Show filters
78 Total Results
Displaying 31-40 of 78
Sort by:
Attacker Value
Unknown

CVE-2014-9030

Disclosure Date: November 24, 2014 (last updated October 05, 2023)
The do_mmu_update function in arch/x86/mm.c in Xen 3.2.x through 4.4.x does not properly manage page references, which allows remote domains to cause a denial of service by leveraging control over an HVM guest and a crafted MMU_MACHPHYS_UPDATE.
0
Attacker Value
Unknown

CVE-2014-8595

Disclosure Date: November 19, 2014 (last updated October 05, 2023)
arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a crafted (1) CALL, (2) JMP, (3) RETF, (4) LCALL, (5) LJMP, or (6) LRET far branch instruction.
0
Attacker Value
Unknown

CVE-2014-8594

Disclosure Date: November 19, 2014 (last updated October 05, 2023)
The do_mmu_update function in arch/x86/mm.c in Xen 4.x through 4.4.x does not properly restrict updates to only PV page tables, which allows remote PV guests to cause a denial of service (NULL pointer dereference) by leveraging hardware emulation services for HVM guests using Hardware Assisted Paging (HAP).
0
Attacker Value
Unknown

CVE-2014-7156

Disclosure Date: October 02, 2014 (last updated October 05, 2023)
The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 3.3.x through 4.4.x does not check the supervisor mode permissions for instructions that generate software interrupts, which allows local HVM guest users to cause a denial of service (guest crash) via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-7154

Disclosure Date: October 02, 2014 (last updated October 05, 2023)
Race condition in HVMOP_track_dirty_vram in Xen 4.0.0 through 4.4.x does not ensure possession of the guarding lock for dirty video RAM tracking, which allows certain local guest domains to cause a denial of service via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-7155

Disclosure Date: October 02, 2014 (last updated October 05, 2023)
The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which allows local HVM users to cause a denial of service (guest crash) or gain guest kernel mode privileges via vectors involving an (1) HLT, (2) LGDT, (3) LIDT, or (4) LMSW instruction.
0
Attacker Value
Unknown

CVE-2014-7188

Disclosure Date: October 02, 2014 (last updated October 05, 2023)
The hvm_msr_read_intercept function in arch/x86/hvm/hvm.c in Xen 4.1 through 4.4.x uses an improper MSR range for x2APIC emulation, which allows local HVM guests to cause a denial of service (host crash) or read data from the hypervisor or other guests via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-5149

Disclosure Date: August 22, 2014 (last updated October 05, 2023)
Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using shadow pagetables, are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5146.
0
Attacker Value
Unknown

CVE-2014-5146

Disclosure Date: August 22, 2014 (last updated October 05, 2023)
Certain MMU virtualization operations in Xen 4.2.x through 4.4.x before the xsa97-hap patch, when using Hardware Assisted Paging (HAP), are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5149.
0
Attacker Value
Unknown

CVE-2014-4021

Disclosure Date: June 18, 2014 (last updated October 05, 2023)
Xen 3.2.x through 4.4.x does not properly clean memory pages recovered from guests, which allows local guest OS users to obtain sensitive information via unspecified vectors.
0