cbcvebase.

Oracle Vm Virtualbox vulnerabilities

430 known vulnerabilities affecting oracle/vm_virtualbox.

Total CVEs
430
CISA KEV
1
actively exploited
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH201MEDIUM170LOW54

Vulnerabilities

Page 2 of 22
CVE-2022-39425P3HIGHCVSS 8.1fixed in 6.1.402022-10-18
CVE-2022-39425 [HIGH] CWE-306 CVE-2022-39425: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.40. Difficult to exploit vulnerability allows unauthenticated attacker with network access via VRDP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Or
nvd
CVE-2023-22018P3HIGHCVSS 8.1≥ 6.0.0, < 6.1.46≥ 7.0.0, < 7.0.102023-07-18
CVE-2023-22018 [HIGH] CVE-2023-22018: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppo Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.46 and Prior to 7.0.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via RDP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in take
nvd
CVE-2022-39424P3HIGHCVSS 8.1fixed in 6.1.402022-10-18
CVE-2022-39424 [HIGH] CWE-94 CVE-2022-39424: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.40. Difficult to exploit vulnerability allows unauthenticated attacker with network access via VRDP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Ora
nvd
CVE-2023-21886P3HIGHCVSS 8.1fixed in 6.1.42≥ 7.0.0, < 7.0.62023-01-18
CVE-2023-21886 [HIGH] CWE-94 CVE-2023-21886: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppo Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.42 and prior to 7.0.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle VM VirtualBox. Successful attacks of this vulnerabili
nvd
CVE-2018-5407P4MEDIUMCVSS 4.7PoCfixed in 6.0.02018-11-15
CVE-2018-5407 [MEDIUM] CWE-200 CVE-2018-5407: Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerab Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
nvd
CVE-2014-0981P4MEDIUMCVSS 4.4PoCv4.2.0v4.2.2+13 more2014-03-31
CVE-2014-0981 [MEDIUM] CWE-399 CVE-2014-0981: VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x befo VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium server via crafted Chromium network pointer in a (1) CR_MESSAGE_READBACK or (2) CR_MESSAGE_WRITEBACK
nvd
CVE-2022-39426P3HIGHCVSS 8.1fixed in 6.1.402022-10-18
CVE-2022-39426 [HIGH] CWE-306 CVE-2022-39426: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.40. Difficult to exploit vulnerability allows unauthenticated attacker with network access via VRDP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Or
nvd
CVE-2018-3294P3CRITICALCVSS 9.0fixed in 5.2.202018-10-17
CVE-2018-3294 [CRITICAL] CVE-2018-3294: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). T Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.2.20. Easily exploitable vulnerability allows low privileged attacker with network access via VRDP to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than th
nvd
CVE-2024-21115P3HIGHCVSS 8.8fixed in 7.0.162024-04-16
CVE-2024-21115 [HIGH] CWE-284 CVE-2024-21115: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppo Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Ora
nvd
CVE-2015-3195P3MEDIUMCVSS 5.3fixed in 4.3.36≥ 5.0.0, < 5.0.142015-12-06
CVE-2015-3195 [MEDIUM] CWE-200 CVE-2015-3195: The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 befo The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS appl
nvd
CVE-2020-2959P3HIGHCVSS 8.6fixed in 5.2.40≥ 6.0.0, < 6.0.20+1 more2020-04-15
CVE-2020-2959 [HIGH] CVE-2020-2959: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via MLD to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM Virtua
nvd
CVE-2024-21112P3HIGHCVSS 8.8fixed in 7.0.162024-04-16
CVE-2024-21112 [HIGH] CWE-284 CVE-2024-21112: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppo Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Ora
nvd
CVE-2024-21114P3HIGHCVSS 8.8fixed in 7.0.162024-04-16
CVE-2024-21114 [HIGH] CWE-284 CVE-2024-21114: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppo Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Ora
nvd
CVE-2024-21113P3HIGHCVSS 8.8fixed in 7.0.162024-04-16
CVE-2024-21113 [HIGH] CWE-284 CVE-2024-21113: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppo Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Ora
nvd
CVE-2026-60150P3HIGHCVSS 7.8v7.2.122026-07-21
CVE-2026-60150 [HIGH] CWE-269 CVE-2026-60150: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability ca
nvd
CVE-2026-47047P3HIGHCVSS 7.8v7.2.122026-07-21
CVE-2026-47047 [HIGH] CWE-269 CVE-2026-47047: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability ca
nvd
CVE-2026-47054P3HIGHCVSS 7.8v7.2.122026-07-21
CVE-2026-47054 [HIGH] CWE-269 CVE-2026-47054: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability ca
nvd
CVE-2014-2477P4LOWCVSS 3.6PoC≤ 4.0.24v4.0+61 more2014-07-17
CVE-2014-2477 [LOW] CVE-2014-2477: Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.26, 4.1.34, 4.2.26, and 4.3.12 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-2486.
nvd
CVE-2019-2723P3HIGHCVSS 8.8fixed in 5.2.28≥ 6.0.0, < 6.0.62019-04-23
CVE-2019-2723 [HIGH] CWE-190 CVE-2019-2723: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). S Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the
nvd
CVE-2019-2722P3HIGHCVSS 8.8fixed in 5.2.28≥ 6.0.0, < 6.0.62019-04-23
CVE-2019-2722 [HIGH] CVE-2019-2722: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). S Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerab
nvd
Oracle Vm Virtualbox vulnerabilities | cvebase