Show filters
58 Total Results
Displaying 41-50 of 58
Sort by:
Attacker Value
Unknown

CVE-2013-2077

Disclosure Date: August 28, 2013 (last updated October 05, 2023)
Xen 4.0.x, 4.1.x, and 4.2.x does not properly restrict the contents of a XRSTOR, which allows local PV guest users to cause a denial of service (unhandled exception and hypervisor crash) via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-2072

Disclosure Date: August 28, 2013 (last updated October 05, 2023)
Buffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4.0.x, 4.1.x, and 4.2.x allows local administrators with permissions to configure VCPU affinity to cause a denial of service (memory corruption and xend toolstack crash) and possibly gain privileges via a crafted cpumap.
0
Attacker Value
Unknown

CVE-2013-2078

Disclosure Date: August 14, 2013 (last updated October 05, 2023)
Xen 4.0.2 through 4.0.4, 4.1.x, and 4.2.x allows local PV guest users to cause a denial of service (hypervisor crash) via certain bit combinations to the XSETBV instruction.
0
Attacker Value
Unknown

CVE-2013-1964

Disclosure Date: May 21, 2013 (last updated October 05, 2023)
Xen 4.0.x and 4.1.x incorrectly releases a grant reference when releasing a non-v1, non-transitive grant, which allows local guest administrators to cause a denial of service (host crash), obtain sensitive information, or possibly have other impacts via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-1917

Disclosure Date: May 13, 2013 (last updated October 05, 2023)
Xen 3.1 through 4.x, when running 64-bit hosts on Intel CPUs, does not clear the NT flag when using an IRET after a SYSENTER instruction, which allows PV guest users to cause a denial of service (hypervisor crash) by triggering a #GP fault, which is not properly handled by another IRET instruction.
0
Attacker Value
Unknown

CVE-2013-1952

Disclosure Date: May 13, 2013 (last updated October 05, 2023)
Xen 4.x, when using Intel VT-d for a bus mastering capable PCI device, does not properly check the source when accessing a bridge device's interrupt remapping table entries for MSI interrupts, which allows local guest domains to cause a denial of service (interrupt injection) via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-1920

Disclosure Date: April 12, 2013 (last updated October 05, 2023)
Xen 4.2.x, 4.1.x, and earlier, when the hypervisor is running "under memory pressure" and the Xen Security Module (XSM) is enabled, uses the wrong ordering of operations when extending the per-domain event channel tracking table, which causes a use-after-free and allows local guest kernels to inject arbitrary events and gain privileges via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-5514

Disclosure Date: December 13, 2012 (last updated October 05, 2023)
The guest_physmap_mark_populate_on_demand function in Xen 4.2 and earlier does not properly unlock the subject GFNs when checking if they are in use, which allows local guest HVM administrators to cause a denial of service (hang) via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-6333

Disclosure Date: December 13, 2012 (last updated October 05, 2023)
Multiple HVM control operations in Xen 3.4 through 4.2 allow local HVM guest OS administrators to cause a denial of service (physical CPU consumption) via a large input.
0
Attacker Value
Unknown

CVE-2012-5510

Disclosure Date: December 13, 2012 (last updated October 05, 2023)
Xen 4.x, when downgrading the grant table version, does not properly remove the status page from the tracking list when freeing the page, which allows local guest OS administrators to cause a denial of service (hypervisor crash) via unspecified vectors.
0