ALT-BU-2013-1463-1
Branch t7 update bulletin.
Package branding-altlinux-kdesktop updated to version 7.0.2-alt2 for branch t7 in task 111106.
Closed bugs
Запускается в KDE
Package kernel-image-un-def updated to version 3.12.6-alt1 for branch t7 in task 111106.
Closed vulnerabilities
BDU:2014-00094
Уязвимость операционной системы Linux, позволяющая злоумышленнику повысить свои привилегии
BDU:2014-00095
Уязвимость операционной системы Linux, позволяющая злоумышленнику вызвать отказ в обслуживании
Modified: 2025-04-11
CVE-2013-4587
Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main.c in the KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges via a large id value.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=338c7dbadd2671189cec7faf64c84d01071b3f96
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00003.html
- http://lists.opensuse.org/opensuse-updates/2014-02/msg00045.html
- http://www.openwall.com/lists/oss-security/2013/12/12/12
- http://www.ubuntu.com/usn/USN-2109-1
- http://www.ubuntu.com/usn/USN-2110-1
- http://www.ubuntu.com/usn/USN-2113-1
- http://www.ubuntu.com/usn/USN-2117-1
- http://www.ubuntu.com/usn/USN-2128-1
- http://www.ubuntu.com/usn/USN-2129-1
- http://www.ubuntu.com/usn/USN-2135-1
- http://www.ubuntu.com/usn/USN-2136-1
- http://www.ubuntu.com/usn/USN-2138-1
- http://www.ubuntu.com/usn/USN-2139-1
- http://www.ubuntu.com/usn/USN-2141-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1030986
- https://github.com/torvalds/linux/commit/338c7dbadd2671189cec7faf64c84d01071b3f96
- https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.54
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=338c7dbadd2671189cec7faf64c84d01071b3f96
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00003.html
- http://lists.opensuse.org/opensuse-updates/2014-02/msg00045.html
- http://www.openwall.com/lists/oss-security/2013/12/12/12
- http://www.ubuntu.com/usn/USN-2109-1
- http://www.ubuntu.com/usn/USN-2110-1
- http://www.ubuntu.com/usn/USN-2113-1
- http://www.ubuntu.com/usn/USN-2117-1
- http://www.ubuntu.com/usn/USN-2128-1
- http://www.ubuntu.com/usn/USN-2129-1
- http://www.ubuntu.com/usn/USN-2135-1
- http://www.ubuntu.com/usn/USN-2136-1
- http://www.ubuntu.com/usn/USN-2138-1
- http://www.ubuntu.com/usn/USN-2139-1
- http://www.ubuntu.com/usn/USN-2141-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1030986
- https://github.com/torvalds/linux/commit/338c7dbadd2671189cec7faf64c84d01071b3f96
- https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.54
Modified: 2025-04-11
CVE-2013-6367
The apic_get_tmcct function in arch/x86/kvm/lapic.c in the KVM subsystem in the Linux kernel through 3.12.5 allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via crafted modifications of the TMICT value.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b963a22e6d1a266a67e9eecc88134713fd54775c
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00003.html
- http://lists.opensuse.org/opensuse-updates/2014-02/msg00045.html
- http://rhn.redhat.com/errata/RHSA-2013-1801.html
- http://rhn.redhat.com/errata/RHSA-2014-0163.html
- http://rhn.redhat.com/errata/RHSA-2014-0284.html
- http://www.openwall.com/lists/oss-security/2013/12/12/12
- http://www.securityfocus.com/bid/64270
- http://www.ubuntu.com/usn/USN-2109-1
- http://www.ubuntu.com/usn/USN-2110-1
- http://www.ubuntu.com/usn/USN-2113-1
- http://www.ubuntu.com/usn/USN-2117-1
- http://www.ubuntu.com/usn/USN-2128-1
- http://www.ubuntu.com/usn/USN-2129-1
- http://www.ubuntu.com/usn/USN-2135-1
- http://www.ubuntu.com/usn/USN-2136-1
- http://www.ubuntu.com/usn/USN-2138-1
- http://www.ubuntu.com/usn/USN-2139-1
- http://www.ubuntu.com/usn/USN-2141-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1032207
- https://github.com/torvalds/linux/commit/b963a22e6d1a266a67e9eecc88134713fd54775c
- https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.54
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b963a22e6d1a266a67e9eecc88134713fd54775c
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00003.html
- http://lists.opensuse.org/opensuse-updates/2014-02/msg00045.html
- http://rhn.redhat.com/errata/RHSA-2013-1801.html
- http://rhn.redhat.com/errata/RHSA-2014-0163.html
- http://rhn.redhat.com/errata/RHSA-2014-0284.html
- http://www.openwall.com/lists/oss-security/2013/12/12/12
- http://www.securityfocus.com/bid/64270
- http://www.ubuntu.com/usn/USN-2109-1
- http://www.ubuntu.com/usn/USN-2110-1
- http://www.ubuntu.com/usn/USN-2113-1
- http://www.ubuntu.com/usn/USN-2117-1
- http://www.ubuntu.com/usn/USN-2128-1
- http://www.ubuntu.com/usn/USN-2129-1
- http://www.ubuntu.com/usn/USN-2135-1
- http://www.ubuntu.com/usn/USN-2136-1
- http://www.ubuntu.com/usn/USN-2138-1
- http://www.ubuntu.com/usn/USN-2139-1
- http://www.ubuntu.com/usn/USN-2141-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1032207
- https://github.com/torvalds/linux/commit/b963a22e6d1a266a67e9eecc88134713fd54775c
