AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2015-8338

HIGH · CVSS 7.2 EPSS 0.42%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2015-12-17 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.2. It affects Exchange. It may lead to a denial-of-service condition.

CVE
CVE-2015-8338
Severity
HIGH
CVSS
7.2
EPSS
0.42%
Exchange

Original NVD Description

Xen 4.6.x and earlier does not properly enforce limits on page order inputs for the (1) XENMEM_increase_reservation, (2) XENMEM_populate_physmap, (3) XENMEM_exchange, and possibly other HYPERVISOR_memory_op suboperations, which allows ARM guest OS administrators to cause a denial of service (CPU consumption, guest reboot, or watchdog timeout and host reboot) and possibly have unspecified other impact via unknown vectors.