9637</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>AV:A/AC:H/Au:S/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0172.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="27" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9637</Title>
         <Notes>
               <Note Audience="All" Ordinal="27" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.5 CVSS V2 Vector: AV:A/AC:H/Au:S/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9637</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>AV:A/AC:H/Au:S/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0173.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="28" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9385</Title>
         <Notes>
               <Note Audience="All" Ordinal="28" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.3 CVSS V2 Vector: AV:N/AC:M/Au:S/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9385</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.3</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0164.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="29" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9385</Title>
         <Notes>
               <Note Audience="All" Ordinal="29" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.3 CVSS V2 Vector: AV:N/AC:M/Au:S/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9385</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.3</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0165.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="30" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9385</Title>
         <Notes>
               <Note Audience="All" Ordinal="30" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.3 CVSS V2 Vector: AV:N/AC:M/Au:S/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9385</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.3</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0166.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="31" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3134</Title>
         <Notes>
               <Note Audience="All" Ordinal="31" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The netfilter subsystem in the Linux kernel through 4.5.2 does notvalidate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call. CVSS Base Score: 6.2 CVSS V2 Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3134</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.2</BaseScore>
               <Vector>AV:L/AC:H/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0158.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="32" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3134</Title>
         <Notes>
               <Note Audience="All" Ordinal="32" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The netfilter subsystem in the Linux kernel through 4.5.2 does notvalidate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call. CVSS Base Score: 6.2 CVSS V2 Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3134</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.2</BaseScore>
               <Vector>AV:L/AC:H/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0138.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="33" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3134</Title>
         <Notes>
               <Note Audience="All" Ordinal="33" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The netfilter subsystem in the Linux kernel through 4.5.2 does notvalidate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call. CVSS Base Score: 6.2 CVSS V2 Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3134</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.2</BaseScore>
               <Vector>AV:L/AC:H/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0139.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="34" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9381</Title>
         <Notes>
               <Note Audience="All" Ordinal="34" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9381</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0164.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="35" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9381</Title>
         <Notes>
               <Note Audience="All" Ordinal="35" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9381</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0165.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="36" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9381</Title>
         <Notes>
               <Note Audience="All" Ordinal="36" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9381</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0166.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="37" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9386</Title>
         <Notes>
               <Note Audience="All" Ordinal="37" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9386</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0164.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="38" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9386</Title>
         <Notes>
               <Note Audience="All" Ordinal="38" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9386</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0165.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="39" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9386</Title>
         <Notes>
               <Note Audience="All" Ordinal="39" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9386</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0166.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="40" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4998</Title>
         <Notes>
               <Note Audience="All" Ordinal="40" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The IPT_SO_SET_REPLACE setsockopt implementation in the netfiltersubsystem in the Linux kernel before 4.6 allows local users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from kernel heap memory by leveraging in-container root access to provide a crafted offset value that leads to crossing a ruleset blob boundary. CVSS Base Score: 5.6 CVSS V2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4998</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.6</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0158.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="41" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0723</Title>
         <Notes>
               <Note Audience="All" Ordinal="41" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. Race condition in the tty_ioctl function in drivers/tty/tty_io.c inthe Linux kernel through 4.4.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (use-after-free and system crash) by making a TIOCGETD ioctl call during processing of a TIOCSETD ioctl call. CVSS Base Score: 5.6 CVSS V2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0723</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.6</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0100.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="42" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4998</Title>
         <Notes>
               <Note Audience="All" Ordinal="42" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The IPT_SO_SET_REPLACE setsockopt implementation in the netfiltersubsystem in the Linux kernel before 4.6 allows local users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from kernel heap memory by leveraging in-container root access to provide a crafted offset value that leads to crossing a ruleset blob boundary. CVSS Base Score: 5.6 CVSS V2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4998</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.6</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0133.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="43" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4998</Title>
