NVD

Id
30255  
Name
CVE-2014-1666  
Description
The do_physdev_op function in Xen 4.1.5, 4.1.6.1, 4.2.2 through 4.2.3, and 4.3.x does not properly restrict access to the (1) PHYSDEVOP_prepare_msix and (2) PHYSDEVOP_release_msix operations, which allows local PV guests to cause a denial of service (host or guest malfunction) or possibly gain privileges via unspecified vectors.  
Reject
 
CVSS Version
2  
CVSS Score
8.3  
Severity
High  
CVSS Base Score
8.3  
CVSS Impact Subscore
10  
CVSS Exploit Subscore
6.5  
CVSS Vector
(AV:A/AC:L/Au:N/C:C/I:C/A:C)  
Pub Date
2017-01-19  
Published
2014-01-26  
Modified Date
2017-01-06  
Seq
2014-1666  

Actions