rpm package
opensuse/virtualbox&distro=openSUSE Leap 15.0
pkg:rpm/opensuse/virtualbox&distro=openSUSE%20Leap%2015.0
Vulnerabilities (67)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-2679 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Apr 23, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2678 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Apr 23, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2657 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Apr 23, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2656 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Apr 23, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2574 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Apr 23, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-1543 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Mar 6, 2019 | ChaCha20-Poly1305 is an AEAD cipher, and requires a unique nonce input for every encryption operation. RFC 7539 specifies that the nonce value (IV) should be 96 bits (12 bytes). OpenSSL allows a variable nonce length and front pads the nonce with 0 bytes if it is less than 12 byt | ||
| CVE-2019-2556 | — | < 5.2.24-lp150.4.33.1 | 5.2.24-lp150.4.33.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2555 | — | < 5.2.24-lp150.4.33.1 | 5.2.24-lp150.4.33.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2554 | — | < 5.2.24-lp150.4.33.1 | 5.2.24-lp150.4.33.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2553 | — | < 5.2.24-lp150.4.33.1 | 5.2.24-lp150.4.33.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2552 | — | < 5.2.24-lp150.4.33.1 | 5.2.24-lp150.4.33.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2548 | — | < 5.2.24-lp150.4.33.1 | 5.2.24-lp150.4.33.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2527 | — | < 5.2.24-lp150.4.33.1 | 5.2.24-lp150.4.33.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.26 and prior to 6.0.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2526 | — | < 5.2.24-lp150.4.33.1 | 5.2.24-lp150.4.33.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where | ||
| CVE-2019-2525 | — | < 5.2.24-lp150.4.33.1 | 5.2.24-lp150.4.33.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where | ||
| CVE-2019-2524 | — | < 5.2.24-lp150.4.33.1 | 5.2.24-lp150.4.33.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2523 | — | < 5.2.24-lp150.4.33.1 | 5.2.24-lp150.4.33.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where | ||
| CVE-2019-2522 | — | < 5.2.24-lp150.4.33.1 | 5.2.24-lp150.4.33.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where | ||
| CVE-2019-2521 | — | < 5.2.24-lp150.4.33.1 | 5.2.24-lp150.4.33.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where | ||
| CVE-2019-2520 | — | < 5.2.24-lp150.4.33.1 | 5.2.24-lp150.4.33.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where |
- CVE-2019-2679Apr 23, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2678Apr 23, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2657Apr 23, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2656Apr 23, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2574Apr 23, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-1543Mar 6, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
ChaCha20-Poly1305 is an AEAD cipher, and requires a unique nonce input for every encryption operation. RFC 7539 specifies that the nonce value (IV) should be 96 bits (12 bytes). OpenSSL allows a variable nonce length and front pads the nonce with 0 bytes if it is less than 12 byt
- CVE-2019-2556Jan 16, 2019affected < 5.2.24-lp150.4.33.1fixed 5.2.24-lp150.4.33.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2555Jan 16, 2019affected < 5.2.24-lp150.4.33.1fixed 5.2.24-lp150.4.33.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2554Jan 16, 2019affected < 5.2.24-lp150.4.33.1fixed 5.2.24-lp150.4.33.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2553Jan 16, 2019affected < 5.2.24-lp150.4.33.1fixed 5.2.24-lp150.4.33.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2552Jan 16, 2019affected < 5.2.24-lp150.4.33.1fixed 5.2.24-lp150.4.33.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2548Jan 16, 2019affected < 5.2.24-lp150.4.33.1fixed 5.2.24-lp150.4.33.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2527Jan 16, 2019affected < 5.2.24-lp150.4.33.1fixed 5.2.24-lp150.4.33.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.26 and prior to 6.0.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2526Jan 16, 2019affected < 5.2.24-lp150.4.33.1fixed 5.2.24-lp150.4.33.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where
- CVE-2019-2525Jan 16, 2019affected < 5.2.24-lp150.4.33.1fixed 5.2.24-lp150.4.33.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where
- CVE-2019-2524Jan 16, 2019affected < 5.2.24-lp150.4.33.1fixed 5.2.24-lp150.4.33.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2523Jan 16, 2019affected < 5.2.24-lp150.4.33.1fixed 5.2.24-lp150.4.33.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where
- CVE-2019-2522Jan 16, 2019affected < 5.2.24-lp150.4.33.1fixed 5.2.24-lp150.4.33.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where
- CVE-2019-2521Jan 16, 2019affected < 5.2.24-lp150.4.33.1fixed 5.2.24-lp150.4.33.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where
- CVE-2019-2520Jan 16, 2019affected < 5.2.24-lp150.4.33.1fixed 5.2.24-lp150.4.33.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where
Page 2 of 4