Show filters
85 Total Results
Displaying 71-80 of 85
Sort by:
Attacker Value
Unknown

CVE-2013-2072

Disclosure Date: August 28, 2013 (last updated October 05, 2023)
Buffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4.0.x, 4.1.x, and 4.2.x allows local administrators with permissions to configure VCPU affinity to cause a denial of service (memory corruption and xend toolstack crash) and possibly gain privileges via a crafted cpumap.
0
Attacker Value
Unknown

CVE-2013-2195

Disclosure Date: August 23, 2013 (last updated October 05, 2023)
The Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an unspecified impact via a crafted kernel, related to "pointer dereferences" involving unexpected calculations.
0
Attacker Value
Unknown

CVE-2013-2196

Disclosure Date: August 23, 2013 (last updated October 05, 2023)
Multiple unspecified vulnerabilities in the Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an unspecified impact via a crafted kernel, related to "other problems" that are not CVE-2013-2194 or CVE-2013-2195.
0
Attacker Value
Unknown

CVE-2013-2194

Disclosure Date: August 23, 2013 (last updated October 05, 2023)
Multiple integer overflows in the Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an unspecified impact via a crafted kernel.
0
Attacker Value
Unknown

CVE-2013-2078

Disclosure Date: August 14, 2013 (last updated October 05, 2023)
Xen 4.0.2 through 4.0.4, 4.1.x, and 4.2.x allows local PV guest users to cause a denial of service (hypervisor crash) via certain bit combinations to the XSETBV instruction.
0
Attacker Value
Unknown

CVE-2013-1918

Disclosure Date: May 13, 2013 (last updated October 05, 2023)
Certain page table manipulation operations in Xen 4.1.x, 4.2.x, and earlier are not preemptible, which allows local PV kernels to cause a denial of service via vectors related to "deep page table traversal."
0
Attacker Value
Unknown

CVE-2013-1919

Disclosure Date: May 13, 2013 (last updated October 05, 2023)
Xen 4.2.x and 4.1.x does not properly restrict access to IRQs, which allows local stub domain clients to gain access to IRQs and cause a denial of service via vectors related to "passed-through IRQs or PCI devices."
0
Attacker Value
Unknown

CVE-2013-1917

Disclosure Date: May 13, 2013 (last updated October 05, 2023)
Xen 3.1 through 4.x, when running 64-bit hosts on Intel CPUs, does not clear the NT flag when using an IRET after a SYSENTER instruction, which allows PV guest users to cause a denial of service (hypervisor crash) by triggering a #GP fault, which is not properly handled by another IRET instruction.
0
Attacker Value
Unknown

CVE-2013-1922

Disclosure Date: May 13, 2013 (last updated October 05, 2023)
qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk image based on the header, which allows local guest OS administrators to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted, a different vulnerability than CVE-2008-2004.
0
Attacker Value
Unknown

CVE-2013-1952

Disclosure Date: May 13, 2013 (last updated October 05, 2023)
Xen 4.x, when using Intel VT-d for a bus mastering capable PCI device, does not properly check the source when accessing a bridge device's interrupt remapping table entries for MSI interrupts, which allows local guest domains to cause a denial of service (interrupt injection) via unspecified vectors.
0