ALT-BU-2013-1448-1
Branch sisyphus update bulletin.
Package virtualbox updated to version 4.3.4-alt1 for branch sisyphus in task 109958.
Closed vulnerabilities
Modified: 2025-04-11
CVE-2014-0404
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0406.
- http://osvdb.org/102061
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64911
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90372
- http://osvdb.org/102061
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64911
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90372
Modified: 2025-04-11
CVE-2014-0405
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0407.
- http://osvdb.org/102059
- http://secunia.com/advisories/56490
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64900
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90370
- http://osvdb.org/102059
- http://secunia.com/advisories/56490
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64900
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90370
Modified: 2025-04-11
CVE-2014-0406
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0404.
- http://osvdb.org/102060
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64905
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90371
- http://osvdb.org/102060
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64905
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90371
Modified: 2025-04-11
CVE-2014-0407
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0405.
- http://osvdb.org/102058
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64913
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90369
- http://osvdb.org/102058
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64913
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90369
Modified: 2025-04-12
CVE-2015-0377
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.26, 4.0.28, 4.1.36, and 4.2.28 allows local users to affect availability via unknown vectors related to Core, a different vulnerability than CVE-2015-0418.
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.c7zero.info/stuff/csw2017_ExploringYourSystemDeeper_updated.pdf
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72219
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100176
- https://security.gentoo.org/glsa/201612-27
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.c7zero.info/stuff/csw2017_ExploringYourSystemDeeper_updated.pdf
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72219
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100176
- https://security.gentoo.org/glsa/201612-27
Modified: 2025-04-12
CVE-2015-0418
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.26, 4.0.28, 4.1.36, and 4.2.28 allows local users to affect availability via unknown vectors related to Core, a different vulnerability than CVE-2015-0377.
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72194
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100182
- https://security.gentoo.org/glsa/201612-27
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72194
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100182
- https://security.gentoo.org/glsa/201612-27
Package kernel-modules-virtualbox-addition-std-def updated to version 4.3.4-alt1.199192.1 for branch sisyphus in task 109958.
Closed vulnerabilities
Modified: 2025-04-11
CVE-2014-0404
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0406.
- http://osvdb.org/102061
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64911
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90372
- http://osvdb.org/102061
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64911
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90372
Modified: 2025-04-11
CVE-2014-0405
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0407.
- http://osvdb.org/102059
- http://secunia.com/advisories/56490
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64900
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90370
- http://osvdb.org/102059
- http://secunia.com/advisories/56490
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64900
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90370
Modified: 2025-04-11
CVE-2014-0406
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0404.
- http://osvdb.org/102060
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64905
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90371
- http://osvdb.org/102060
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64905
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90371
Modified: 2025-04-11
CVE-2014-0407
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0405.
- http://osvdb.org/102058
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64913
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90369
- http://osvdb.org/102058
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64913
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90369
Modified: 2025-04-12
CVE-2015-0377
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.26, 4.0.28, 4.1.36, and 4.2.28 allows local users to affect availability via unknown vectors related to Core, a different vulnerability than CVE-2015-0418.
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.c7zero.info/stuff/csw2017_ExploringYourSystemDeeper_updated.pdf
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72219
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100176
- https://security.gentoo.org/glsa/201612-27
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.c7zero.info/stuff/csw2017_ExploringYourSystemDeeper_updated.pdf
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72219
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100176
- https://security.gentoo.org/glsa/201612-27
Modified: 2025-04-12
CVE-2015-0418
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.26, 4.0.28, 4.1.36, and 4.2.28 allows local users to affect availability via unknown vectors related to Core, a different vulnerability than CVE-2015-0377.
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72194
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100182
- https://security.gentoo.org/glsa/201612-27
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72194
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100182
- https://security.gentoo.org/glsa/201612-27
Package kernel-modules-virtualbox-std-def updated to version 4.3.4-alt1.199192.1 for branch sisyphus in task 109958.
Closed vulnerabilities
Modified: 2025-04-11
CVE-2014-0404
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0406.
- http://osvdb.org/102061
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64911
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90372
- http://osvdb.org/102061
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64911
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90372
Modified: 2025-04-11
CVE-2014-0405
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0407.
- http://osvdb.org/102059
- http://secunia.com/advisories/56490
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64900
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90370
- http://osvdb.org/102059
- http://secunia.com/advisories/56490
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64900
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90370
Modified: 2025-04-11
CVE-2014-0406
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0404.
- http://osvdb.org/102060
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64905
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90371
- http://osvdb.org/102060
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64905
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90371
Modified: 2025-04-11
CVE-2014-0407
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0405.
- http://osvdb.org/102058
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64913
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90369
- http://osvdb.org/102058
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64913
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90369
Modified: 2025-04-12
CVE-2015-0377
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.26, 4.0.28, 4.1.36, and 4.2.28 allows local users to affect availability via unknown vectors related to Core, a different vulnerability than CVE-2015-0418.
