cbcvebase.
CVE-2015-2152
published 2015-03-18

CVE-2015-2152: Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which…

PriorityP49low1.9CVSS 2.0
AVLACMAuNCNIPAN
EPSS
0.42%
34.0th percentile
Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access to the VGA console by (1) setting the DISPLAY environment variable, when compiled with SDL support, or connecting to the VNC server on (2) ::1 or (3) 127.0.0.1, when not compiled with SDL support.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianxen< xen 4.4.1-9 (bookworm)xen 4.4.1-9 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
xenxen<= 4.5.0
xenxen>= 0 < 4.4.1-94.4.1-9
xenxen>= 0 < 4.4.1-94.4.1-9
xenxen>= 0 < 4.4.1-94.4.1-9
xenxen>= 0 < 4.4.1-94.4.1-9

CVSS provenance

nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:P/A:N
osv1.9LOW
vendor_debian1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.