         <Notes>
               <Note Audience="All" Ordinal="43" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The IPT_SO_SET_REPLACE setsockopt implementation in the netfiltersubsystem in the Linux kernel before 4.6 allows local users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from kernel heap memory by leveraging in-container root access to provide a crafted offset value that leads to crossing a ruleset blob boundary. CVSS Base Score: 5.6 CVSS V2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4998</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.6</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0134.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="44" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8787</Title>
         <Notes>
               <Note Audience="All" Ordinal="44" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.cin the Linux kernel before 4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by sending certain IPv4 packets to an incompletely configured interface, a related issue to CVE-2003-1604. CVSS Base Score: 5.4 CVSS V2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8787</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.4</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0100.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="45" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8956</Title>
         <Notes>
               <Note Audience="All" Ordinal="45" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The rfcomm_sock_bind function in net/bluetooth/rfcomm/sock.c in theLinux kernel before 4.2 allows local users to obtain sensitive information or cause a denial of service (NULL pointer dereference) via vectors involving a bind system call on a Bluetooth RFCOMM socket. CVSS Base Score: 5.4 CVSS V2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8956</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.4</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0162.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="46" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8956</Title>
         <Notes>
               <Note Audience="All" Ordinal="46" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The rfcomm_sock_bind function in net/bluetooth/rfcomm/sock.c in theLinux kernel before 4.2 allows local users to obtain sensitive information or cause a denial of service (NULL pointer dereference) via vectors involving a bind system call on a Bluetooth RFCOMM socket. CVSS Base Score: 5.4 CVSS V2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8956</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.4</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0163.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="47" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8956</Title>
         <Notes>
               <Note Audience="All" Ordinal="47" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The rfcomm_sock_bind function in net/bluetooth/rfcomm/sock.c in theLinux kernel before 4.2 allows local users to obtain sensitive information or cause a denial of service (NULL pointer dereference) via vectors involving a bind system call on a Bluetooth RFCOMM socket. CVSS Base Score: 5.4 CVSS V2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8956</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.4</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0167.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="48" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2834</Title>
         <Notes>
               <Note Audience="All" Ordinal="48" Title="Details" Type="Details">This is a vulnerability in  nss nss-util  in Oracle VM Server for x86. Mozilla Network Security Services (NSS) before 3.23, as used inMozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2834</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0159.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="49" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2834</Title>
         <Notes>
               <Note Audience="All" Ordinal="49" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. Mozilla Network Security Services (NSS) before 3.23, as used inMozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2834</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0160.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="50" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2776</Title>
         <Notes>
               <Note Audience="All" Ordinal="50" Title="Details" Type="Details">This is a vulnerability in  bind  in Oracle VM Server for x86. buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query. CVSS Base Score: 5 CVSS V2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2776</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0136.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="51" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2776</Title>
         <Notes>
               <Note Audience="All" Ordinal="51" Title="Details" Type="Details">This is a vulnerability in  bind  in Oracle VM Server for x86. buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query. CVSS Base Score: 5 CVSS V2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2776</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0137.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="52" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2848</Title>
         <Notes>
               <Note Audience="All" Ordinal="52" Title="Details" Type="Details">This is a vulnerability in  bind  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5 CVSS V2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2848</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0145.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="53" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2848</Title>
         <Notes>
               <Note Audience="All" Ordinal="53" Title="Details" Type="Details">This is a vulnerability in  bind  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5 CVSS V2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2848</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0146.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="54" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-8864</Title>
         <Notes>
               <Note Audience="All" Ordinal="54" Title="Details" Type="Details">This is a vulnerability in  bind  in Oracle VM Server for x86. named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c. CVSS Base Score: 5 CVSS V2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-8864</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0152.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="55" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-8864</Title>
         <Notes>
               <Note Audience="All" Ordinal="55" Title="Details" Type="Details">This is a vulnerability in  bind  in Oracle VM Server for x86. named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c. CVSS Base Score: 5 CVSS V2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-8864</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0153.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="56" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2179</Title>
         <Notes>
