VYPR

Xen

by Xen

Source repositories

CVEs (515)

  • CVE-2013-1432Aug 28, 2013
    risk 0.00cvss epss 0.01

    Xen 4.1.x and 4.2.x, when the XSA-45 patch is in place, does not properly maintain references on pages stored for deferred cleanup, which allows local PV guest kernels to cause a denial of service (premature page free and hypervisor crash) or possibly gain privileges via…

  • CVE-2013-2196Aug 23, 2013
    risk 0.00cvss epss 0.00

    Multiple unspecified vulnerabilities in the Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an unspecified impact via a crafted kernel, related to "other problems" that are not CVE-2013-2194 or CVE-2013-2195.

  • CVE-2013-2195Aug 23, 2013
    risk 0.00cvss epss 0.00

    The Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an unspecified impact via a crafted kernel, related to "pointer dereferences" involving unexpected calculations.

  • CVE-2013-2194Aug 23, 2013
    risk 0.00cvss epss 0.00

    Multiple integer overflows in the Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an unspecified impact via a crafted kernel.

  • CVE-2013-2078Aug 14, 2013
    risk 0.00cvss epss 0.00

    Xen 4.0.2 through 4.0.4, 4.1.x, and 4.2.x allows local PV guest users to cause a denial of service (hypervisor crash) via certain bit combinations to the XSETBV instruction.

  • CVE-2013-1964May 21, 2013
    risk 0.00cvss epss 0.00

    Xen 4.0.x and 4.1.x incorrectly releases a grant reference when releasing a non-v1, non-transitive grant, which allows local guest administrators to cause a denial of service (host crash), obtain sensitive information, or possibly have other impacts via unspecified vectors.

  • CVE-2013-1952May 13, 2013
    risk 0.00cvss epss 0.00

    Xen 4.x, when using Intel VT-d for a bus mastering capable PCI device, does not properly check the source when accessing a bridge device's interrupt remapping table entries for MSI interrupts, which allows local guest domains to cause a denial of service (interrupt injection)…

  • CVE-2013-1922May 13, 2013
    risk 0.00cvss epss 0.00

    qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk image based on the header, which allows local guest OS administrators to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is…

  • CVE-2013-1919May 13, 2013
    risk 0.00cvss epss 0.00

    Xen 4.2.x and 4.1.x does not properly restrict access to IRQs, which allows local stub domain clients to gain access to IRQs and cause a denial of service via vectors related to "passed-through IRQs or PCI devices."

  • CVE-2013-1918May 13, 2013
    risk 0.00cvss epss 0.00

    Certain page table manipulation operations in Xen 4.1.x, 4.2.x, and earlier are not preemptible, which allows local PV kernels to cause a denial of service via vectors related to "deep page table traversal."

  • CVE-2013-1917May 13, 2013
    risk 0.00cvss epss 0.00

    Xen 3.1 through 4.x, when running 64-bit hosts on Intel CPUs, does not clear the NT flag when using an IRET after a SYSENTER instruction, which allows PV guest users to cause a denial of service (hypervisor crash) by triggering a #GP fault, which is not properly handled by…

  • CVE-2013-1920Apr 12, 2013
    risk 0.00cvss epss 0.00

    Xen 4.2.x, 4.1.x, and earlier, when the hypervisor is running "under memory pressure" and the Xen Security Module (XSM) is enabled, uses the wrong ordering of operations when extending the per-domain event channel tracking table, which causes a use-after-free and allows local…

  • CVE-2013-0215Mar 7, 2013
    risk 0.00cvss epss 0.01

    oxenstored in Xen 4.1.x, Xen 4.2.x, and xen-unstable does not properly consider the state of the Xenstore ring during read operations, which allows guest OS users to cause a denial of service (daemon crash and host-control outage, or memory consumption) or obtain sensitive…

  • CVE-2013-0151Mar 7, 2013
    risk 0.00cvss epss 0.01

    The do_hvm_op function in xen/arch/x86/hvm/hvm.c in Xen 4.2.x on the x86_32 platform does not prevent HVM_PARAM_NESTEDHVM (aka nested virtualization) operations, which allows guest OS users to cause a denial of service (long-duration page mappings and host OS crash) by…

  • CVE-2013-0153Feb 14, 2013
    risk 0.00cvss epss 0.00

    The AMD IOMMU support in Xen 4.2.x, 4.1.x, 3.3, and other versions, when using AMD-Vi for PCI passthrough, uses the same interrupt remapping table for the host and all guests, which allows guests to cause a denial of service by injecting an interrupt into other guests.

  • CVE-2012-5634Feb 14, 2013
    risk 0.00cvss epss 0.01

    Xen 4.2.x, 4.1.x, and 4.0, when using Intel VT-d for PCI passthrough, does not properly configure VT-d when supporting a device that is behind a legacy PCI Bridge, which allows local guests to cause a denial of service to other guests by injecting an interrupt.

  • CVE-2013-0231Feb 13, 2013
    risk 0.00cvss epss 0.00

    The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/conf_space_capability_msi.c) in Xen for the Linux kernel 2.6.18 and 3.8 allows guest OS users with PCI device access to cause a denial of service via a large number of kernel log messages. NOTE: some…

  • CVE-2013-0190Feb 13, 2013
    risk 0.00cvss epss 0.00

    The xen_failsafe_callback function in Xen for the Linux kernel 2.6.23 and other versions, when running a 32-bit PVOPS guest, allows local users to cause a denial of service (guest crash) by triggering an iret fault, leading to use of an incorrect stack pointer and stack…

  • CVE-2013-0152Feb 13, 2013
    risk 0.00cvss epss 0.00

    Memory leak in Xen 4.2 and unstable allows local HVM guests to cause a denial of service (host memory consumption) by performing nested virtualization in a way that triggers errors that are not properly handled.

  • CVE-2013-0154Jan 12, 2013
    risk 0.00cvss epss 0.00

    The get_page_type function in xen/arch/x86/mm.c in Xen 4.2, when debugging is enabled, allows local PV or HVM guest administrators to cause a denial of service (assertion failure and hypervisor crash) via unspecified vectors related to a hypercall.

Page 23 of 26