CVE-2015-4896
published 2015-10-21CVE-2015-4896: Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.0.34, 4.1.42, 4.2.34, 4.3.32, and 5.0.8, when a VM…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.67%
88.4th percentile
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.0.34, 4.1.42, 4.2.34, 4.3.32, and 5.0.8, when a VM has the Remote Display feature (RDP) enabled, allows remote attackers to affect availability via unknown vectors related to Core.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | virtualbox | < virtualbox 5.0.8-dfsg-1 (sid) | virtualbox 5.0.8-dfsg-1 (sid) |
| oracle | vm_virtualbox | >= 4.0.0 < 4.0.34 | 4.0.34 |
| oracle | vm_virtualbox | >= 4.1.0 < 4.1.42 | 4.1.42 |
| oracle | vm_virtualbox | >= 4.2.0 < 4.2.34 | 4.2.34 |
| oracle | vm_virtualbox | >= 4.3.0 < 4.3.32 | 4.3.32 |
| oracle | vm_virtualbox | >= 5.0.0 < 5.0.8 | 5.0.8 |
| sun | virtualbox | >= 0 < 4.3.34-dfsg-1+deb8u1ubuntu1.14.04.1 | 4.3.34-dfsg-1+deb8u1ubuntu1.14.04.1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jjhg-cr8w-r8h7: Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4
ghsa_unreviewed·2022-05-14
CVE-2015-4896 [MEDIUM] GHSA-jjhg-cr8w-r8h7: Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.0.34, 4.1.42, 4.2.34, 4.3.32, and 5.0.8, when a VM has the Remote Display feature (RDP) enabled, allows remote attackers to affect availability via unknown vectors related to Core.
OSV
CVE-2015-4896: Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4
osv·2015-10-21·CVSS 5.0
CVE-2015-4896 [MEDIUM] CVE-2015-4896: Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.0.34, 4.1.42, 4.2.34, 4.3.32, and 5.0.8, when a VM has the Remote Display feature (RDP) enabled, allows remote attackers to affect availability via unknown vectors related to Core.
Debian
CVE-2015-4896: virtualbox - Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtua...
vendor_debian·2015·CVSS 5.0
CVE-2015-4896 [MEDIUM] CVE-2015-4896: virtualbox - Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtua...
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.0.34, 4.1.42, 4.2.34, 4.3.32, and 5.0.8, when a VM has the Remote Display feature (RDP) enabled, allows remote attackers to affect availability via unknown vectors related to Core.
Scope: local
sid: resolved (fixed in 5.0.8-dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.opensuse.org/opensuse-updates/2015-11/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00172.htmlhttp://www.debian.org/security/2015/dsa-3384http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlhttp://www.securityfocus.com/bid/77198http://www.securitytracker.com/id/1033880http://lists.opensuse.org/opensuse-updates/2015-11/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00172.htmlhttp://www.debian.org/security/2015/dsa-3384http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlhttp://www.securityfocus.com/bid/77198http://www.securitytracker.com/id/1033880
2015-10-21
Published