CVE-2013-4356
- EPSS 0.09%
- Veröffentlicht 09.10.2013 22:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more than 5TB of RAM, which allows local 64-bit PV guests to read or write to invalid memory and cause a denial of service (crash).
CVE-2013-4355
- EPSS 0.09%
- Veröffentlicht 01.10.2013 17:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.3.x and earlier does not properly handle certain errors, which allows local HVM guests to obtain hypervisor stack memory via a (1) port or (2) memory mapped I/O write or (3) other unspecified operations related to addresses without associated m...
CVE-2013-4361
- EPSS 0.11%
- Veröffentlicht 01.10.2013 17:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the correct variable for the source effective address, which allows local HVM guests to obtain hypervisor stack information by reading the values used by the instruction.
CVE-2011-2901
- EPSS 0.12%
- Veröffentlicht 01.10.2013 17:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Off-by-one error in the __addr_ok macro in Xen 3.3 and earlier allows local 64 bit PV guest administrators to cause a denial of service (host crash) via unspecified hypercalls that ignore virtual-address bits.
CVE-2013-1442
- EPSS 0.11%
- Veröffentlicht 30.09.2013 21:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly clear previous data from registers when using an XSAVE or XRSTOR to extend the state components of a saved or restored vCPU after touching other restored extended registers,...
CVE-2013-4329
- EPSS 0.16%
- Veröffentlicht 12.09.2013 18:37:43
- Zuletzt bearbeitet 11.04.2025 00:51:21
The xenlight library (libxl) in Xen 4.0.x through 4.2.x, when IOMMU is disabled, provides access to a busmastering-capable PCI passthrough device before the IOMMU setup is complete, which allows local HVM guest domains to gain privileges or cause a d...
CVE-2013-1432
- EPSS 0.41%
- Veröffentlicht 28.08.2013 21:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.1.x and 4.2.x, when the XSA-45 patch is in place, does not properly maintain references on pages stored for deferred cleanup, which allows local PV guest kernels to cause a denial of service (premature page free and hypervisor crash) or possibl...
CVE-2013-2072
- EPSS 0.41%
- Veröffentlicht 28.08.2013 21:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4.0.x, 4.1.x, and 4.2.x allows local administrators with permissions to configure VCPU affinity to cause a denial of service (memory corruption and xend toolstack crash) a...
CVE-2013-2076
- EPSS 0.18%
- Veröffentlicht 28.08.2013 21:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.0.x, 4.1.x, and 4.2.x, when running on AMD64 processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one domain to determine portions of the state of floating point instruct...
CVE-2013-2077
- EPSS 0.12%
- Veröffentlicht 28.08.2013 21:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.0.x, 4.1.x, and 4.2.x does not properly restrict the contents of a XRSTOR, which allows local PV guest users to cause a denial of service (unhandled exception and hypervisor crash) via unspecified vectors.