               <Note Audience="All" Ordinal="56" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle VM Server for x86. The DTLS implementation in OpenSSL before 1.1.0 does not properlyrestrict the lifetime of queue entries associated with unused out-of-order messages, which allows remote attackers to cause a denial of service (memory consumption) by maintaining many crafted DTLS sessions simultaneously, related to d1_lib.c, statem_dtls.c, statem_lib.c, and statem_srvr.c. CVSS Base Score: 5 CVSS V2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2179</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0135.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="57" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-6304</Title>
         <Notes>
               <Note Audience="All" Ordinal="57" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle VM Server for x86. Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions. CVSS Base Score: 5 CVSS V2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-6304</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0135.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="58" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8816</Title>
         <Notes>
               <Note Audience="All" Ordinal="58" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The hub_activate function in drivers/usb/core/hub.c in the Linuxkernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device. CVSS Base Score: 4.9 CVSS V2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8816</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0100.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="59" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2847</Title>
         <Notes>
               <Note Audience="All" Ordinal="59" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. fs/pipe.c in the Linux kernel before 4.5 does not limit the amount ofunread data in pipes, which allows local users to cause a denial of service (memory consumption) by creating many pipes with non-default sizes. CVSS Base Score: 4.9 CVSS V2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2847</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0100.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="60" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4951</Title>
         <Notes>
               <Note Audience="All" Ordinal="60" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The tipc_nl_publ_dump function in net/tipc/socket.c in the Linuxkernel through 4.6 does not verify socket existence, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a dumpit operation. CVSS Base Score: 4.9 CVSS V2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4951</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0100.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="61" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-8650</Title>
         <Notes>
               <Note Audience="All" Ordinal="61" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through4.8.11 does not ensure that memory is allocated for limb data, which allows local users to cause a denial of service (stack memory corruption and panic) via an add_key system call for an RSA key with a zero exponent. CVSS Base Score: 4.9 CVSS V2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-8650</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0174.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="62" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-8650</Title>
         <Notes>
               <Note Audience="All" Ordinal="62" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through4.8.11 does not ensure that memory is allocated for limb data, which allows local users to cause a denial of service (stack memory corruption and panic) via an add_key system call for an RSA key with a zero exponent. CVSS Base Score: 4.9 CVSS V2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-8650</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0175.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="63" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-7777</Title>
         <Notes>
               <Note Audience="All" Ordinal="63" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, whichallows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruction while the hypervisor is preparing to emulate it. CVSS Base Score: 4.9 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-7777</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0164.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="64" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-7777</Title>
         <Notes>
               <Note Audience="All" Ordinal="64" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, whichallows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruction while the hypervisor is preparing to emulate it. CVSS Base Score: 4.9 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-7777</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0165.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="65" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-7777</Title>
         <Notes>
               <Note Audience="All" Ordinal="65" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, whichallows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruction while the hypervisor is preparing to emulate it. CVSS Base Score: 4.9 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-7777</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0166.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="66" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3070</Title>
         <Notes>
               <Note Audience="All" Ordinal="66" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The trace_writeback_dirty_page implementation ininclude/trace/events/writeback.h in the Linux kernel before 4.4 improperly interacts with mm/migrate.c, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by triggering a certain page move. CVSS Base Score: 4.7 CVSS V2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3070</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.7</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0162.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="67" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3070</Title>
         <Notes>
               <Note Audience="All" Ordinal="67" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The trace_writeback_dirty_page implementation ininclude/trace/events/writeback.h in the Linux kernel before 4.4 improperly interacts with mm/migrate.c, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by triggering a certain page move. CVSS Base Score: 4.7 CVSS V2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3070</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.7</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0163.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="68" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3070</Title>
         <Notes>
               <Note Audience="All" Ordinal="68" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The trace_writeback_dirty_page implementation ininclude/trace/events/writeback.h in the Linux kernel before 4.4 improperly interacts with mm/migrate.c, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by triggering a certain page move. CVSS Base Score: 4.7 CVSS V2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3070</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.7</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0167.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="69" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4581</Title>
         <Notes>
               <Note Audience="All" Ordinal="69" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. fs/pnode.c in the Linux kernel before 4.5.4 does not properly traversea mount propagation tree in a certain case involving a slave mount, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted series of mount system calls. CVSS Base Score: 4.7 CVSS V2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4581</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.7</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0100.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="70" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-6327</Title>
