CVE-2015-4896

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.0.34, 4.1.42, 4.2.34, 4.3.32, and 5.0.8, when a VM has the Remote Display feature (RDP) enabled, allows remote attackers to affect availability via unknown vectors related to Core.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
oracleCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
VendorProductVersion
oraclevm_virtualbox
4.0.0 ≤
𝑥
< 4.0.34
oraclevm_virtualbox
4.1.0 ≤
𝑥
< 4.1.42
oraclevm_virtualbox
4.2.0 ≤
𝑥
< 4.2.34
oraclevm_virtualbox
4.3.0 ≤
𝑥
< 4.3.32
oraclevm_virtualbox
5.0.0 ≤
𝑥
< 5.0.8
debiandebian_linux
7.0
debiandebian_linux
8.0
debiandebian_linux
9.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
virtualbox
sid/contrib
7.0.20-dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
virtualbox
wily
Fixed 5.0.10-dfsg-2ubuntu1
released
vivid
Fixed 4.3.34-dfsg-1+deb8u1ubuntu1.14.04.1
released
trusty
Fixed 4.3.34-dfsg-1+deb8u1ubuntu1.14.04.1
released
precise
Fixed 4.1.44-dfsg-1+deb7u1ubuntu1
released