Lucene search

K
cve[email protected]CVE-2015-5279
HistorySep 28, 2015 - 4:59 p.m.

CVE-2015-5279

2015-09-2816:59:02
CWE-119
web.nvd.nist.gov
80
cve-2015-5279
buffer overflow
qemu
denial of service
arbitrary code execution
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.5%

Heap-based buffer overflow in the ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via vectors related to receiving packets.

Affected configurations

NVD
Node
qemuqemuRange2.4.0
CPENameOperatorVersion
qemu:qemuqemule2.4.0

References

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.5%