cbcvebase.
CVE-2015-5154
published 2015-08-12

CVE-2015-5154: Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, allows local guest…

PriorityP434high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.63%
46.2th percentile
Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, allows local guest users to execute arbitrary code on the host via unspecified ATAPI commands.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianqemu< qemu 1:2.4+dfsg-1a (bookworm)qemu 1:2.4+dfsg-1a (bookworm)
debianxen< qemu 1:2.4+dfsg-1a (bookworm)qemu 1:2.4+dfsg-1a (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
qemuqemu<= 2.3.0
qemuqemu>= 0 < 1:2.4+dfsg-1a1:2.4+dfsg-1a
qemuqemu>= 0 < 1:2.4+dfsg-1a1:2.4+dfsg-1a
qemuqemu>= 0 < 1:2.4+dfsg-1a1:2.4+dfsg-1a
qemuqemu>= 0 < 1:2.4+dfsg-1a1:2.4+dfsg-1a
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.152.0.0+dfsg-2ubuntu1.15
suselinux_enterprise_debuginfo
suselinux_enterprise_desktop
suselinux_enterprise_desktop
suselinux_enterprise_server
suselinux_enterprise_software_development_kit
suselinux_enterprise_software_development_kit
susesuse_linux_enterprise_server
xenxen<= 4.5.0
xenxen
xenxen>= 0 < 4.4.0-14.4.0-1
xenxen>= 0 < 4.4.0-14.4.0-1
xenxen>= 0 < 4.4.0-14.4.0-1
xenxen>= 0 < 4.4.0-14.4.0-1

CVSS provenance

nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
vendor_ubuntu6.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.