CVE-2015-0236

libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.

Published: 2015-01-29 Last update: 2026-05-06 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2015-0236 is rated Low Risk (36.9/100): CVSS Low severity, with medium exploitation likelihood (EPSS 0.49%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2015-0236

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-05-13 0.65% 0.49% -0.16%
2 2025-12-28 0.49% 0.65% +0.16%
3 2025-12-27 0.49%

Full EPSS history (14 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2015-0236

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
3.5 2.0 LOW
AV:N/AC:M/Au:S/C:P/I:N/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:S)
A single authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
6.8 2.9 [email protected]

Weakness enumeration for CVE-2015-0236

OS Trackers for CVE-2015-0236

vendor priority summary link
debian not yet assigned CVE-2015-0236 not yet assigned priority: Debian including 1 source packages (libvirt), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2015-0236
redhat low https://access.redhat.com/security/cve/CVE-2015-0236
suse low CVE-2015-0236 severity low: SUSE including 870 source package names (amazon/suse-sles-15-sp1-chost-byos-v20210304-hvm-ssd-x86_64, amazon/suse-sles-15-sp1-chost-byos-v20220127-hvm-ssd-x86_64, …), 1343 product×package rows across 70 product lines (HPE Helion OpenStack 8, SUSE Liberty Linux 7, … (70 product lines)): Fixed 874, Known Not Affected 238, Known Affected 231. https://www.suse.com/security/cve/CVE-2015-0236/
ubuntu low CVE-2015-0236 low priority: Ubuntu including 1 source packages (libvirt), 7 status rows across 7 suites (lucid, precise, trusty, upstream, utopic, vivid, wily): not-affected 3, ignored 2, released 2. https://ubuntu.com/security/CVE-2015-0236

Affected software / configurations for CVE-2015-0236

Vendor Product Version Raw CPE
mageia mageia 4.0 cpe:2.3:o:mageia:mageia:4.0:*:*:*:*:*:*:*
redhat libvirt <= 1.2.11 cpe:2.3:a:redhat:libvirt:*:*:*:*:*:*:*:*
redhat libvirt 1.2.0 cpe:2.3:a:redhat:libvirt:1.2.0:*:*:*:*:*:*:*
redhat libvirt 1.2.1 cpe:2.3:a:redhat:libvirt:1.2.1:*:*:*:*:*:*:*
redhat libvirt 1.2.2 cpe:2.3:a:redhat:libvirt:1.2.2:*:*:*:*:*:*:*
redhat libvirt 1.2.3 cpe:2.3:a:redhat:libvirt:1.2.3:*:*:*:*:*:*:*
redhat libvirt 1.2.4 cpe:2.3:a:redhat:libvirt:1.2.4:*:*:*:*:*:*:*
redhat libvirt 1.2.5 cpe:2.3:a:redhat:libvirt:1.2.5:*:*:*:*:*:*:*
redhat libvirt 1.2.6 cpe:2.3:a:redhat:libvirt:1.2.6:*:*:*:*:*:*:*
redhat libvirt 1.2.7 cpe:2.3:a:redhat:libvirt:1.2.7:*:*:*:*:*:*:*
redhat libvirt 1.2.8 cpe:2.3:a:redhat:libvirt:1.2.8:*:*:*:*:*:*:*
redhat libvirt 1.2.9 cpe:2.3:a:redhat:libvirt:1.2.9:*:*:*:*:*:*:*
redhat libvirt 1.2.10 cpe:2.3:a:redhat:libvirt:1.2.10:*:*:*:*:*:*:*
canonical ubuntu_linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
canonical ubuntu_linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
canonical ubuntu_linux 15.04 cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*
canonical ubuntu_linux 15.10 cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
redhat enterprise_linux_desktop 7.0 cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
redhat enterprise_linux_hpc_node 7.0 cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*
redhat enterprise_linux_server 7.0 cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
redhat enterprise_linux_workstation 7.0 cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

References for CVE-2015-0236

cvelogic Threat Intelligence