CVE-2015-5165 describes a heap memory disclosure vulnerability in the QEMU RTL8139 network card device model, specifically affecting Xen 4.5.x and earlier, as well as various Linux distributions including Arista, Debian, Fedora, Oracle, Red Hat, and SUSE. This critical vulnerability (CVSS 9.3) allows remote attackers to read process heap memory through unspecified vectors, indicating a high potential for data compromise with moderate attack complexity. While not listed on CISA's KEV catalog and lacking public exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion and media coverage, suggesting awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.5.0CPE matchmatch criteria | cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:* | ||
4.5.1CPE matchmatch criteria | cpe:2.3:o:xen:xen:4.5.1:*:*:*:*:*:*:* | ||
21CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:* | ||
22CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.