Show filters
61 Total Results
Displaying 51-60 of 61
Sort by:
Attacker Value
Unknown
CVE-2013-2212
Disclosure Date: August 28, 2013 (last updated October 05, 2023)
The vmx_set_uc_mode function in Xen 3.3 through 4.3, when disabling caches, allows local HVM guests with access to memory mapped I/O regions to cause a denial of service (CPU consumption and possibly hypervisor or guest kernel panic) via a crafted GFN range.
0
Attacker Value
Unknown
CVE-2013-1432
Disclosure Date: August 28, 2013 (last updated October 05, 2023)
Xen 4.1.x and 4.2.x, when the XSA-45 patch is in place, does not properly maintain references on pages stored for deferred cleanup, which allows local PV guest kernels to cause a denial of service (premature page free and hypervisor crash) or possibly gain privileges via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-3495
Disclosure Date: August 28, 2013 (last updated October 05, 2023)
The Intel VT-d Interrupt Remapping engine in Xen 3.3.x through 4.3.x allows local guests to cause a denial of service (kernel panic) via a malformed Message Signaled Interrupt (MSI) from a PCI device that is bus mastering capable that triggers a System Error Reporting (SERR) Non-Maskable Interrupt (NMI).
0
Attacker Value
Unknown
CVE-2013-2211
Disclosure Date: August 28, 2013 (last updated October 05, 2023)
The libxenlight (libxl) toolstack library in Xen 4.0.x, 4.1.x, and 4.2.x uses weak permissions for xenstore keys for paravirtualised and emulated serial console devices, which allows local guest administrators to modify the xenstore value via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-2076
Disclosure Date: August 28, 2013 (last updated November 08, 2023)
Xen 4.0.x, 4.1.x, and 4.2.x, when running on AMD64 processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one domain to determine portions of the state of floating point instructions of other domains, which can be leveraged to obtain sensitive information such as cryptographic keys, a similar vulnerability to CVE-2006-1056. NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processors in a security-relevant fashion that was not addressed by the kernels.
0
Attacker Value
Unknown
CVE-2013-2077
Disclosure Date: August 28, 2013 (last updated October 05, 2023)
Xen 4.0.x, 4.1.x, and 4.2.x does not properly restrict the contents of a XRSTOR, which allows local PV guest users to cause a denial of service (unhandled exception and hypervisor crash) via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-2072
Disclosure Date: August 28, 2013 (last updated October 05, 2023)
Buffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4.0.x, 4.1.x, and 4.2.x allows local administrators with permissions to configure VCPU affinity to cause a denial of service (memory corruption and xend toolstack crash) and possibly gain privileges via a crafted cpumap.
0
Attacker Value
Unknown
CVE-2013-2078
Disclosure Date: August 14, 2013 (last updated October 05, 2023)
Xen 4.0.2 through 4.0.4, 4.1.x, and 4.2.x allows local PV guest users to cause a denial of service (hypervisor crash) via certain bit combinations to the XSETBV instruction.
0
Attacker Value
Unknown
CVE-2013-1964
Disclosure Date: May 21, 2013 (last updated October 05, 2023)
Xen 4.0.x and 4.1.x incorrectly releases a grant reference when releasing a non-v1, non-transitive grant, which allows local guest administrators to cause a denial of service (host crash), obtain sensitive information, or possibly have other impacts via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-1918
Disclosure Date: May 13, 2013 (last updated October 05, 2023)
Certain page table manipulation operations in Xen 4.1.x, 4.2.x, and earlier are not preemptible, which allows local PV kernels to cause a denial of service via vectors related to "deep page table traversal."
0