Vulnerabilities > XEN > XEN > 4.1.6.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2013-12-24 | CVE-2013-4554 | Permissions, Privileges, and Access Controls vulnerability in XEN Xen 3.0.3 through 4.1.x (possibly 4.1.6.1), 4.2.x (possibly 4.2.3), and 4.3.x (possibly 4.3.1) does not properly prevent access to hypercalls, which allows local guest users to gain privileges via a crafted application running in ring 1 or 2. | 5.2 |
2013-12-24 | CVE-2013-4553 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in XEN The XEN_DOMCTL_getmemlist hypercall in Xen 3.4.x through 4.3.x (possibly 4.3.1) does not always obtain the page_alloc_lock and mm_rwlock in the same order, which allows local guest administrators to cause a denial of service (host deadlock). | 5.2 |
2013-11-02 | CVE-2013-4416 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in XEN The Ocaml xenstored implementation (oxenstored) in Xen 4.1.x, 4.2.x, and 4.3.x allows local guest domains to cause a denial of service (domain shutdown) via a large message reply. | 5.2 |
2013-11-02 | CVE-2013-4494 | Improper Input Validation vulnerability in multiple products Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlock) via unspecified vectors. | 5.2 |
2013-10-17 | CVE-2013-4368 | Information Exposure vulnerability in XEN The outs instruction emulation in Xen 3.1.x, 4.2.x, 4.3.x, and earlier, when using FS: or GS: segment override, uses an uninitialized variable as a segment base, which allows local 64-bit PV guests to obtain sensitive information (hypervisor stack content) via unspecified vectors related to stale data in a segment register. | 1.9 |
2013-08-23 | CVE-2013-2196 | Remote Privilege Escalation vulnerability in Xen Multiple unspecified vulnerabilities in the Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an unspecified impact via a crafted kernel, related to "other problems" that are not CVE-2013-2194 or CVE-2013-2195. local xen | 6.9 |
2013-08-23 | CVE-2013-2195 | Numeric Errors vulnerability in XEN The Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an unspecified impact via a crafted kernel, related to "pointer dereferences" involving unexpected calculations. | 6.9 |
2013-08-23 | CVE-2013-2194 | Numeric Errors vulnerability in XEN Multiple integer overflows in the Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an unspecified impact via a crafted kernel. | 6.9 |
2012-12-13 | CVE-2012-5515 | Local Denial of Service vulnerability in Xen 'extent_order' Values The (1) XENMEM_decrease_reservation, (2) XENMEM_populate_physmap, and (3) XENMEM_exchange hypercalls in Xen 4.2 and earlier allow local guest administrators to cause a denial of service (long loop and hang) via a crafted extent_order value. local xen | 4.7 |
2012-12-13 | CVE-2012-5514 | Local Denial of Service vulnerability in Xen The guest_physmap_mark_populate_on_demand function in Xen 4.2 and earlier does not properly unlock the subject GFNs when checking if they are in use, which allows local guest HVM administrators to cause a denial of service (hang) via unspecified vectors. local xen | 4.7 |