CVE-2014-2986
- EPSS 0.21%
- Published 28.04.2014 14:09:08
- Last modified 12.04.2025 10:46:40
The vgic_distr_mmio_write function in the virtual guest interrupt controller (GIC) distributor (arch/arm/vgic.c) in Xen 4.4.x, when running on an ARM system, allows local guest users to cause a denial of service (NULL pointer dereference and host cra...
CVE-2014-2915
- EPSS 0.12%
- Published 24.04.2014 14:55:04
- Last modified 12.04.2025 10:46:40
Xen 4.4.x, when running on ARM systems, does not properly restrict access to hardware features, which allows local guest users to cause a denial of service (host or guest crash) via unspecified vectors, related to (1) cache control, (2) coprocessors,...
CVE-2014-2580
- EPSS 0.07%
- Published 15.04.2014 23:13:13
- Last modified 12.04.2025 10:46:40
The netback driver in Xen, when using certain Linux versions that do not allow sleeping in softirq context, allows local guest administrators to cause a denial of service ("scheduling while atomic" error and host crash) via a malformed packet, which ...
CVE-2014-1891
- EPSS 0.32%
- Published 01.04.2014 06:35:53
- Last modified 12.04.2025 10:46:40
Multiple integer overflows in the (1) FLASK_GETBOOL, (2) FLASK_SETBOOL, (3) FLASK_USER, and (4) FLASK_CONTEXT_TO_SID suboperations in the flask hypercall in Xen 4.3.x, 4.2.x, 4.1.x, 3.2.x, and earlier, when XSM is enabled, allow local users to cause ...
CVE-2014-1892
- EPSS 0.32%
- Published 01.04.2014 06:35:53
- Last modified 12.04.2025 10:46:40
Xen 3.3 through 4.1, when XSM is enabled, allows local users to cause a denial of service via vectors related to a "large memory allocation," a different vulnerability than CVE-2014-1891, CVE-2014-1893, and CVE-2014-1894.
CVE-2014-1893
- EPSS 0.32%
- Published 01.04.2014 06:35:53
- Last modified 12.04.2025 10:46:40
Multiple integer overflows in the (1) FLASK_GETBOOL and (2) FLASK_SETBOOL suboperations in the flask hypercall in Xen 4.1.x, 3.3.x, 3.2.x, and earlier, when XSM is enabled, allow local users to cause a denial of service (processor fault) via unspecif...
CVE-2014-1894
- EPSS 0.32%
- Published 01.04.2014 06:35:53
- Last modified 12.04.2025 10:46:40
Multiple integer overflows in unspecified suboperations in the flask hypercall in Xen 3.2.x and earlier, when XSM is enabled, allow local users to cause a denial of service (processor fault) via unspecified vectors, a different vulnerability than CVE...
CVE-2014-1895
- EPSS 0.11%
- Published 01.04.2014 06:35:53
- Last modified 12.04.2025 10:46:40
Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op.c in Xen 4.2.x and 4.3.x, when the maximum number of physical CPUs are in use, allows local users to cause a denial of service (host crash) or obtain sensitive infor...
CVE-2014-1896
- EPSS 0.14%
- Published 01.04.2014 06:35:53
- Last modified 12.04.2025 10:46:40
The (1) do_send and (2) do_recv functions in io.c in libvchan in Xen 4.2.x, 4.3.x, and 4.4-RC series allows local guests to cause a denial of service or possibly gain privileges via crafted xenstore ring indexes, which triggers a "read or write past ...
- EPSS 0.12%
- Published 01.04.2014 06:35:52
- Last modified 12.04.2025 10:46:40
Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the CD-ROM to cause a denial of service (guest crash) via a crafted SAI READ CAPACITY SCSI command....