CVE-2011-2901
- EPSS 0.12%
- Veröffentlicht 01.10.2013 17:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Off-by-one error in the __addr_ok macro in Xen 3.3 and earlier allows local 64 bit PV guest administrators to cause a denial of service (host crash) via unspecified hypercalls that ignore virtual-address bits.
CVE-2013-1442
- EPSS 0.11%
- Veröffentlicht 30.09.2013 21:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly clear previous data from registers when using an XSAVE or XRSTOR to extend the state components of a saved or restored vCPU after touching other restored extended registers,...
CVE-2013-4329
- EPSS 0.16%
- Veröffentlicht 12.09.2013 18:37:43
- Zuletzt bearbeitet 11.04.2025 00:51:21
The xenlight library (libxl) in Xen 4.0.x through 4.2.x, when IOMMU is disabled, provides access to a busmastering-capable PCI passthrough device before the IOMMU setup is complete, which allows local HVM guest domains to gain privileges or cause a d...
CVE-2013-1432
- EPSS 0.41%
- Veröffentlicht 28.08.2013 21:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.1.x and 4.2.x, when the XSA-45 patch is in place, does not properly maintain references on pages stored for deferred cleanup, which allows local PV guest kernels to cause a denial of service (premature page free and hypervisor crash) or possibl...
CVE-2013-2072
- EPSS 0.36%
- Veröffentlicht 28.08.2013 21:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4.0.x, 4.1.x, and 4.2.x allows local administrators with permissions to configure VCPU affinity to cause a denial of service (memory corruption and xend toolstack crash) a...
CVE-2013-2076
- EPSS 0.18%
- Veröffentlicht 28.08.2013 21:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.0.x, 4.1.x, and 4.2.x, when running on AMD64 processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one domain to determine portions of the state of floating point instruct...
CVE-2013-2077
- EPSS 0.12%
- Veröffentlicht 28.08.2013 21:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.0.x, 4.1.x, and 4.2.x does not properly restrict the contents of a XRSTOR, which allows local PV guest users to cause a denial of service (unhandled exception and hypervisor crash) via unspecified vectors.
CVE-2013-2211
- EPSS 0.23%
- Veröffentlicht 28.08.2013 21:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
The libxenlight (libxl) toolstack library in Xen 4.0.x, 4.1.x, and 4.2.x uses weak permissions for xenstore keys for paravirtualised and emulated serial console devices, which allows local guest administrators to modify the xenstore value via unspeci...
CVE-2013-2212
- EPSS 0.18%
- Veröffentlicht 28.08.2013 21:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
The vmx_set_uc_mode function in Xen 3.3 through 4.3, when disabling caches, allows local HVM guests with access to memory mapped I/O regions to cause a denial of service (CPU consumption and possibly hypervisor or guest kernel panic) via a crafted GF...
CVE-2013-3495
- EPSS 0.08%
- Veröffentlicht 28.08.2013 21:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Intel VT-d Interrupt Remapping engine in Xen 3.3.x through 4.3.x allows local guests to cause a denial of service (kernel panic) via a malformed Message Signaled Interrupt (MSI) from a PCI device that is bus mastering capable that triggers a Syst...