         <Notes>
               <Note Audience="All" Ordinal="70" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. drivers/infiniband/ulp/srpt/ib_srpt.c in the Linux kernel before 4.5.1allows local users to cause a denial of service (NULL pointer dereference and system crash) by using an ABORT_TASK command to abort a device write operation. CVSS Base Score: 4.7 CVSS V2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-6327</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.7</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0163.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="71" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-6480</Title>
         <Notes>
               <Note Audience="All" Ordinal="71" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. Race condition in the ioctl_send_fib function indrivers/scsi/aacraid/commctrl.c in the Linux kernel through 4.7 allows local users to cause a denial of service (out-of-bounds access or system crash) by changing a certain size value, aka a double CVSS Base Score: 4.7 CVSS V2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-6480</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.7</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0162.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="72" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-6480</Title>
         <Notes>
               <Note Audience="All" Ordinal="72" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. Race condition in the ioctl_send_fib function indrivers/scsi/aacraid/commctrl.c in the Linux kernel through 4.7 allows local users to cause a denial of service (out-of-bounds access or system crash) by changing a certain size value, aka a double CVSS Base Score: 4.7 CVSS V2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-6480</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.7</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0163.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="73" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-6480</Title>
         <Notes>
               <Note Audience="All" Ordinal="73" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. Race condition in the ioctl_send_fib function indrivers/scsi/aacraid/commctrl.c in the Linux kernel through 4.7 allows local users to cause a denial of service (out-of-bounds access or system crash) by changing a certain size value, aka a double CVSS Base Score: 4.7 CVSS V2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-6480</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.7</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0167.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="74" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2053</Title>
         <Notes>
               <Note Audience="All" Ordinal="74" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The asn1_ber_decoder function in lib/asn1_decoder.c in the Linuxkernel before 4.3 allows attackers to cause a denial of service (panic) via an ASN.1 BER file that lacks a public key, leading to mishandling by the public_key_verify_signature function in crypto/asymmetric_keys/public_key.c. CVSS Base Score: 4.6 CVSS V2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2053</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.6</BaseScore>
               <Vector>AV:L/AC:L/Au:S/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0162.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="75" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2053</Title>
         <Notes>
               <Note Audience="All" Ordinal="75" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The asn1_ber_decoder function in lib/asn1_decoder.c in the Linuxkernel before 4.3 allows attackers to cause a denial of service (panic) via an ASN.1 BER file that lacks a public key, leading to mishandling by the public_key_verify_signature function in crypto/asymmetric_keys/public_key.c. CVSS Base Score: 4.6 CVSS V2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2053</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.6</BaseScore>
               <Vector>AV:L/AC:L/Au:S/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0163.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="76" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9379</Title>
         <Notes>
               <Note Audience="All" Ordinal="76" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.6 CVSS V2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9379</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.6</BaseScore>
               <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0164.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="77" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9379</Title>
         <Notes>
               <Note Audience="All" Ordinal="77" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.6 CVSS V2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9379</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.6</BaseScore>
               <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0165.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="78" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9379</Title>
         <Notes>
               <Note Audience="All" Ordinal="78" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.6 CVSS V2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9379</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.6</BaseScore>
               <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0166.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="79" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9380</Title>
         <Notes>
               <Note Audience="All" Ordinal="79" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.6 CVSS V2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9380</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.6</BaseScore>
               <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0164.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="80" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9380</Title>
         <Notes>
               <Note Audience="All" Ordinal="80" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.6 CVSS V2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9380</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.6</BaseScore>
               <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0165.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="81" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9380</Title>
         <Notes>
               <Note Audience="All" Ordinal="81" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.6 CVSS V2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9380</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.6</BaseScore>
               <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0166.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="82" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9382</Title>
         <Notes>
               <Note Audience="All" Ordinal="82" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.6 CVSS V2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9382</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.6</BaseScore>
               <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0164.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="83" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9382</Title>
