CVE-2014-7155
- EPSS 1.03%
- Veröffentlicht 02.10.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which allows local HVM users to cause a denial of service (guest crash) or gain guest kernel mode privileges ...
CVE-2014-7156
- EPSS 0.8%
- Veröffentlicht 02.10.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 3.3.x through 4.4.x does not check the supervisor mode permissions for instructions that generate software interrupts, which allows local HVM guest users to cause a denial of servi...
CVE-2014-7188
- EPSS 2.55%
- Veröffentlicht 02.10.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The hvm_msr_read_intercept function in arch/x86/hvm/hvm.c in Xen 4.1 through 4.4.x uses an improper MSR range for x2APIC emulation, which allows local HVM guests to cause a denial of service (host crash) or read data from the hypervisor or other gues...
CVE-2014-5147
- EPSS 0.21%
- Veröffentlicht 29.08.2014 16:55:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
Xen 4.4.x, when running a 64-bit kernel on an ARM system, does not properly handle traps from the guest domain that use a different address width, which allows local guest users to cause a denial of service (host crash) via a crafted 32-bit process.
CVE-2014-5146
- EPSS 0.07%
- Veröffentlicht 22.08.2014 14:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Certain MMU virtualization operations in Xen 4.2.x through 4.4.x before the xsa97-hap patch, when using Hardware Assisted Paging (HAP), are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking thes...
CVE-2014-5149
- EPSS 0.07%
- Veröffentlicht 22.08.2014 14:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using shadow pagetables, are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page a...
CVE-2014-4022
- EPSS 0.17%
- Veröffentlicht 09.07.2014 14:55:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The alloc_domain_struct function in arch/arm/domain.c in Xen 4.4.x, when running on an ARM platform, does not properly initialize the structure containing the grant table pages for a domain, which allows local guest administrators to obtain sensitive...
CVE-2014-4021
- EPSS 0.23%
- Veröffentlicht 18.06.2014 19:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Xen 3.2.x through 4.4.x does not properly clean memory pages recovered from guests, which allows local guest OS users to obtain sensitive information via unspecified vectors.
CVE-2014-3967
- EPSS 0.26%
- Veröffentlicht 05.06.2014 20:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x does not properly check the return value from the IRQ setup check, which allows local HVM guest administrators to cause a denial of service (NULL pointer dereference and crash) via unspecif...
CVE-2014-3968
- EPSS 0.38%
- Veröffentlicht 05.06.2014 20:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x allows local guest HVM administrators to cause a denial of service (host crash) via a large number of crafted requests, which trigger an error messages to be logged.