Show filters
44 Total Results
Displaying 21-30 of 44
Sort by:
Attacker Value
Unknown
CVE-2014-8866
Disclosure Date: December 01, 2014 (last updated October 05, 2023)
The compatibility mode hypercall argument translation in Xen 3.3.x through 4.4.x, when running on a 64-bit hypervisor, allows local 32-bit HVM guests to cause a denial of service (host crash) via vectors involving altering the high halves of registers while in 64-bit mode.
0
Attacker Value
Unknown
CVE-2014-9030
Disclosure Date: November 24, 2014 (last updated October 05, 2023)
The do_mmu_update function in arch/x86/mm.c in Xen 3.2.x through 4.4.x does not properly manage page references, which allows remote domains to cause a denial of service by leveraging control over an HVM guest and a crafted MMU_MACHPHYS_UPDATE.
0
Attacker Value
Unknown
CVE-2014-8595
Disclosure Date: November 19, 2014 (last updated October 05, 2023)
arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a crafted (1) CALL, (2) JMP, (3) RETF, (4) LCALL, (5) LJMP, or (6) LRET far branch instruction.
0
Attacker Value
Unknown
CVE-2014-7155
Disclosure Date: October 02, 2014 (last updated October 05, 2023)
The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which allows local HVM users to cause a denial of service (guest crash) or gain guest kernel mode privileges via vectors involving an (1) HLT, (2) LGDT, (3) LIDT, or (4) LMSW instruction.
0
Attacker Value
Unknown
CVE-2014-1891
Disclosure Date: April 01, 2014 (last updated October 05, 2023)
Multiple integer overflows in the (1) FLASK_GETBOOL, (2) FLASK_SETBOOL, (3) FLASK_USER, and (4) FLASK_CONTEXT_TO_SID suboperations in the flask hypercall in Xen 4.3.x, 4.2.x, 4.1.x, 3.2.x, and earlier, when XSM is enabled, allow local users to cause a denial of service (processor fault) via unspecified vectors, a different vulnerability than CVE-2014-1892, CVE-2014-1893, and CVE-2014-1894.
0
Attacker Value
Unknown
CVE-2014-1893
Disclosure Date: April 01, 2014 (last updated October 05, 2023)
Multiple integer overflows in the (1) FLASK_GETBOOL and (2) FLASK_SETBOOL suboperations in the flask hypercall in Xen 4.1.x, 3.3.x, 3.2.x, and earlier, when XSM is enabled, allow local users to cause a denial of service (processor fault) via unspecified vectors, a different vulnerability than CVE-2014-1891, CVE-2014-1892, and CVE-2014-1894.
0
Attacker Value
Unknown
CVE-2014-1892
Disclosure Date: April 01, 2014 (last updated October 05, 2023)
Xen 3.3 through 4.1, when XSM is enabled, allows local users to cause a denial of service via vectors related to a "large memory allocation," a different vulnerability than CVE-2014-1891, CVE-2014-1893, and CVE-2014-1894.
0
Attacker Value
Unknown
CVE-2011-1166
Disclosure Date: January 07, 2014 (last updated October 05, 2023)
Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of service (host crash) by specifying user mode execution without user-mode pagetables.
0
Attacker Value
Unknown
CVE-2013-4553
Disclosure Date: December 24, 2013 (last updated October 05, 2023)
The XEN_DOMCTL_getmemlist hypercall in Xen 3.4.x through 4.3.x (possibly 4.3.1) does not always obtain the page_alloc_lock and mm_rwlock in the same order, which allows local guest administrators to cause a denial of service (host deadlock).
0
Attacker Value
Unknown
CVE-2013-4554
Disclosure Date: December 24, 2013 (last updated October 05, 2023)
Xen 3.0.3 through 4.1.x (possibly 4.1.6.1), 4.2.x (possibly 4.2.3), and 4.3.x (possibly 4.3.1) does not properly prevent access to hypercalls, which allows local guest users to gain privileges via a crafted application running in ring 1 or 2.
0