Vulnerabilities > Oracle > VM Virtualbox

DATE CVE VULNERABILITY TITLE RISK
2016-10-25 CVE-2016-5605 Improper Access Control vulnerability in Oracle VM Virtualbox
Unspecified vulnerability in the Oracle VM VirtualBox component before 5.1.4 in Oracle Virtualization allows remote attackers to affect confidentiality and integrity via vectors related to VRDE.
network
low complexity
oracle CWE-284
critical
9.1
2016-10-25 CVE-2016-5538 Unspecified vulnerability in Oracle VM Virtualbox 5.0.27/5.1.7
Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect confidentiality, integrity, and availability via vectors related to Core, a different vulnerability than CVE-2016-5501.
local
low complexity
oracle
6.7
2016-10-25 CVE-2016-5501 Unspecified vulnerability in Oracle VM Virtualbox
Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect confidentiality, integrity, and availability via vectors related to Core, a different vulnerability than CVE-2016-5538.
local
high complexity
oracle
7.8
2016-07-21 CVE-2016-3612 Unspecified vulnerability in Oracle VM Virtualbox
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 5.0.22 allows remote attackers to affect confidentiality via vectors related to Core.
network
high complexity
oracle
5.9
2016-07-21 CVE-2016-3597 Unspecified vulnerability in Oracle VM Virtualbox
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 5.0.26 allows local users to affect availability via vectors related to Core.
local
low complexity
oracle
5.5
2016-04-21 CVE-2016-0678 Unspecified vulnerability in Oracle VM Virtualbox 5.0.18
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 5.0.18 allows local users to affect confidentiality, integrity, and availability via vectors related to Core.
local
high complexity
oracle
6.7
2016-02-15 CVE-2015-3197 Information Exposure vulnerability in multiple products
ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 traffic, related to the get_client_master_key and get_client_hello functions.
network
high complexity
oracle openssl CWE-200
5.9
2015-12-06 CVE-2015-3195 Information Exposure vulnerability in multiple products
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.
5.3