Xen 3.x, possibly before 3.1.2, when running on IA64 systems, does not check the RID value for movtorr, which allows a VTi domain to read memory of other domains.
Xen 3.1.1 allows virtual guest system users to cause a denial of service (hypervisor crash) by using a debug register (DR7) to set certain breakpoints.
Xen 3.1.1 does not prevent modification of the CR4 TSC from applications, which allows pv guests to cause a denial of service (crash).