- https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.54
Modified: 2025-04-11
CVE-2013-6368
The KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges or cause a denial of service (system crash) via a VAPIC synchronization operation involving a page-end address.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fda4e2e85589191b123d31cdc21fd33ee70f50fd
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00003.html
- http://lists.opensuse.org/opensuse-updates/2014-02/msg00045.html
- http://rhn.redhat.com/errata/RHSA-2013-1801.html
- http://rhn.redhat.com/errata/RHSA-2014-0163.html
- http://rhn.redhat.com/errata/RHSA-2014-0284.html
- http://www.openwall.com/lists/oss-security/2013/12/12/12
- http://www.securityfocus.com/bid/64291
- http://www.ubuntu.com/usn/USN-2113-1
- http://www.ubuntu.com/usn/USN-2117-1
- http://www.ubuntu.com/usn/USN-2133-1
- http://www.ubuntu.com/usn/USN-2134-1
- http://www.ubuntu.com/usn/USN-2135-1
- http://www.ubuntu.com/usn/USN-2136-1
- http://www.ubuntu.com/usn/USN-2138-1
- http://www.ubuntu.com/usn/USN-2139-1
- http://www.ubuntu.com/usn/USN-2141-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1032210
- https://github.com/torvalds/linux/commit/fda4e2e85589191b123d31cdc21fd33ee70f50fd
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fda4e2e85589191b123d31cdc21fd33ee70f50fd
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00003.html
- http://lists.opensuse.org/opensuse-updates/2014-02/msg00045.html
- http://rhn.redhat.com/errata/RHSA-2013-1801.html
- http://rhn.redhat.com/errata/RHSA-2014-0163.html
- http://rhn.redhat.com/errata/RHSA-2014-0284.html
- http://www.openwall.com/lists/oss-security/2013/12/12/12
- http://www.securityfocus.com/bid/64291
- http://www.ubuntu.com/usn/USN-2113-1
- http://www.ubuntu.com/usn/USN-2117-1
- http://www.ubuntu.com/usn/USN-2133-1
- http://www.ubuntu.com/usn/USN-2134-1
- http://www.ubuntu.com/usn/USN-2135-1
- http://www.ubuntu.com/usn/USN-2136-1
- http://www.ubuntu.com/usn/USN-2138-1
- http://www.ubuntu.com/usn/USN-2139-1
- http://www.ubuntu.com/usn/USN-2141-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1032210
- https://github.com/torvalds/linux/commit/fda4e2e85589191b123d31cdc21fd33ee70f50fd
Modified: 2025-04-11
CVE-2013-6376
The recalculate_apic_map function in arch/x86/kvm/lapic.c in the KVM subsystem in the Linux kernel through 3.12.5 allows guest OS users to cause a denial of service (host OS crash) via a crafted ICR write operation in x2apic mode.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=17d68b763f09a9ce824ae23eb62c9efc57b69271
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00003.html
- http://www.openwall.com/lists/oss-security/2013/12/12/12
- http://www.securityfocus.com/bid/64319
- http://www.ubuntu.com/usn/USN-2113-1
- http://www.ubuntu.com/usn/USN-2117-1
- http://www.ubuntu.com/usn/USN-2136-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1033106
- https://github.com/torvalds/linux/commit/17d68b763f09a9ce824ae23eb62c9efc57b69271
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=17d68b763f09a9ce824ae23eb62c9efc57b69271
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00003.html
- http://www.openwall.com/lists/oss-security/2013/12/12/12
- http://www.securityfocus.com/bid/64319
- http://www.ubuntu.com/usn/USN-2113-1
- http://www.ubuntu.com/usn/USN-2117-1
- http://www.ubuntu.com/usn/USN-2136-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1033106
- https://github.com/torvalds/linux/commit/17d68b763f09a9ce824ae23eb62c9efc57b69271
Package kernel-modules-virtualbox-addition-std-def updated to version 4.3.4-alt1.199193.1 for branch t7 in task 111106.
Closed vulnerabilities
Modified: 2025-04-11
CVE-2014-0404
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0406.
- http://osvdb.org/102061
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64911
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90372
- http://osvdb.org/102061
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64911
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90372
Modified: 2025-04-11
CVE-2014-0405
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0407.
- http://osvdb.org/102059
- http://secunia.com/advisories/56490
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64900
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90370
- http://osvdb.org/102059
- http://secunia.com/advisories/56490
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64900
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90370
Modified: 2025-04-11
CVE-2014-0406
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0404.
- http://osvdb.org/102060
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64905
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90371
- http://osvdb.org/102060
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64905
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90371
Modified: 2025-04-11
CVE-2014-0407
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0405.
