CVE-2014-0407Oracle VM Virtualbox vulnerability

16 documents6 sources
Severity
3.5LOWNVD
OSV3.4
EPSS
0.1%
top 77.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 15
Latest updateMay 17

Description

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0405.

CVSS vector

AV:L/AC:H/C:P/I:P/A:PExploitability: 1.5 | Impact: 6.4

Affected Packages2 packages

NVDoracle/vm_virtualbox4.1.28+48
Ubuntusun/virtualbox< 4.3.10-dfsg-1

🔴Vulnerability Details

7
GHSA
GHSA-247g-7x8j-8cc8: Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 32022-05-17
GHSA
GHSA-9h56-55p8-xgj2: Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 32022-05-17
OSV
openjdk-7 vulnerabilities2015-01-28
OSV
CVE-2014-0405: Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 32014-01-15
CVEList
CVE-2014-0407: Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 32014-01-15

📋Vendor Advisories

2
Debian
CVE-2014-0405: virtualbox-guest-additions-iso - Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtua...2014
Debian
CVE-2014-0407: virtualbox - Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtua...2014

💬Community

4
Bugzilla
CVE-2014-0460 OpenJDK: missing randomization of JNDI DNS client query IDs (JNDI, 8030731)2014-04-14
Bugzilla
CVE-2014-2402 OpenJDK: Incorrect NIO channel separation (Libraries, 8026716)2014-04-14
Bugzilla
CVE-2014-0455 OpenJDK: MethodHandle variable argument lists handling (Libraries, 8029844)2014-04-14
Bugzilla
CVE-2014-2413 OpenJDK: method handle call hierachy bypass (Libraries, 8032686)2014-04-14
CVE-2014-0407 — Oracle VM Virtualbox vulnerability | cvebase