CVE-2016-5605
published 2016-10-25CVE-2016-5605: Unspecified vulnerability in the Oracle VM VirtualBox component before 5.1.4 in Oracle Virtualization allows remote attackers to affect confidentiality and…
PriorityP350critical9.1CVSS 3.0
AVNACLPRNUINSUCHIHAN
EPSS
2.43%
82.4th percentile
Unspecified vulnerability in the Oracle VM VirtualBox component before 5.1.4 in Oracle Virtualization allows remote attackers to affect confidentiality and integrity via vectors related to VRDE.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | virtualbox | < virtualbox 5.1.4-dfsg-1 (sid) | virtualbox 5.1.4-dfsg-1 (sid) |
| oracle | vm_virtualbox | <= 5.1.2 | — |
CVSS provenance
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_debian9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2016-5605: virtualbox - Unspecified vulnerability in the Oracle VM VirtualBox component before 5.1.4 in ...
vendor_debian·2016·CVSS 9.1
CVE-2016-5605 [CRITICAL] CVE-2016-5605: virtualbox - Unspecified vulnerability in the Oracle VM VirtualBox component before 5.1.4 in ...
Unspecified vulnerability in the Oracle VM VirtualBox component before 5.1.4 in Oracle Virtualization allows remote attackers to affect confidentiality and integrity via vectors related to VRDE.
Scope: local
sid: resolved (fixed in 5.1.4-dfsg-1)
GHSA
GHSA-h5vc-c65p-cgj9: Unspecified vulnerability in the Oracle VM VirtualBox component before 5
ghsa_unreviewed·2022-05-17
CVE-2016-5605 [CRITICAL] CWE-284 GHSA-h5vc-c65p-cgj9: Unspecified vulnerability in the Oracle VM VirtualBox component before 5
Unspecified vulnerability in the Oracle VM VirtualBox component before 5.1.4 in Oracle Virtualization allows remote attackers to affect confidentiality and integrity via vectors related to VRDE.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.securityfocus.com/bid/93685http://www.securitytracker.com/id/1037053http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.securityfocus.com/bid/93685http://www.securitytracker.com/id/1037053
2016-10-25
Published