Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-4037

12
FAUCET Score

CVE-2015-4037 describes a denial-of-service vulnerability in QEMU versions 2.3.0 and earlier, specifically within the slirp_smb function. This flaw allows local attackers to prevent QEMU from instantiating by pre-creating predictably named temporary files. With a CVSS score of 1.9, it is considered low severity, requiring local access and moderate attack complexity to achieve a partial availability impact. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.3.0CPE matchmatch criteria
cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

1.9LOW

AV:L/AC:M/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
LOCAL
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
3.4
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.37%
Probability of exploitation in next 30 days
EPSS Percentile
29.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0037 is in the 66th percentile among its peer group of 747 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (8)

redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kvm
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: qemu-kvm
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: qemu-guest-agent
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: qemu-kvm
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: qemu-kvm-rhev
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)Fixed in: qemu-kvm-rhev
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux OpenStack Platform 6 (Juno)Fixed in: qemu-kvm-rhev
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 4Fixed in: qemu-kvm-rhev

Vendor Advisories (1)

redhatCVE-2015-4037Moderate

qemu: insecure temporary file use in /net/slirp.c

May 13, 2015

References

lists.fedoraproject.org / pipermail/package-announce/2015-June/160058.html
lists.fedoraproject.org / pipermail/package-announce/2015-June/160414.html
lists.opensuse.org / opensuse-security-announce/2015-06/msg00027.html
lists.opensuse.org / opensuse-security-announce/2015-09/msg00015.html
lists.opensuse.org / opensuse-updates/2015-11/msg00063.html
bugzilla.redhat.com / show_bug.cgi
debian.org / security/2015/dsa-3284
debian.org / security/2015/dsa-3285
openwall.com / lists/oss-security/2015/05/13/7
openwall.com / lists/oss-security/2015/05/16/5
openwall.com / lists/oss-security/2015/05/23/4
securityfocus.com / bid/74809
securitytracker.com / id/1032547
ubuntu.com / usn/USN-2630-1