         <Notes>
               <Note Audience="All" Ordinal="83" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.6 CVSS V2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9382</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.6</BaseScore>
               <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0165.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="84" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9382</Title>
         <Notes>
               <Note Audience="All" Ordinal="84" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.6 CVSS V2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9382</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.6</BaseScore>
               <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0166.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="85" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-5285</Title>
         <Notes>
               <Note Audience="All" Ordinal="85" Title="Details" Type="Details">This is a vulnerability in  nss nss-util  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-5285</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0159.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="86" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-8635</Title>
         <Notes>
               <Note Audience="All" Ordinal="86" Title="Details" Type="Details">This is a vulnerability in  nss nss-util  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-8635</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0159.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="87" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-5285</Title>
         <Notes>
               <Note Audience="All" Ordinal="87" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-5285</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0160.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="88" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-8635</Title>
         <Notes>
               <Note Audience="All" Ordinal="88" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-8635</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0160.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="89" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2181</Title>
         <Notes>
               <Note Audience="All" Ordinal="89" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle VM Server for x86. The Anti-Replay feature in the DTLS implementation in OpenSSL before1.1.0 mishandles early use of a new epoch number in conjunction with a large sequence number, which allows remote attackers to cause a denial of service (false-positive packet drops) via spoofed DTLS records, related to rec_layer_d1.c and ssl3_record.c. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2181</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0135.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="90" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2182</Title>
         <Notes>
               <Note Audience="All" Ordinal="90" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle VM Server for x86. The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0does not properly validate division results, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2182</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0135.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="91" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2182</Title>
         <Notes>
               <Note Audience="All" Ordinal="91" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle VM Server for x86. The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0does not properly validate division results, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2182</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0141.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="92" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2183</Title>
         <Notes>
               <Note Audience="All" Ordinal="92" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle VM Server for x86. The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSecprotocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a Sweet32 attack. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2183</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0141.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="93" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-6302</Title>
         <Notes>
               <Note Audience="All" Ordinal="93" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle VM Server for x86. The tls_decrypt_ticket function in ssl/t1_lib.c in OpenSSL before1.1.0 does not consider the HMAC size during validation of the ticket length, which allows remote attackers to cause a denial of service via a ticket that is too short. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-6302</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0135.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="94" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-6313</Title>
         <Notes>
               <Note Audience="All" Ordinal="94" Title="Details" Type="Details">This is a vulnerability in  libgcrypt  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-6313</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0156.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="95" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2069</Title>
         <Notes>
               <Note Audience="All" Ordinal="95" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. Race condition in arch/x86/mm/tlb.c in the Linux kernel before 4.4.1allows local users to gain privileges by triggering access to a paging structure by a different CPU. CVSS Base Score: 3.7 CVSS V2 Vector: AV:L/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2069</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.7</BaseScore>
               <Vector>AV:L/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0100.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="96" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8374</Title>
         <Notes>
               <Note Audience="All" Ordinal="96" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandlescompressed inline extents, which allows local users to obtain sensitive pre-truncation information from a file via a clone action. CVSS Base Score: 3.5 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8374</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.5</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0158.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="97" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8374</Title>
         <Notes>
               <Note Audience="All" Ordinal="97" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandlescompressed inline extents, which allows local users to obtain sensitive pre-truncation information from a file via a clone action. CVSS Base Score: 3.5 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8374</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.5</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0133.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="98" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3699</Title>
         <Notes>
               <Note Audience="All" Ordinal="98" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red HatEnterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended Secure Boot restrictions and execute untrusted code by appending ACPI tables to the initrd. CVSS Base Score: 3.3 CVSS V2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3699</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.3</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:N/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0162.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="99" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3699</Title>
