{"api_version":"1","generated_at":"2026-07-23T03:39:04+00:00","cve":"CVE-2015-2152","urls":{"html":"https://cve.report/CVE-2015-2152","api":"https://cve.report/api/cve/CVE-2015-2152.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-2152","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-2152"},"summary":{"title":"CVE-2015-2152","description":"Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access to the VGA console by (1) setting the DISPLAY environment variable, when compiled with SDL support, or connecting to the VNC server on (2) ::1 or (3) 127.0.0.1, when not compiled with SDL support.","state":"PUBLISHED","assigner":"mitre","published_at":"2015-03-18 16:59:02","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"1.9","severity":"","vector":"AV:L/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:N/I:P/A:N","baseScore":1.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://security.gentoo.org/glsa/201504-04","name":"https://security.gentoo.org/glsa/201504-04","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Xen: Multiple vulnerabilities (GLSA 201504-04) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1031806","name":"http://www.securitytracker.com/id/1031806","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Xen Multiple Flaws Let Local Guest Users Deny Service or Obtain Information From Other Guest Systems - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://xenbits.xen.org/xsa/advisory-119.html","name":"http://xenbits.xen.org/xsa/advisory-119.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"XSA-119 - Xen Security Advisories","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152776.html","name":"http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152776.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[SECURITY] Fedora 21 Update: xen-4.4.1-16.fc21","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152588.html","name":"http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152588.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[SECURITY] Fedora 20 Update: xen-4.3.3-12.fc20","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1031919","name":"http://www.securitytracker.com/id/1031919","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Xen HVM qemu Flaw Lets Local Users Access VGA Backend on the Target Guest System - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152483.html","name":"http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152483.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[SECURITY] Fedora 22 Update: xen-4.5.0-6.fc22","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00014.html","name":"http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00014.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] openSUSE-SU-2015:0732-1: important: Security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/73068","name":"http://www.securityfocus.com/bid/73068","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Xen CVE-2015-2152 Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-2152","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-2152","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"2152","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"20","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"2152","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"21","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"2152","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"22","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"2152","vulnerable":"1","versionEndIncluding":"4.5.0","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"xen","cpe5":"xen","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T05:10:14.268Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"GLSA-201504-04","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"https://security.gentoo.org/glsa/201504-04"},{"name":"1031919","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1031919"},{"name":"FEDORA-2015-3944","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152776.html"},{"name":"FEDORA-2015-3721","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152588.html"},{"name":"73068","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/73068"},{"name":"FEDORA-2015-3935","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152483.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://xenbits.xen.org/xsa/advisory-119.html"},{"name":"openSUSE-SU-2015:0732","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00014.html"},{"name":"1031806","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1031806"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-03-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access to the VGA console by (1) setting the DISPLAY environment variable, when compiled with SDL support, or connecting to the VNC server on (2) ::1 or (3) 127.0.0.1, when not compiled with SDL support."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-12-30T16:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"GLSA-201504-04","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"https://security.gentoo.org/glsa/201504-04"},{"name":"1031919","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1031919"},{"name":"FEDORA-2015-3944","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152776.html"},{"name":"FEDORA-2015-3721","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152588.html"},{"name":"73068","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/73068"},{"name":"FEDORA-2015-3935","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152483.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://xenbits.xen.org/xsa/advisory-119.html"},{"name":"openSUSE-SU-2015:0732","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00014.html"},{"name":"1031806","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1031806"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2015-2152","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access to the VGA console by (1) setting the DISPLAY environment variable, when compiled with SDL support, or connecting to the VNC server on (2) ::1 or (3) 127.0.0.1, when not compiled with SDL support."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"GLSA-201504-04","refsource":"GENTOO","url":"https://security.gentoo.org/glsa/201504-04"},{"name":"1031919","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1031919"},{"name":"FEDORA-2015-3944","refsource":"FEDORA","url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152776.html"},{"name":"FEDORA-2015-3721","refsource":"FEDORA","url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152588.html"},{"name":"73068","refsource":"BID","url":"http://www.securityfocus.com/bid/73068"},{"name":"FEDORA-2015-3935","refsource":"FEDORA","url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152483.html"},{"name":"http://xenbits.xen.org/xsa/advisory-119.html","refsource":"CONFIRM","url":"http://xenbits.xen.org/xsa/advisory-119.html"},{"name":"openSUSE-SU-2015:0732","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00014.html"},{"name":"1031806","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1031806"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2015-2152","datePublished":"2015-03-18T16:00:00.000Z","dateReserved":"2015-02-28T00:00:00.000Z","dateUpdated":"2024-08-06T05:10:14.268Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-03-18 16:59:02","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:N/I:P/A:N","baseScore":1.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.4,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:*","versionEndIncluding":"4.5.0","matchCriteriaId":"FE6592AF-775F-4B8A-8E33-57A1239852E3"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*","matchCriteriaId":"FF47C9F0-D8DA-4B55-89EB-9B2C9383ADB9"},{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*","matchCriteriaId":"56BDB5A0-0839-4A20-A003-B8CD56F48171"},{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*","matchCriteriaId":"253C303A-E577-4488-93E6-68A8DD942C38"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"2152","Ordinal":"1","Title":"CVE-2015-2152","CVE":"CVE-2015-2152","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"2152","Ordinal":"1","NoteData":"Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access to the VGA console by (1) setting the DISPLAY environment variable, when compiled with SDL support, or connecting to the VNC server on (2) ::1 or (3) 127.0.0.1, when not compiled with SDL support.","Type":"Description","Title":"CVE-2015-2152"},{"CveYear":"2015","CveId":"2152","Ordinal":"2","NoteData":"2015-03-18","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"2152","Ordinal":"3","NoteData":"2016-12-30","Type":"Other","Title":"Modified"}]}}}