Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2014-0983Oracle VM Virtualbox vulnerability

CWE-3998 documents7 sources
Severity
6.9MEDIUMNVD
EPSS
12.0%
top 6.20%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMar 31
Latest updateMay 14

Description

Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch.py in Oracle VirtualBox 4.2.x through 4.2.20 and 4.3.x before 4.3.8, when using 3D Acceleration, allow local guest OS users to execute arbitrary code on the Chromium server via certain CR_MESSAGE_OPCODES messages with a crafted index, which are not properly handled by the (1) CR_VERTEXATTRIB4NUBARB_OPCODE to the crServerDispatchVertexAttrib4NubARB function, (2) C

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0

Affected Packages2 packages

NVDoracle/vm_virtualbox15 versions+14
Ubuntusun/virtualbox< 4.3.10-dfsg-1

🔴Vulnerability Details

3
GHSA
GHSA-p4cx-p88v-xqv9: Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch2022-05-14
OSV
CVE-2014-0983: Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch2014-03-31
CVEList
CVE-2014-0983: Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch2014-03-28

💥Exploits & PoCs

3
Exploit-DB
Oracle VM VirtualBox 4.3.6 - 3D Acceleration Virtual Machine Escape (Metasploit)2014-08-14
Exploit-DB
Oracle VM VirtualBox - 3D Acceleration Multiple Vulnerabilities2014-03-12
Metasploit
VirtualBox 3D Acceleration Virtual Machine Escape

📋Vendor Advisories

1
Debian
CVE-2014-0983: virtualbox - Multiple array index errors in programs that are automatically generated by VBox...2014
CVE-2014-0983 — Oracle VM Virtualbox vulnerability | cvebase