- http://osvdb.org/102058
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64913
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90369
- http://osvdb.org/102058
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64913
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90369
Modified: 2025-04-12
CVE-2015-0377
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.26, 4.0.28, 4.1.36, and 4.2.28 allows local users to affect availability via unknown vectors related to Core, a different vulnerability than CVE-2015-0418.
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.c7zero.info/stuff/csw2017_ExploringYourSystemDeeper_updated.pdf
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72219
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100176
- https://security.gentoo.org/glsa/201612-27
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.c7zero.info/stuff/csw2017_ExploringYourSystemDeeper_updated.pdf
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72219
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100176
- https://security.gentoo.org/glsa/201612-27
Modified: 2025-04-12
CVE-2015-0418
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.26, 4.0.28, 4.1.36, and 4.2.28 allows local users to affect availability via unknown vectors related to Core, a different vulnerability than CVE-2015-0377.
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72194
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100182
- https://security.gentoo.org/glsa/201612-27
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72194
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100182
- https://security.gentoo.org/glsa/201612-27
Package kernel-modules-virtualbox-std-def updated to version 4.3.4-alt1.199193.1 for branch t7 in task 111106.
Closed vulnerabilities
Modified: 2025-04-11
CVE-2014-0404
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0406.
- http://osvdb.org/102061
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64911
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90372
- http://osvdb.org/102061
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64911
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90372
Modified: 2025-04-11
CVE-2014-0405
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0407.
- http://osvdb.org/102059
- http://secunia.com/advisories/56490
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64900
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90370
- http://osvdb.org/102059
- http://secunia.com/advisories/56490
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64900
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90370
Modified: 2025-04-11
CVE-2014-0406
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0404.
- http://osvdb.org/102060
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64905
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90371
- http://osvdb.org/102060
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64905
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90371
Modified: 2025-04-11
CVE-2014-0407
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0405.
- http://osvdb.org/102058
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64913
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90369
- http://osvdb.org/102058
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64913
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90369
Modified: 2025-04-12
CVE-2015-0377
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.26, 4.0.28, 4.1.36, and 4.2.28 allows local users to affect availability via unknown vectors related to Core, a different vulnerability than CVE-2015-0418.
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.c7zero.info/stuff/csw2017_ExploringYourSystemDeeper_updated.pdf
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72219
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100176
- https://security.gentoo.org/glsa/201612-27
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.c7zero.info/stuff/csw2017_ExploringYourSystemDeeper_updated.pdf
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72219
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100176
- https://security.gentoo.org/glsa/201612-27
Modified: 2025-04-12
CVE-2015-0418
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.26, 4.0.28, 4.1.36, and 4.2.28 allows local users to affect availability via unknown vectors related to Core, a different vulnerability than CVE-2015-0377.
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72194
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100182
- https://security.gentoo.org/glsa/201612-27
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72194
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100182
- https://security.gentoo.org/glsa/201612-27
Package kernel-modules-virtualbox-un-def updated to version 4.3.4-alt1.199686.1 for branch t7 in task 111106.
Closed vulnerabilities
Modified: 2025-04-11
CVE-2014-0404
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0406.
- http://osvdb.org/102061
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64911
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90372
- http://osvdb.org/102061
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64911
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90372
Modified: 2025-04-11
CVE-2014-0405
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0407.
- http://osvdb.org/102059
- http://secunia.com/advisories/56490
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64900
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90370
- http://osvdb.org/102059
- http://secunia.com/advisories/56490
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64900
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90370
Modified: 2025-04-11
CVE-2014-0406
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0404.
- http://osvdb.org/102060
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64905
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90371
- http://osvdb.org/102060
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64905
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90371
Modified: 2025-04-11
CVE-2014-0407
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0405.
- http://osvdb.org/102058
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64913
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90369
- http://osvdb.org/102058
- http://secunia.com/advisories/56490
- http://www.debian.org/security/2014/dsa-2878
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/64758
- http://www.securityfocus.com/bid/64913
- http://www.securitytracker.com/id/1029610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90369
Modified: 2025-04-12
CVE-2015-0377
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.26, 4.0.28, 4.1.36, and 4.2.28 allows local users to affect availability via unknown vectors related to Core, a different vulnerability than CVE-2015-0418.
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.c7zero.info/stuff/csw2017_ExploringYourSystemDeeper_updated.pdf
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72219
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100176
- https://security.gentoo.org/glsa/201612-27
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.c7zero.info/stuff/csw2017_ExploringYourSystemDeeper_updated.pdf
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72219
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100176
- https://security.gentoo.org/glsa/201612-27
Modified: 2025-04-12
CVE-2015-0418
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.26, 4.0.28, 4.1.36, and 4.2.28 allows local users to affect availability via unknown vectors related to Core, a different vulnerability than CVE-2015-0377.
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72194
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100182
- https://security.gentoo.org/glsa/201612-27
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html
- http://secunia.com/advisories/62694
- http://www.debian.org/security/2015/dsa-3143
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72194
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100182
- https://security.gentoo.org/glsa/201612-27