CVE-2015-2044
published 2015-03-12CVE-2015-2044: The emulation routines for unspecified X86 devices in Xen 3.2.x through 4.5.x does not properly initialize data, which allow local HVM guest users to obtain…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.41%
33.5th percentile
The emulation routines for unspecified X86 devices in Xen 3.2.x through 4.5.x does not properly initialize data, which allow local HVM guest users to obtain sensitive information via vectors involving an unsupported access size.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.4.1-8 (bookworm) | xen 4.4.1-8 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: information leak via internal x86 system device emulation (XSA-121)
vendor_redhat·2015-03-06·CVSS 2.1
CVE-2015-2044 [LOW] CWE-212 xen: information leak via internal x86 system device emulation (XSA-121)
xen: information leak via internal x86 system device emulation (XSA-121)
The emulation routines for unspecified X86 devices in Xen 3.2.x through 4.5.x does not properly initialize data, which allow local HVM guest users to obtain sensitive information via vectors involving an unsupported access size.
Statement: Not vulnerable.
This issue does not affect the Xen hypervisor as shipped with Red Hat Enterprise Linux 5.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2015-2044: xen - The emulation routines for unspecified X86 devices in Xen 3.2.x through 4.5.x do...
vendor_debian·2015·CVSS 2.1
CVE-2015-2044 [LOW] CVE-2015-2044: xen - The emulation routines for unspecified X86 devices in Xen 3.2.x through 4.5.x do...
The emulation routines for unspecified X86 devices in Xen 3.2.x through 4.5.x does not properly initialize data, which allow local HVM guest users to obtain sensitive information via vectors involving an unsupported access size.
Scope: local
bookworm: resolved (fixed in 4.4.1-8)
bullseye: resolved (fixed in 4.4.1-8)
forky: resolved (fixed in 4.4.1-8)
sid: resolved (fixed in 4.4.1-8)
trixie: resolved (fixed in 4.4.1-8)
GHSA
GHSA-p925-cpg4-hv5v: The emulation routines for unspecified X86 devices in Xen 3
ghsa_unreviewed·2022-05-14
CVE-2015-2044 [LOW] CWE-200 GHSA-p925-cpg4-hv5v: The emulation routines for unspecified X86 devices in Xen 3
The emulation routines for unspecified X86 devices in Xen 3.2.x through 4.5.x does not properly initialize data, which allow local HVM guest users to obtain sensitive information via vectors involving an unsupported access size.
OSV
CVE-2015-2044: The emulation routines for unspecified X86 devices in Xen 3
osv·2015-03-12·CVSS 2.1
CVE-2015-2044 [LOW] CVE-2015-2044: The emulation routines for unspecified X86 devices in Xen 3
The emulation routines for unspecified X86 devices in Xen 3.2.x through 4.5.x does not properly initialize data, which allow local HVM guest users to obtain sensitive information via vectors involving an unsupported access size.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152483.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/152588.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/152776.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00014.htmlhttp://support.citrix.com/article/CTX200484http://www.debian.org/security/2015/dsa-3181http://www.securityfocus.com/bid/72954http://www.securitytracker.com/id/1031806http://www.securitytracker.com/id/1031836http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-423503.htmhttp://xenbits.xen.org/xsa/advisory-121.htmlhttps://security.gentoo.org/glsa/201504-04http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152483.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/152588.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/152776.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00014.htmlhttp://support.citrix.com/article/CTX200484http://www.debian.org/security/2015/dsa-3181http://www.securityfocus.com/bid/72954http://www.securitytracker.com/id/1031806http://www.securitytracker.com/id/1031836http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-423503.htmhttp://xenbits.xen.org/xsa/advisory-121.htmlhttps://security.gentoo.org/glsa/201504-04
2015-03-12
Published