CVE-2013-2211
- EPSS 0.23%
- Veröffentlicht 28.08.2013 21:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
The libxenlight (libxl) toolstack library in Xen 4.0.x, 4.1.x, and 4.2.x uses weak permissions for xenstore keys for paravirtualised and emulated serial console devices, which allows local guest administrators to modify the xenstore value via unspeci...
CVE-2013-2212
- EPSS 0.18%
- Veröffentlicht 28.08.2013 21:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
The vmx_set_uc_mode function in Xen 3.3 through 4.3, when disabling caches, allows local HVM guests with access to memory mapped I/O regions to cause a denial of service (CPU consumption and possibly hypervisor or guest kernel panic) via a crafted GF...
CVE-2013-3495
- EPSS 0.08%
- Veröffentlicht 28.08.2013 21:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Intel VT-d Interrupt Remapping engine in Xen 3.3.x through 4.3.x allows local guests to cause a denial of service (kernel panic) via a malformed Message Signaled Interrupt (MSI) from a PCI device that is bus mastering capable that triggers a Syst...
CVE-2013-2194
- EPSS 0.04%
- Veröffentlicht 23.08.2013 16:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple integer overflows in the Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an unspecified impact via a crafted kernel.
CVE-2013-2195
- EPSS 0.04%
- Veröffentlicht 23.08.2013 16:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an unspecified impact via a crafted kernel, related to "pointer dereferences" involving unexpected calculations.
CVE-2013-2196
- EPSS 0.04%
- Veröffentlicht 23.08.2013 16:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple unspecified vulnerabilities in the Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an unspecified impact via a crafted kernel, related to "other problems" that are not CVE-2013-2...
CVE-2013-2078
- EPSS 0.06%
- Veröffentlicht 14.08.2013 15:55:06
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.0.2 through 4.0.4, 4.1.x, and 4.2.x allows local PV guest users to cause a denial of service (hypervisor crash) via certain bit combinations to the XSETBV instruction.
CVE-2013-1964
- EPSS 0.08%
- Veröffentlicht 21.05.2013 18:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.0.x and 4.1.x incorrectly releases a grant reference when releasing a non-v1, non-transitive grant, which allows local guest administrators to cause a denial of service (host crash), obtain sensitive information, or possibly have other impacts ...
CVE-2013-1952
- EPSS 0.07%
- Veröffentlicht 13.05.2013 23:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.x, when using Intel VT-d for a bus mastering capable PCI device, does not properly check the source when accessing a bridge device's interrupt remapping table entries for MSI interrupts, which allows local guest domains to cause a denial of ser...
CVE-2013-1917
- EPSS 0.07%
- Veröffentlicht 13.05.2013 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 3.1 through 4.x, when running 64-bit hosts on Intel CPUs, does not clear the NT flag when using an IRET after a SYSENTER instruction, which allows PV guest users to cause a denial of service (hypervisor crash) by triggering a #GP fault, which is ...