AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2015-3340

LOW · CVSS 2.9 EPSS 0.79%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2015-04-28 · Last synced 2026-08-04

CyberRota Analysis

This is a low severity vulnerability with a CVSS score of 2.9. It may be remotely exploitable.

CVE
CVE-2015-3340
Severity
LOW
CVSS
2.9
EPSS
0.79%

Original NVD Description

Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request.