CVE-2018-3005
published 2018-07-18CVE-2018-3005: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.2.16…
PriorityP413medium4CVSS 3.0
AVLACLPRNUINSUCNINAL
EPSS
0.49%
39.3th percentile
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 4.0 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | virtualbox | < virtualbox 5.2.16-dfsg-1 (sid) | virtualbox 5.2.16-dfsg-1 (sid) |
| oracle | vm_virtualbox | < 5.2.16 | 5.2.16 |
| oracle_corporation | vm_virtualbox | >= unspecified < 5.2.16 | 5.2.16 |
CVSS provenance
nvdv3.04.0MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv4.0MEDIUM
vendor_debian4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h5g6-4mhq-jc8h: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
ghsa_unreviewed·2022-05-13
CVE-2018-3005 [MEDIUM] GHSA-h5g6-4mhq-jc8h: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 4.0 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
OSV
CVE-2018-3005: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
osv·2018-07-18·CVSS 4.0
CVE-2018-3005 [MEDIUM] CVE-2018-3005: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 4.0 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Debian
CVE-2018-3005: virtualbox - Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (su...
vendor_debian·2018·CVSS 4.0
CVE-2018-3005 [MEDIUM] CVE-2018-3005: virtualbox - Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (su...
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 4.0 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Scope: local
sid: resolved (fixed in 5.2.16-dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-12395 Mozilla: WebExtension bypass of domain restrictions through header rewriting
bugzilla·2018-10-23·CVSS 7.5
CVE-2018-12395 [HIGH] CVE-2018-12395 Mozilla: WebExtension bypass of domain restrictions through header rewriting
CVE-2018-12395 Mozilla: WebExtension bypass of domain restrictions through header rewriting
By rewriting the `Host` request headers using the `webRequest` API, a WebExtension can bypass domain restrictions through domain fronting. This would allow access to domains that share a host that are otherwise restricted.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-27/#CVE-2018-12395
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Rob Wu, Andrew Swan
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:3005 https://access.redhat.com/errata/RHSA-2018:3005
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:3006 https://access.redhat.com
Bugzilla
CVE-2018-12392 Mozilla: Crash with nested event loops
bugzilla·2018-10-23·CVSS 9.8
CVE-2018-12392 [CRITICAL] CVE-2018-12392 Mozilla: Crash with nested event loops
CVE-2018-12392 Mozilla: Crash with nested event loops
When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-27/#CVE-2018-12392
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Nils
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:3005 https://access.redhat.com/errata/RHSA-2018:3005
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:3006 https://access.redhat.com/errata/RHSA-2018:3006
---
This issue has been addressed in the following products:
Red Hat Enterpri
Bugzilla
CVE-2018-12397 Mozilla: WebExtension local file permission check bypass
bugzilla·2018-10-23·CVSS 7.1
CVE-2018-12397 [HIGH] CVE-2018-12397 Mozilla: WebExtension local file permission check bypass
CVE-2018-12397 Mozilla: WebExtension local file permission check bypass
A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-27/#CVE-2018-12397
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Rob Wu
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:3005 https://access.redhat.com/errata/RHSA-2018:3005
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-
Bugzilla
CVE-2018-12396 Mozilla: WebExtension content scripts can execute in disallowed contexts
bugzilla·2018-10-23·CVSS 6.5
CVE-2018-12396 [MEDIUM] CVE-2018-12396 Mozilla: WebExtension content scripts can execute in disallowed contexts
CVE-2018-12396 Mozilla: WebExtension content scripts can execute in disallowed contexts
A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential privilege escalation by the WebExtension on sites where content scripts should not be run.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-27/#CVE-2018-12396
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Rob Wu
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:3005 https://access.redhat.com/errata/RHSA-2018:3005
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:3006 https://access.redhat.com/
Bugzilla
CVE-2018-12389 Mozilla: Memory safety bugs fixed in Firefox ESR 60.3
bugzilla·2018-10-23·CVSS 8.8
CVE-2018-12389 [HIGH] CVE-2018-12389 Mozilla: Memory safety bugs fixed in Firefox ESR 60.3
CVE-2018-12389 Mozilla: Memory safety bugs fixed in Firefox ESR 60.3
Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-27/#CVE-2018-12389
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Daniel Veditz, Philipp
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:3005 https://access.redhat.com/errata/RHSA-2018:3005
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:3006 https://access
Bugzilla
CVE-2018-12393 Mozilla: Integer overflow during Unicode conversion while loading JavaScript
bugzilla·2018-10-23·CVSS 7.5
CVE-2018-12393 [HIGH] CVE-2018-12393 Mozilla: Integer overflow during Unicode conversion while loading JavaScript
CVE-2018-12393 Mozilla: Integer overflow during Unicode conversion while loading JavaScript
A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write.
*Note: 64-bit builds are not vulnerable to this issue.*
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-27/#CVE-2018-12393
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:3005 https://access.redhat.com/errata/RHSA-2018:3005
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:3006 https://ac
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.securityfocus.com/bid/104764http://www.securitytracker.com/id/1041296http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.securityfocus.com/bid/104764http://www.securitytracker.com/id/1041296
2018-07-18
Published