Sun Virtualbox vulnerabilities
153 known vulnerabilities affecting sun/virtualbox.
Total CVEs
153
CISA KEV
0
Public exploits
15
Exploited in wild
0
Severity breakdown
HIGH70MEDIUM54LOW29
Vulnerabilities
Page 1 of 8
CVE-2018-2698P3HIGHCVSS 8.8PoC≥ 0, < 6.1.16-dfsg-6~ubuntu1.20.04.12018-01-18
CVE-2018-2698 [HIGH] CVE-2018-2698: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerabili
osv
CVE-2017-3316P3HIGHCVSS 8.4PoC≥ 0, < 5.1.38-dfsg-0ubuntu1.16.04.12017-01-27
CVE-2017-3316 [HIGH] CVE-2017-3316: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI). Supported versions that are affected are VirtualBox prior to 5.0.32 and prior to 5.1.14. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise Oracle VM VirtualBox. Successful attacks require human int
osv
CVE-2017-10129P3HIGHCVSS 8.8PoC≥ 0, < 5.1.38-dfsg-0ubuntu1.16.04.12017-08-08
CVE-2017-10129 [HIGH] CVE-2017-10129: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle
osv
CVE-2017-10204P3HIGHCVSS 8.8PoC≥ 0, < 5.1.38-dfsg-0ubuntu1.16.04.12017-08-08
CVE-2017-10204 [HIGH] CVE-2017-10204: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle
osv
CVE-2017-3561P3HIGHCVSS 8.8PoC≥ 0, < 5.1.38-dfsg-0ubuntu1.16.04.12017-04-24
CVE-2017-3561 [HIGH] CVE-2017-3561: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerab
osv
CVE-2017-3576P3HIGHCVSS 8.8PoC≥ 0, < 5.1.38-dfsg-0ubuntu1.16.04.12017-04-24
CVE-2017-3576 [HIGH] CVE-2017-3576: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerab
osv
CVE-2017-3563P3HIGHCVSS 8.8PoC≥ 0, < 5.1.38-dfsg-0ubuntu1.16.04.12017-04-24
CVE-2017-3563 [HIGH] CVE-2017-3563: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerab
osv
CVE-2017-3558P3HIGHCVSS 8.5PoC≥ 0, < 5.1.38-dfsg-0ubuntu1.16.04.12017-04-24
CVE-2017-3558 [HIGH] CVE-2017-3558: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnera
osv
CVE-2014-0983P3MEDIUMCVSS 6.9PoC≥ 0, < 4.3.10-dfsg-12014-03-31
CVE-2014-0983 [MEDIUM] CVE-2014-0983: Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch
Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch.py in Oracle VirtualBox 4.2.x through 4.2.20 and 4.3.x before 4.3.8, when using 3D Acceleration, allow local guest OS users to execute arbitrary code on the Chromium server via certain CR_MESS
osv
CVE-2017-3587P3HIGHCVSS 8.4PoC≥ 0, < 5.1.38-dfsg-0ubuntu1.16.04.12017-04-24
CVE-2017-3587 [HIGH] CVE-2017-3587: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Shared Folder)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Shared Folder). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.
osv
CVE-2017-3575P3HIGHCVSS 7.9PoC≥ 0, < 5.1.38-dfsg-0ubuntu1.16.04.12017-04-24
CVE-2017-3575 [HIGH] CVE-2017-3575: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnera
osv
CVE-2009-3692P4HIGHCVSS 7.2PoCv3.0.0v3.0.2+2 more2009-10-13
CVE-2009-3692 [HIGH] CVE-2009-3692: Unspecified vulnerability in the VBoxNetAdpCtl configuration tool in Sun VirtualBox 3.0.x before 3.0
Unspecified vulnerability in the VBoxNetAdpCtl configuration tool in Sun VirtualBox 3.0.x before 3.0.8 on Solaris x86, Linux, and Mac OS X allows local users to gain privileges via unknown vectors.
nvd
CVE-2014-0981P4MEDIUMCVSS 4.4PoC≥ 0, < 4.3.10-dfsg-12014-03-31
CVE-2014-0981 [MEDIUM] CVE-2014-0981: VBox/GuestHost/OpenGL/util/net
VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium server via crafted Chromium network pointer in a (1) CR_MESSAGE_READBACK or (2) CR_MESSAGE_WRITEBACK message to the VBoxSharedCrOpenGL service, which triggers an arbitrary pointe
osv
CVE-2020-2959P3HIGHCVSS 8.6≥ 0, < 6.1.16-dfsg-6~ubuntu1.20.04.12020-04-15
CVE-2020-2959 [HIGH] CVE-2020-2959: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via MLD to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, at
osv
CVE-2014-2477P4LOWCVSS 3.6PoC≥ 0, < 4.3.34-dfsg-1+deb8u1ubuntu1.14.04.12014-07-17
CVE-2014-2477 [LOW] CVE-2014-2477: Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.26, 4.1.34, 4.2.26, and 4.3.12 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-2486.
osv
CVE-2020-2902P3HIGHCVSS 8.8≥ 0, < 6.1.16-dfsg-6~ubuntu1.20.04.12020-04-15
CVE-2020-2902 [HIGH] CVE-2020-2902: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vuln
osv
CVE-2019-2511P3HIGHCVSS 7.5≥ 0, < 6.1.16-dfsg-6~ubuntu1.20.04.12019-01-16
CVE-2019-2511 [HIGH] CVE-2019-2511: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unaut
osv
CVE-2019-2552P3HIGHCVSS 8.8≥ 0, < 6.1.16-dfsg-6~ubuntu1.20.04.12019-01-16
CVE-2019-2552 [HIGH] CVE-2019-2552: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerabili
osv
CVE-2019-2524P3HIGHCVSS 8.8≥ 0, < 6.1.16-dfsg-6~ubuntu1.20.04.12019-01-16
CVE-2019-2524 [HIGH] CVE-2019-2524: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerabili
osv
CVE-2019-2500P3HIGHCVSS 8.8≥ 0, < 6.1.16-dfsg-6~ubuntu1.20.04.12019-01-16
CVE-2019-2500 [HIGH] CVE-2019-2500: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerabili
osv
1 / 8Next →