Lucene search

K
cveMitreCVE-2014-3968
HistoryJun 05, 2014 - 8:55 p.m.

CVE-2014-3968

2014-06-0520:55:06
mitre
web.nvd.nist.gov
33
cve-2014-3968
xen
hvmop_inject_msi
denial of service
host crash
nvd

CVSS2

5.5

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:A/AC:L/Au:S/C:N/I:N/A:C

AI Score

5.8

Confidence

Low

EPSS

0.001

Percentile

29.8%

The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x allows local guest HVM administrators to cause a denial of service (host crash) via a large number of crafted requests, which trigger an error messages to be logged.

Affected configurations

Nvd
Node
xenxenMatch4.3.0
OR
xenxenMatch4.3.1
Node
xenxenMatch4.2.0
OR
xenxenMatch4.2.1
OR
xenxenMatch4.2.2
OR
xenxenMatch4.2.3
Node
opensuseopensuseMatch12.3
OR
opensuseopensuseMatch13.1
Node
xenxenMatch4.4.0
OR
xenxenMatch4.4.0rc1
VendorProductVersionCPE
xenxen4.3.0cpe:2.3:o:xen:xen:4.3.0:*:*:*:*:*:*:*
xenxen4.3.1cpe:2.3:o:xen:xen:4.3.1:*:*:*:*:*:*:*
xenxen4.2.0cpe:2.3:o:xen:xen:4.2.0:*:*:*:*:*:*:*
xenxen4.2.1cpe:2.3:o:xen:xen:4.2.1:*:*:*:*:*:*:*
xenxen4.2.2cpe:2.3:o:xen:xen:4.2.2:*:*:*:*:*:*:*
xenxen4.2.3cpe:2.3:o:xen:xen:4.2.3:*:*:*:*:*:*:*
opensuseopensuse12.3cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
opensuseopensuse13.1cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
xenxen4.4.0cpe:2.3:o:xen:xen:4.4.0:*:*:*:*:*:*:*
xenxen4.4.0cpe:2.3:o:xen:xen:4.4.0:rc1:*:*:*:*:*:*

CVSS2

5.5

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:A/AC:L/Au:S/C:N/I:N/A:C

AI Score

5.8

Confidence

Low

EPSS

0.001

Percentile

29.8%