9.3
CVE-2015-5165
- EPSS 13.29%
- Veröffentlicht 12.08.2015 14:59:24
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version 21
Fedoraproject ≫ Fedora Version 22
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp1
Suse ≫ Linux Enterprise Server Version 10 Update sp4 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp1 SwEdition ltss
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Redhat ≫ Virtualization Version 3.0
Redhat ≫ Enterprise Linux Compute Node Eus Version 7.1
Redhat ≫ Enterprise Linux Compute Node Eus Version 7.2
Redhat ≫ Enterprise Linux Compute Node Eus Version 7.3
Redhat ≫ Enterprise Linux Compute Node Eus Version 7.4
Redhat ≫ Enterprise Linux Compute Node Eus Version 7.5
Redhat ≫ Enterprise Linux Compute Node Eus Version 7.6
Redhat ≫ Enterprise Linux Compute Node Eus Version 7.7
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Eus Version 6.7
Redhat ≫ Enterprise Linux Eus Compute Node Version 6.7
Redhat ≫ Enterprise Linux For Power Big Endian Version 6.0
Redhat ≫ Enterprise Linux For Power Big Endian Version 7.0
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 6.7_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.1_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.2_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.3_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.4_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.5_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.6_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.7_ppc64
Redhat ≫ Enterprise Linux For Scientific Computing Version 6.0
Redhat ≫ Enterprise Linux For Scientific Computing Version 7.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Aus Version 7.3
Redhat ≫ Enterprise Linux Server Aus Version 7.4
Redhat ≫ Enterprise Linux Server Aus Version 7.6
Redhat ≫ Enterprise Linux Server Aus Version 7.7
Redhat ≫ Enterprise Linux Server Eus Version 7.1
Redhat ≫ Enterprise Linux Server Eus Version 7.2
Redhat ≫ Enterprise Linux Server Eus Version 7.3
Redhat ≫ Enterprise Linux Server Eus Version 7.4
Redhat ≫ Enterprise Linux Server Eus Version 7.5
Redhat ≫ Enterprise Linux Server Eus Version 7.6
Redhat ≫ Enterprise Linux Server Eus Version 7.7
Redhat ≫ Enterprise Linux Server Eus From Rhui Version 6.7
Redhat ≫ Enterprise Linux Server From Rhui Version 6.0
Redhat ≫ Enterprise Linux Server From Rhui Version 7.0
Redhat ≫ Enterprise Linux Server Tus Version 7.3
Redhat ≫ Enterprise Linux Server Tus Version 7.6
Redhat ≫ Enterprise Linux Server Tus Version 7.7
Redhat ≫ Enterprise Linux Workstation Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 7.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 13.29% | 0.959 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-908 Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00027.html
https://www.arista.com/en/support/advisories-notices/security-advisories/1180-security-advisory-13
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00018.html
http://www.debian.org/security/2015/dsa-3348
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165373.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167792.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167820.html
http://rhn.redhat.com/errata/RHSA-2015-1674.html
http://rhn.redhat.com/errata/RHSA-2015-1683.html
http://rhn.redhat.com/errata/RHSA-2015-1739.html
http://rhn.redhat.com/errata/RHSA-2015-1740.html
http://rhn.redhat.com/errata/RHSA-2015-1793.html
http://rhn.redhat.com/errata/RHSA-2015-1833.html
http://support.citrix.com/article/CTX201717
http://www.debian.org/security/2015/dsa-3349
http://www.securityfocus.com/bid/76153
http://www.securitytracker.com/id/1033176
http://xenbits.xen.org/xsa/advisory-140.html