Show filters
99 Total Results
Displaying 51-60 of 99
Sort by:
Attacker Value
Unknown
CVE-2013-1432
Disclosure Date: August 28, 2013 (last updated October 05, 2023)
Xen 4.1.x and 4.2.x, when the XSA-45 patch is in place, does not properly maintain references on pages stored for deferred cleanup, which allows local PV guest kernels to cause a denial of service (premature page free and hypervisor crash) or possibly gain privileges via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-2211
Disclosure Date: August 28, 2013 (last updated October 05, 2023)
The libxenlight (libxl) toolstack library in Xen 4.0.x, 4.1.x, and 4.2.x uses weak permissions for xenstore keys for paravirtualised and emulated serial console devices, which allows local guest administrators to modify the xenstore value via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-2076
Disclosure Date: August 28, 2013 (last updated November 08, 2023)
Xen 4.0.x, 4.1.x, and 4.2.x, when running on AMD64 processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one domain to determine portions of the state of floating point instructions of other domains, which can be leveraged to obtain sensitive information such as cryptographic keys, a similar vulnerability to CVE-2006-1056. NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processors in a security-relevant fashion that was not addressed by the kernels.
0
Attacker Value
Unknown
CVE-2013-2077
Disclosure Date: August 28, 2013 (last updated October 05, 2023)
Xen 4.0.x, 4.1.x, and 4.2.x does not properly restrict the contents of a XRSTOR, which allows local PV guest users to cause a denial of service (unhandled exception and hypervisor crash) via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-2072
Disclosure Date: August 28, 2013 (last updated October 05, 2023)
Buffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4.0.x, 4.1.x, and 4.2.x allows local administrators with permissions to configure VCPU affinity to cause a denial of service (memory corruption and xend toolstack crash) and possibly gain privileges via a crafted cpumap.
0
Attacker Value
Unknown
CVE-2013-2078
Disclosure Date: August 14, 2013 (last updated October 05, 2023)
Xen 4.0.2 through 4.0.4, 4.1.x, and 4.2.x allows local PV guest users to cause a denial of service (hypervisor crash) via certain bit combinations to the XSETBV instruction.
0
Attacker Value
Unknown
CVE-2013-1964
Disclosure Date: May 21, 2013 (last updated October 05, 2023)
Xen 4.0.x and 4.1.x incorrectly releases a grant reference when releasing a non-v1, non-transitive grant, which allows local guest administrators to cause a denial of service (host crash), obtain sensitive information, or possibly have other impacts via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-1918
Disclosure Date: May 13, 2013 (last updated October 05, 2023)
Certain page table manipulation operations in Xen 4.1.x, 4.2.x, and earlier are not preemptible, which allows local PV kernels to cause a denial of service via vectors related to "deep page table traversal."
0
Attacker Value
Unknown
CVE-2013-1919
Disclosure Date: May 13, 2013 (last updated October 05, 2023)
Xen 4.2.x and 4.1.x does not properly restrict access to IRQs, which allows local stub domain clients to gain access to IRQs and cause a denial of service via vectors related to "passed-through IRQs or PCI devices."
0
Attacker Value
Unknown
CVE-2013-1917
Disclosure Date: May 13, 2013 (last updated October 05, 2023)
Xen 3.1 through 4.x, when running 64-bit hosts on Intel CPUs, does not clear the NT flag when using an IRET after a SYSENTER instruction, which allows PV guest users to cause a denial of service (hypervisor crash) by triggering a #GP fault, which is not properly handled by another IRET instruction.
0