CVE-2013-2194
- EPSS 0.04%
- Veröffentlicht 23.08.2013 16:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple integer overflows in the Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an unspecified impact via a crafted kernel.
CVE-2013-2195
- EPSS 0.04%
- Veröffentlicht 23.08.2013 16:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an unspecified impact via a crafted kernel, related to "pointer dereferences" involving unexpected calculations.
CVE-2013-2196
- EPSS 0.04%
- Veröffentlicht 23.08.2013 16:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple unspecified vulnerabilities in the Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an unspecified impact via a crafted kernel, related to "other problems" that are not CVE-2013-2...
CVE-2013-2078
- EPSS 0.06%
- Veröffentlicht 14.08.2013 15:55:06
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.0.2 through 4.0.4, 4.1.x, and 4.2.x allows local PV guest users to cause a denial of service (hypervisor crash) via certain bit combinations to the XSETBV instruction.
CVE-2013-1964
- EPSS 0.08%
- Veröffentlicht 21.05.2013 18:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.0.x and 4.1.x incorrectly releases a grant reference when releasing a non-v1, non-transitive grant, which allows local guest administrators to cause a denial of service (host crash), obtain sensitive information, or possibly have other impacts ...
CVE-2013-1952
- EPSS 0.07%
- Veröffentlicht 13.05.2013 23:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.x, when using Intel VT-d for a bus mastering capable PCI device, does not properly check the source when accessing a bridge device's interrupt remapping table entries for MSI interrupts, which allows local guest domains to cause a denial of ser...
CVE-2013-1917
- EPSS 0.07%
- Veröffentlicht 13.05.2013 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 3.1 through 4.x, when running 64-bit hosts on Intel CPUs, does not clear the NT flag when using an IRET after a SYSENTER instruction, which allows PV guest users to cause a denial of service (hypervisor crash) by triggering a #GP fault, which is ...
CVE-2013-1918
- EPSS 0.1%
- Veröffentlicht 13.05.2013 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Certain page table manipulation operations in Xen 4.1.x, 4.2.x, and earlier are not preemptible, which allows local PV kernels to cause a denial of service via vectors related to "deep page table traversal."
CVE-2013-1919
- EPSS 0.1%
- Veröffentlicht 13.05.2013 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen 4.2.x and 4.1.x does not properly restrict access to IRQs, which allows local stub domain clients to gain access to IRQs and cause a denial of service via vectors related to "passed-through IRQs or PCI devices."
CVE-2013-1922
- EPSS 0.08%
- Veröffentlicht 13.05.2013 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk image based on the header, which allows local guest OS administrators to read arbitrary files on the host by modifying the header to identify a different format, which is use...