CVE-2013-4369
- EPSS 0.06%
- Veröffentlicht 17.10.2013 23:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The xlu_vif_parse_rate function in the libxlu library in Xen 4.2.x and 4.3.x allows local users to cause a denial of service (NULL pointer dereference) by using the "@" character as the VIF rate configuration.
CVE-2013-4370
- EPSS 0.09%
- Veröffentlicht 17.10.2013 23:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ocaml binding for the xc_vcpu_getaffinity function in Xen 4.2.x and 4.3.x frees certain memory that may still be intended for use, which allows local users to cause a denial of service (heap corruption and crash) and possibly execute arbitrary co...
CVE-2013-4371
- EPSS 0.08%
- Veröffentlicht 17.10.2013 23:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the libxl_list_cpupool function in the libxl toolstack library in Xen 4.2.x and 4.3.x, when running "under memory pressure," returns the original pointer when the realloc function fails, which allows local users to cau...
CVE-2013-4356
- EPSS 0.09%
- Veröffentlicht 09.10.2013 22:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more than 5TB of RAM, which allows local 64-bit PV guests to read or write to invalid memory and cause a denial of service (crash).
CVE-2013-4355
- EPSS 0.09%
- Veröffentlicht 01.10.2013 17:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.3.x and earlier does not properly handle certain errors, which allows local HVM guests to obtain hypervisor stack memory via a (1) port or (2) memory mapped I/O write or (3) other unspecified operations related to addresses without associated m...
CVE-2013-4361
- EPSS 0.11%
- Veröffentlicht 01.10.2013 17:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the correct variable for the source effective address, which allows local HVM guests to obtain hypervisor stack information by reading the values used by the instruction.
CVE-2011-2901
- EPSS 0.12%
- Veröffentlicht 01.10.2013 17:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Off-by-one error in the __addr_ok macro in Xen 3.3 and earlier allows local 64 bit PV guest administrators to cause a denial of service (host crash) via unspecified hypercalls that ignore virtual-address bits.
CVE-2013-1442
- EPSS 0.11%
- Veröffentlicht 30.09.2013 21:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly clear previous data from registers when using an XSAVE or XRSTOR to extend the state components of a saved or restored vCPU after touching other restored extended registers,...
CVE-2013-4329
- EPSS 0.16%
- Veröffentlicht 12.09.2013 18:37:43
- Zuletzt bearbeitet 11.04.2025 00:51:21
The xenlight library (libxl) in Xen 4.0.x through 4.2.x, when IOMMU is disabled, provides access to a busmastering-capable PCI passthrough device before the IOMMU setup is complete, which allows local HVM guest domains to gain privileges or cause a d...
CVE-2013-1432
- EPSS 0.41%
- Veröffentlicht 28.08.2013 21:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.1.x and 4.2.x, when the XSA-45 patch is in place, does not properly maintain references on pages stored for deferred cleanup, which allows local PV guest kernels to cause a denial of service (premature page free and hypervisor crash) or possibl...