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.c7zero.info/stuff/csw2017_ExploringYourSystemDeeper_updated.pdf
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72219
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100176
- https://security.gentoo.org/glsa/201612-27
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.c7zero.info/stuff/csw2017_ExploringYourSystemDeeper_updated.pdf
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72219
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100176
- https://security.gentoo.org/glsa/201612-27
Modified: 2025-04-12
CVE-2015-0418
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.26, 4.0.28, 4.1.36, and 4.2.28 allows local users to affect availability via unknown vectors related to Core, a different vulnerability than CVE-2015-0377.
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72194
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100182
- https://security.gentoo.org/glsa/201612-27
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72194
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100182
- https://security.gentoo.org/glsa/201612-27
Package kernel-modules-virtualbox-un-def updated to version 4.3.4-alt1.199685.1 for branch sisyphus in task 109958.
Closed vulnerabilities
Modified: 2025-04-11
CVE-2014-0404
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0406.
- http://osvdb.org/102061
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64911
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90372
- http://osvdb.org/102061
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64911
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90372
Modified: 2025-04-11
CVE-2014-0405
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0407.
- http://osvdb.org/102059
- http://secunia.com/advisories/56490
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64900
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90370
- http://osvdb.org/102059
- http://secunia.com/advisories/56490
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64900
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90370
Modified: 2025-04-11
CVE-2014-0406
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0404.
- http://osvdb.org/102060
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64905
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90371
- http://osvdb.org/102060
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64905
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90371
Modified: 2025-04-11
CVE-2014-0407
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0405.
- http://osvdb.org/102058
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64913
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90369
- http://osvdb.org/102058
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64913
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90369
Modified: 2025-04-12
CVE-2015-0377
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.26, 4.0.28, 4.1.36, and 4.2.28 allows local users to affect availability via unknown vectors related to Core, a different vulnerability than CVE-2015-0418.
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.c7zero.info/stuff/csw2017_ExploringYourSystemDeeper_updated.pdf
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72219
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100176
- https://security.gentoo.org/glsa/201612-27
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.c7zero.info/stuff/csw2017_ExploringYourSystemDeeper_updated.pdf
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72219
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100176
- https://security.gentoo.org/glsa/201612-27
Modified: 2025-04-12
CVE-2015-0418
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.26, 4.0.28, 4.1.36, and 4.2.28 allows local users to affect availability via unknown vectors related to Core, a different vulnerability than CVE-2015-0377.
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72194
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100182
- https://security.gentoo.org/glsa/201612-27
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72194
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100182
- https://security.gentoo.org/glsa/201612-27
Closed vulnerabilities
Modified: 2021-03-23
BDU:2015-09726
Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
Modified: 2025-04-11
CVE-2013-4545
cURL and libcurl 7.18.0 through 7.32.0, when built with OpenSSL, disables the certificate CN and SAN name field verification (CURLOPT_SSL_VERIFYHOST) when the digital signature verification (CURLOPT_SSL_VERIFYPEER) is disabled, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
- http://curl.haxx.se/docs/adv_20131115.html
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00047.html
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00053.html
- http://www.debian.org/security/2013/dsa-2798
- http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
- http://www.ubuntu.com/usn/USN-2048-1
- https://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04463322
- http://curl.haxx.se/docs/adv_20131115.html
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00047.html
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00053.html
- http://www.debian.org/security/2013/dsa-2798
- http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
- http://www.ubuntu.com/usn/USN-2048-1
- https://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04463322
Modified: 2025-04-11
CVE-2013-6422
The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
- http://curl.haxx.se/docs/adv_20131217.html
- http://www.debian.org/security/2013/dsa-2824
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
- http://www.ubuntu.com/usn/USN-2058-1
- https://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04463322
- http://curl.haxx.se/docs/adv_20131217.html
- http://www.debian.org/security/2013/dsa-2824
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
- http://www.ubuntu.com/usn/USN-2058-1
- https://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04463322
Closed vulnerabilities
Modified: 2025-04-11
CVE-2013-6411
The HandleCrashedAircraft function in aircraft_cmd.cpp in OpenTTD 0.3.6 through 1.3.2 allows remote attackers to cause a denial of service (out-of-bounds read and crash) by crashing an aircraft outside of the map.
- http://bugs.openttd.org/task/5820
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00095.html
- http://seclists.org/oss-sec/2013/q4/375
- http://secunia.com/advisories/55589
- http://secunia.com/advisories/56218
- http://vcs.openttd.org/svn/changeset/26134
- http://www.securityfocus.com/bid/64003
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89334
- https://security.openttd.org/en/CVE-2013-6411
- http://bugs.openttd.org/task/5820
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00095.html
- http://seclists.org/oss-sec/2013/q4/375
- http://secunia.com/advisories/55589
- http://secunia.com/advisories/56218
- http://vcs.openttd.org/svn/changeset/26134
- http://www.securityfocus.com/bid/64003
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89334
- https://security.openttd.org/en/CVE-2013-6411