         <Notes>
               <Note Audience="All" Ordinal="99" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red HatEnterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended Secure Boot restrictions and execute untrusted code by appending ACPI tables to the initrd. CVSS Base Score: 3.3 CVSS V2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3699</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.3</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:N/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0163.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="100" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-6136</Title>
         <Notes>
               <Note Audience="All" Ordinal="100" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. Race condition in the audit_log_single_execve_arg function inkernel/auditsc.c in the Linux kernel through 4.7 allows local users to bypass intended character-set restrictions or disrupt system-call auditing by changing a certain string, aka a double CVSS Base Score: 3.3 CVSS V2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-6136</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.3</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0162.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="101" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-6136</Title>
         <Notes>
               <Note Audience="All" Ordinal="101" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. Race condition in the audit_log_single_execve_arg function inkernel/auditsc.c in the Linux kernel through 4.7 allows local users to bypass intended character-set restrictions or disrupt system-call auditing by changing a certain string, aka a double CVSS Base Score: 3.3 CVSS V2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-6136</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.3</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0163.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="102" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-6136</Title>
         <Notes>
               <Note Audience="All" Ordinal="102" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. Race condition in the audit_log_single_execve_arg function inkernel/auditsc.c in the Linux kernel through 4.7 allows local users to bypass intended character-set restrictions or disrupt system-call auditing by changing a certain string, aka a double CVSS Base Score: 3.3 CVSS V2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-6136</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.3</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0167.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="103" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2117</Title>
         <Notes>
               <Note Audience="All" Ordinal="103" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c inthe Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which allows remote attackers to obtain sensitive information from kernel memory by reading packet data. CVSS Base Score: 2.6 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2117</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.6</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0158.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="104" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2177</Title>
         <Notes>
               <Note Audience="All" Ordinal="104" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle VM Server for x86. OpenSSL through 1.0.2h incorrectly uses pointer arithmetic forheap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging unexpected malloc behavior, related to s3_srvr.c, ssl_sess.c, and t1_lib.c. CVSS Base Score: 2.6 CVSS V2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2177</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.6</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0135.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="105" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2177</Title>
         <Notes>
               <Note Audience="All" Ordinal="105" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle VM Server for x86. OpenSSL through 1.0.2h incorrectly uses pointer arithmetic forheap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging unexpected malloc behavior, related to s3_srvr.c, ssl_sess.c, and t1_lib.c. CVSS Base Score: 2.6 CVSS V2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2177</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.6</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0141.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="106" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8785</Title>
         <Notes>
               <Note Audience="All" Ordinal="106" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The fuse_fill_write_pages function in fs/fuse/file.c in the Linuxkernel before 4.4 allows local users to cause a denial of service (infinite loop) via a writev system call that triggers a zero length for the first segment of an iov. CVSS Base Score: 2.1 CVSS V2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8785</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.1</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0100.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="107" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4569</Title>
         <Notes>
               <Note Audience="All" Ordinal="107" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The snd_timer_user_params function in sound/core/timer.c in the Linuxkernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface. CVSS Base Score: 2.1 CVSS V2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4569</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.1</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0162.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="108" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4569</Title>
         <Notes>
               <Note Audience="All" Ordinal="108" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The snd_timer_user_params function in sound/core/timer.c in the Linuxkernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface. CVSS Base Score: 2.1 CVSS V2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4569</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.1</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0163.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="109" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4569</Title>
         <Notes>
               <Note Audience="All" Ordinal="109" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The snd_timer_user_params function in sound/core/timer.c in the Linuxkernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface. CVSS Base Score: 2.1 CVSS V2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4569</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.1</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0167.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="110" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4578</Title>
         <Notes>
               <Note Audience="All" Ordinal="110" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. sound/core/timer.c in the Linux kernel through 4.6 does not initializecertain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_timer_user_ccallback and (2) snd_timer_user_tinterrupt functions. CVSS Base Score: 2.1 CVSS V2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4578</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.1</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0162.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="111" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4578</Title>
