CVE-2014-1895
- EPSS 0.11%
- Veröffentlicht 01.04.2014 06:35:53
- Zuletzt bearbeitet 12.04.2025 10:46:40
Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op.c in Xen 4.2.x and 4.3.x, when the maximum number of physical CPUs are in use, allows local users to cause a denial of service (host crash) or obtain sensitive infor...
CVE-2014-1896
- EPSS 0.14%
- Veröffentlicht 01.04.2014 06:35:53
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) do_send and (2) do_recv functions in io.c in libvchan in Xen 4.2.x, 4.3.x, and 4.4-RC series allows local guests to cause a denial of service or possibly gain privileges via crafted xenstore ring indexes, which triggers a "read or write past ...
- EPSS 0.12%
- Veröffentlicht 01.04.2014 06:35:52
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the CD-ROM to cause a denial of service (guest crash) via a crafted SAI READ CAPACITY SCSI command....
CVE-2014-2599
- EPSS 0.08%
- Veröffentlicht 28.03.2014 15:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The HVMOP_set_mem_access HVM control operations in Xen 4.1.x for 32-bit and 4.1.x through 4.4.x for 64-bit allow local guest administrators to cause a denial of service (CPU consumption) by leveraging access to certain service domains for HVM guests ...
CVE-2014-1950
- EPSS 0.08%
- Veröffentlicht 14.02.2014 15:55:06
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the xc_cpupool_getinfo function in Xen 4.1.x through 4.3.x, when using a multithreaded toolstack, does not properly handle a failure by the xc_cpumap_alloc function, which allows local users with access to management f...
CVE-2014-1642
- EPSS 0.18%
- Veröffentlicht 26.01.2014 16:58:11
- Zuletzt bearbeitet 11.04.2025 00:51:21
The IRQ setup in Xen 4.2.x and 4.3.x, when using device passthrough and configured to support a large number of CPUs, frees certain memory that may still be intended for use, which allows local guest administrators to cause a denial of service (memor...
CVE-2014-1666
- EPSS 3.25%
- Veröffentlicht 26.01.2014 16:58:11
- Zuletzt bearbeitet 11.04.2025 00:51:21
The do_physdev_op function in Xen 4.1.5, 4.1.6.1, 4.2.2 through 4.2.3, and 4.3.x does not properly restrict access to the (1) PHYSDEVOP_prepare_msix and (2) PHYSDEVOP_release_msix operations, which allows local PV guests to cause a denial of service ...
CVE-2013-4375
- EPSS 0.09%
- Veröffentlicht 19.01.2014 18:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The qdisk PV disk backend in qemu-xen in Xen 4.2.x and 4.3.x before 4.3.1, and qemu 1.1 and other versions, allows local HVM guests to cause a denial of service (domain grant reference consumption) via unspecified vectors.
CVE-2011-1166
- EPSS 0.11%
- Veröffentlicht 07.01.2014 19:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of service (host crash) by specifying user mode execution without user-mode pagetables.
CVE-2011-1780
- EPSS 0.23%
- Veröffentlicht 07.01.2014 19:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The instruction emulation in Xen 3.0.3 allows local SMP guest users to cause a denial of service (host crash) by replacing the instruction that causes the VM to exit in one thread with a different instruction in a different thread.