Lucene search

K
nvd[email protected]NVD:CVE-2014-3124
HistoryMay 07, 2014 - 10:55 a.m.

CVE-2014-3124

2014-05-0710:55:07
CWE-264
web.nvd.nist.gov
4

CVSS2

6.7

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

COMPLETE

AV:A/AC:L/Au:S/C:P/I:P/A:C

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

35.5%

The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM administrators to cause a denial of service (hypervisor crash) or possibly execute arbitrary code by leveraging a separate qemu-dm vulnerability to trigger invalid page table translations for unspecified memory page types.

Affected configurations

Nvd
Node
xenxenMatch4.1.0
OR
xenxenMatch4.1.1
OR
xenxenMatch4.1.2
OR
xenxenMatch4.1.3
OR
xenxenMatch4.1.4
OR
xenxenMatch4.1.5
OR
xenxenMatch4.1.6.1
OR
xenxenMatch4.2.0
OR
xenxenMatch4.2.1
OR
xenxenMatch4.2.2
OR
xenxenMatch4.2.3
OR
xenxenMatch4.3.0
OR
xenxenMatch4.3.1
OR
xenxenMatch4.4.0
OR
xenxenMatch4.4.0rc1
VendorProductVersionCPE
xenxen4.1.0cpe:2.3:o:xen:xen:4.1.0:*:*:*:*:*:*:*
xenxen4.1.1cpe:2.3:o:xen:xen:4.1.1:*:*:*:*:*:*:*
xenxen4.1.2cpe:2.3:o:xen:xen:4.1.2:*:*:*:*:*:*:*
xenxen4.1.3cpe:2.3:o:xen:xen:4.1.3:*:*:*:*:*:*:*
xenxen4.1.4cpe:2.3:o:xen:xen:4.1.4:*:*:*:*:*:*:*
xenxen4.1.5cpe:2.3:o:xen:xen:4.1.5:*:*:*:*:*:*:*
xenxen4.1.6.1cpe:2.3:o:xen:xen:4.1.6.1:*:*:*:*:*:*:*
xenxen4.2.0cpe:2.3:o:xen:xen:4.2.0:*:*:*:*:*:*:*
xenxen4.2.1cpe:2.3:o:xen:xen:4.2.1:*:*:*:*:*:*:*
xenxen4.2.2cpe:2.3:o:xen:xen:4.2.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 151

CVSS2

6.7

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

COMPLETE

AV:A/AC:L/Au:S/C:P/I:P/A:C

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

35.5%