         <Notes>
               <Note Audience="All" Ordinal="111" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. sound/core/timer.c in the Linux kernel through 4.6 does not initializecertain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_timer_user_ccallback and (2) snd_timer_user_tinterrupt functions. CVSS Base Score: 2.1 CVSS V2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4578</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.1</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0163.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="112" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4578</Title>
         <Notes>
               <Note Audience="All" Ordinal="112" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. sound/core/timer.c in the Linux kernel through 4.6 does not initializecertain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_timer_user_ccallback and (2) snd_timer_user_tinterrupt functions. CVSS Base Score: 2.1 CVSS V2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4578</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.1</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0167.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="113" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4913</Title>
         <Notes>
               <Note Audience="All" Ordinal="113" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The get_rock_ridge_filename function in fs/isofs/rock.c in the Linuxkernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem. CVSS Base Score: 2.1 CVSS V2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4913</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.1</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0100.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="114" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4805</Title>
         <Notes>
               <Note Audience="All" Ordinal="114" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in theLinux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a network namespace, related to the ppp_register_net_channel and ppp_unregister_channel functions. CVSS Base Score: 1.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4805</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>1.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0100.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="115" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2178</Title>
         <Notes>
               <Note Audience="All" Ordinal="115" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle VM Server for x86. The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSLthrough 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack. CVSS Base Score: 1.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2178</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>1.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0135.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="116" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2178</Title>
         <Notes>
               <Note Audience="All" Ordinal="116" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle VM Server for x86. The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSLthrough 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack. CVSS Base Score: 1.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2178</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>1.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0141.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="117" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2180</Title>
         <Notes>
               <Note Audience="All" Ordinal="117" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle VM Server for x86. The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in OpenSSL through 1.0.2h allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted time-stamp file that is mishandled by the openssl CVSS Base Score: 1.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2180</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>1.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0135.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="118" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3156</Title>
         <Notes>
               <Note Audience="All" Ordinal="118" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The IPv4 implementation in the Linux kernel before 4.5.2 mishandlesdestruction of device objects, which allows guest OS users to cause a denial of service (host OS networking outage) by arranging for a large number of IP addresses. CVSS Base Score: 1.7 CVSS V2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3156</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>1.7</BaseScore>
               <Vector>AV:L/AC:L/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0100.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="119" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-6306</Title>
         <Notes>
               <Note Audience="All" Ordinal="119" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle VM Server for x86. The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c. CVSS Base Score: 1.2 CVSS V2 Vector: AV:L/AC:H/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-6306</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>1.2</BaseScore>
               <Vector>AV:L/AC:H/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0135.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="120" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-6306</Title>
         <Notes>
               <Note Audience="All" Ordinal="120" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle VM Server for x86. The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c. CVSS Base Score: 1.2 CVSS V2 Vector: AV:L/AC:H/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-6306</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>1.2</BaseScore>
               <Vector>AV:L/AC:H/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0141.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="121" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9932</Title>
         <Notes>
               <Note Audience="All" Ordinal="121" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 0 CVSS V2 Vector: AV:N/AC:N/Au:N/C:N/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9932</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>0</BaseScore>
               <Vector>AV:N/AC:N/Au:N/C:N/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0176.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="122" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9932</Title>
         <Notes>
               <Note Audience="All" Ordinal="122" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 0 CVSS V2 Vector: AV:N/AC:N/Au:N/C:N/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9932</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>0</BaseScore>
               <Vector>AV:N/AC:N/Au:N/C:N/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0177.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="123" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-9932</Title>
         <Notes>
               <Note Audience="All" Ordinal="123" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 0 CVSS V2 Vector: AV:N/AC:N/Au:N/C:N/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-9932</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>0</BaseScore>
               <Vector>AV:N/AC:N/Au:N/C:N/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0178.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
</cvrf:cvrfdoc>
