Lucene search

K
cve[email protected]CVE-2015-5225
HistoryNov 06, 2015 - 9:59 p.m.

CVE-2015-5225

2015-11-0621:59:05
CWE-119
web.nvd.nist.gov
57
cve-2015-5225
buffer overflow
vnc
qemu
denial of service
heap memory corruption
arbitrary code execution
security vulnerability

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.7%

Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service (heap memory corruption and process crash) or possibly execute arbitrary code on the host via unspecified vectors, related to refreshing the server display surface.

Affected configurations

NVD
Node
redhatopenstackMatch5.0
OR
redhatopenstackMatch6.0
OR
redhatopenstackMatch7.0
Node
fedoraprojectfedoraMatch21
OR
fedoraprojectfedoraMatch22
OR
fedoraprojectfedoraMatch23
Node
qemuqemuRange2.4.0

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.7%