CVE-2014-1666
- EPSS 3.25%
- Veröffentlicht 26.01.2014 16:58:11
- Zuletzt bearbeitet 11.04.2025 00:51:21
The do_physdev_op function in Xen 4.1.5, 4.1.6.1, 4.2.2 through 4.2.3, and 4.3.x does not properly restrict access to the (1) PHYSDEVOP_prepare_msix and (2) PHYSDEVOP_release_msix operations, which allows local PV guests to cause a denial of service ...
CVE-2013-4375
- EPSS 0.09%
- Veröffentlicht 19.01.2014 18:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The qdisk PV disk backend in qemu-xen in Xen 4.2.x and 4.3.x before 4.3.1, and qemu 1.1 and other versions, allows local HVM guests to cause a denial of service (domain grant reference consumption) via unspecified vectors.
CVE-2011-1166
- EPSS 0.11%
- Veröffentlicht 07.01.2014 19:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of service (host crash) by specifying user mode execution without user-mode pagetables.
CVE-2011-1780
- EPSS 0.23%
- Veröffentlicht 07.01.2014 19:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The instruction emulation in Xen 3.0.3 allows local SMP guest users to cause a denial of service (host crash) by replacing the instruction that causes the VM to exit in one thread with a different instruction in a different thread.
CVE-2011-1936
- EPSS 0.08%
- Veröffentlicht 07.01.2014 19:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen, when using x86 Intel processors and the VMX virtualization extension is enabled, does not properly handle cpuid instruction emulation when exiting the VM, which allows local guest users to cause a denial of service (guest crash) via unspecified ...
CVE-2011-2519
- EPSS 0.14%
- Veröffentlicht 27.12.2013 01:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen in the Linux kernel, when running a guest on a host without hardware assisted paging (HAP), allows guest users to cause a denial of service (invalid pointer dereference and hypervisor crash) via the SAHF instruction.
CVE-2013-4553
- EPSS 0.33%
- Veröffentlicht 24.12.2013 19:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
The XEN_DOMCTL_getmemlist hypercall in Xen 3.4.x through 4.3.x (possibly 4.3.1) does not always obtain the page_alloc_lock and mm_rwlock in the same order, which allows local guest administrators to cause a denial of service (host deadlock).
CVE-2013-4554
- EPSS 0.21%
- Veröffentlicht 24.12.2013 19:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 3.0.3 through 4.1.x (possibly 4.1.6.1), 4.2.x (possibly 4.2.3), and 4.3.x (possibly 4.3.1) does not properly prevent access to hypercalls, which allows local guest users to gain privileges via a crafted application running in ring 1 or 2.
CVE-2013-6400
- EPSS 0.39%
- Veröffentlicht 13.12.2013 18:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.2.x and 4.3.x, when using Intel VT-d and a PCI device has been assigned, does not clear the flag that suppresses IOMMU TLB flushes when unspecified errors occur, which causes the TLB entries to not be flushed and allows local guest administrato...
CVE-2013-6375
- EPSS 0.63%
- Veröffentlicht 23.11.2013 11:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properly flush the TLB after clearing a present translation table entry, which allows local guest administrators to cause a denial of service or gain privileges via unspecified ...