AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2015-5154

HIGH · CVSS 7.2 EPSS 0.63%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2015-08-12 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2015-5154
Severity
HIGH
CVSS
7.2
EPSS
0.63%

Original Filing — NVD Description

Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, allows local guest users to execute arbitrary code on the host via unspecified ATAPI commands.