CVE-2013-2211
- EPSS 0.23%
- Published 28.08.2013 21:55:08
- Last modified 11.04.2025 00:51:21
The libxenlight (libxl) toolstack library in Xen 4.0.x, 4.1.x, and 4.2.x uses weak permissions for xenstore keys for paravirtualised and emulated serial console devices, which allows local guest administrators to modify the xenstore value via unspeci...
CVE-2013-2212
- EPSS 0.18%
- Published 28.08.2013 21:55:08
- Last modified 11.04.2025 00:51:21
The vmx_set_uc_mode function in Xen 3.3 through 4.3, when disabling caches, allows local HVM guests with access to memory mapped I/O regions to cause a denial of service (CPU consumption and possibly hypervisor or guest kernel panic) via a crafted GF...
CVE-2013-3495
- EPSS 0.08%
- Published 28.08.2013 21:55:08
- Last modified 11.04.2025 00:51:21
The Intel VT-d Interrupt Remapping engine in Xen 3.3.x through 4.3.x allows local guests to cause a denial of service (kernel panic) via a malformed Message Signaled Interrupt (MSI) from a PCI device that is bus mastering capable that triggers a Syst...
CVE-2013-2194
- EPSS 0.04%
- Published 23.08.2013 16:55:07
- Last modified 11.04.2025 00:51:21
Multiple integer overflows in the Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an unspecified impact via a crafted kernel.
CVE-2013-2195
- EPSS 0.04%
- Published 23.08.2013 16:55:07
- Last modified 11.04.2025 00:51:21
The Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an unspecified impact via a crafted kernel, related to "pointer dereferences" involving unexpected calculations.
CVE-2013-2196
- EPSS 0.04%
- Published 23.08.2013 16:55:07
- Last modified 11.04.2025 00:51:21
Multiple unspecified vulnerabilities in the Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an unspecified impact via a crafted kernel, related to "other problems" that are not CVE-2013-2...
CVE-2013-2078
- EPSS 0.06%
- Published 14.08.2013 15:55:06
- Last modified 11.04.2025 00:51:21
Xen 4.0.2 through 4.0.4, 4.1.x, and 4.2.x allows local PV guest users to cause a denial of service (hypervisor crash) via certain bit combinations to the XSETBV instruction.
CVE-2013-1964
- EPSS 0.08%
- Published 21.05.2013 18:55:01
- Last modified 11.04.2025 00:51:21
Xen 4.0.x and 4.1.x incorrectly releases a grant reference when releasing a non-v1, non-transitive grant, which allows local guest administrators to cause a denial of service (host crash), obtain sensitive information, or possibly have other impacts ...
CVE-2013-1952
- EPSS 0.07%
- Published 13.05.2013 23:55:02
- Last modified 11.04.2025 00:51:21
Xen 4.x, when using Intel VT-d for a bus mastering capable PCI device, does not properly check the source when accessing a bridge device's interrupt remapping table entries for MSI interrupts, which allows local guest domains to cause a denial of ser...
CVE-2013-1917
- EPSS 0.07%
- Published 13.05.2013 23:55:01
- Last modified 11.04.2025 00:51:21
Xen 3.1 through 4.x, when running 64-bit hosts on Intel CPUs, does not clear the NT flag when using an IRET after a SYSENTER instruction, which allows PV guest users to cause a denial of service (hypervisor crash) by triggering a #GP fault, which is ...