Lucene search

K
nvd[email protected]NVD:CVE-2015-7812
HistoryNov 17, 2015 - 3:59 p.m.

CVE-2015-7812

2015-11-1715:59:14
CWE-254
web.nvd.nist.gov
1

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

8.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.7%

The hypercall_create_continuation function in arch/arm/domain.c in Xen 4.4.x through 4.6.x allows local guest users to cause a denial of service (host crash) via a preemptible hypercall to the multicall interface.

Affected configurations

NVD
Node
xenxenMatch4.4.0
OR
xenxenMatch4.4.1-
OR
xenxenMatch4.4.2
OR
xenxenMatch4.4.3
OR
xenxenMatch4.5.0
OR
xenxenMatch4.5.1
OR
xenxenMatch4.5.2
OR
xenxenMatch4.6.0

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

8.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.7%