Show filters
555 Total Results
Displaying 471-480 of 555
Sort by:
Attacker Value
Unknown
CVE-2013-1919
Disclosure Date: May 13, 2013 (last updated October 05, 2023)
Xen 4.2.x and 4.1.x does not properly restrict access to IRQs, which allows local stub domain clients to gain access to IRQs and cause a denial of service via vectors related to "passed-through IRQs or PCI devices."
0
Attacker Value
Unknown
CVE-2013-1917
Disclosure Date: May 13, 2013 (last updated October 05, 2023)
Xen 3.1 through 4.x, when running 64-bit hosts on Intel CPUs, does not clear the NT flag when using an IRET after a SYSENTER instruction, which allows PV guest users to cause a denial of service (hypervisor crash) by triggering a #GP fault, which is not properly handled by another IRET instruction.
0
Attacker Value
Unknown
CVE-2013-1922
Disclosure Date: May 13, 2013 (last updated October 05, 2023)
qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk image based on the header, which allows local guest OS administrators to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted, a different vulnerability than CVE-2008-2004.
0
Attacker Value
Unknown
CVE-2013-1952
Disclosure Date: May 13, 2013 (last updated October 05, 2023)
Xen 4.x, when using Intel VT-d for a bus mastering capable PCI device, does not properly check the source when accessing a bridge device's interrupt remapping table entries for MSI interrupts, which allows local guest domains to cause a denial of service (interrupt injection) via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-1920
Disclosure Date: April 12, 2013 (last updated October 05, 2023)
Xen 4.2.x, 4.1.x, and earlier, when the hypervisor is running "under memory pressure" and the Xen Security Module (XSM) is enabled, uses the wrong ordering of operations when extending the per-domain event channel tracking table, which causes a use-after-free and allows local guest kernels to inject arbitrary events and gain privileges via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-0151
Disclosure Date: March 07, 2013 (last updated October 05, 2023)
The do_hvm_op function in xen/arch/x86/hvm/hvm.c in Xen 4.2.x on the x86_32 platform does not prevent HVM_PARAM_NESTEDHVM (aka nested virtualization) operations, which allows guest OS users to cause a denial of service (long-duration page mappings and host OS crash) by leveraging administrative access to an HVM guest in a domain with a large number of VCPUs.
0
Attacker Value
Unknown
CVE-2013-0215
Disclosure Date: March 07, 2013 (last updated October 05, 2023)
oxenstored in Xen 4.1.x, Xen 4.2.x, and xen-unstable does not properly consider the state of the Xenstore ring during read operations, which allows guest OS users to cause a denial of service (daemon crash and host-control outage, or memory consumption) or obtain sensitive control-plane data by leveraging guest administrative access.
0
Attacker Value
Unknown
CVE-2012-5634
Disclosure Date: February 14, 2013 (last updated October 05, 2023)
Xen 4.2.x, 4.1.x, and 4.0, when using Intel VT-d for PCI passthrough, does not properly configure VT-d when supporting a device that is behind a legacy PCI Bridge, which allows local guests to cause a denial of service to other guests by injecting an interrupt.
0
Attacker Value
Unknown
CVE-2013-0153
Disclosure Date: February 14, 2013 (last updated October 05, 2023)
The AMD IOMMU support in Xen 4.2.x, 4.1.x, 3.3, and other versions, when using AMD-Vi for PCI passthrough, uses the same interrupt remapping table for the host and all guests, which allows guests to cause a denial of service by injecting an interrupt into other guests.
0
Attacker Value
Unknown
CVE-2013-0152
Disclosure Date: February 13, 2013 (last updated October 05, 2023)
Memory leak in Xen 4.2 and unstable allows local HVM guests to cause a denial of service (host memory consumption) by performing nested virtualization in a way that triggers errors that are not properly handled.
0