Show filters
555 Total Results
Displaying 451-460 of 555
Sort by:
Attacker Value
Unknown

CVE-2013-4371

Disclosure Date: October 17, 2013 (last updated October 05, 2023)
Use-after-free vulnerability in the libxl_list_cpupool function in the libxl toolstack library in Xen 4.2.x and 4.3.x, when running "under memory pressure," returns the original pointer when the realloc function fails, which allows local users to cause a denial of service (heap corruption and crash) and possibly execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-4356

Disclosure Date: October 09, 2013 (last updated October 05, 2023)
Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more than 5TB of RAM, which allows local 64-bit PV guests to read or write to invalid memory and cause a denial of service (crash).
0
Attacker Value
Unknown

CVE-2011-2901

Disclosure Date: October 01, 2013 (last updated October 05, 2023)
Off-by-one error in the __addr_ok macro in Xen 3.3 and earlier allows local 64 bit PV guest administrators to cause a denial of service (host crash) via unspecified hypercalls that ignore virtual-address bits.
0
Attacker Value
Unknown

CVE-2013-4355

Disclosure Date: October 01, 2013 (last updated October 05, 2023)
Xen 4.3.x and earlier does not properly handle certain errors, which allows local HVM guests to obtain hypervisor stack memory via a (1) port or (2) memory mapped I/O write or (3) other unspecified operations related to addresses without associated memory.
0
Attacker Value
Unknown

CVE-2013-4361

Disclosure Date: October 01, 2013 (last updated October 05, 2023)
The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the correct variable for the source effective address, which allows local HVM guests to obtain hypervisor stack information by reading the values used by the instruction.
0
Attacker Value
Unknown

CVE-2013-1442

Disclosure Date: September 30, 2013 (last updated October 05, 2023)
Xen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly clear previous data from registers when using an XSAVE or XRSTOR to extend the state components of a saved or restored vCPU after touching other restored extended registers, which allows local guest OSes to obtain sensitive information by reading the registers.
0
Attacker Value
Unknown

CVE-2013-4329

Disclosure Date: September 12, 2013 (last updated October 05, 2023)
The xenlight library (libxl) in Xen 4.0.x through 4.2.x, when IOMMU is disabled, provides access to a busmastering-capable PCI passthrough device before the IOMMU setup is complete, which allows local HVM guest domains to gain privileges or cause a denial of service via a DMA instruction.
0
Attacker Value
Unknown

CVE-2013-2212

Disclosure Date: August 28, 2013 (last updated October 05, 2023)
The vmx_set_uc_mode function in Xen 3.3 through 4.3, when disabling caches, allows local HVM guests with access to memory mapped I/O regions to cause a denial of service (CPU consumption and possibly hypervisor or guest kernel panic) via a crafted GFN range.
0
Attacker Value
Unknown

CVE-2013-3495

Disclosure Date: August 28, 2013 (last updated October 05, 2023)
The Intel VT-d Interrupt Remapping engine in Xen 3.3.x through 4.3.x allows local guests to cause a denial of service (kernel panic) via a malformed Message Signaled Interrupt (MSI) from a PCI device that is bus mastering capable that triggers a System Error Reporting (SERR) Non-Maskable Interrupt (NMI).
0
Attacker Value
Unknown

CVE-2013-1432

Disclosure Date: August 28, 2013 (last updated October 05, 2023)
Xen 4.1.x and 4.2.x, when the XSA-45 patch is in place, does not properly maintain references on pages stored for deferred cleanup, which allows local PV guest kernels to cause a denial of service (premature page free and hypervisor crash) or possibly gain privileges via unspecified vectors.
0