Search/CVE-2008-3687
CVE

CVE-2008-3687

Heap-based buffer overflow in the flask_security_label function in Xen 3.3, when compiled with the XSM:FLASK module, allows unprivileged domain users (domU) to execute arbitrary code via the flask_op hypercall.

CVSS v3.1
EPSS
2.94%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
Connections
3 relationships
Timeline
disclosure → media coverage
Aug 14, 2008
Disclosure — published as a CVE record. · last revised by NVD Apr 23, 2026