rpm package
opensuse/virtualbox&distro=openSUSE Leap 15.1
pkg:rpm/opensuse/virtualbox&distro=openSUSE%20Leap%2015.1
Vulnerabilities (96)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-2703 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Apr 23, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2696 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Apr 23, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2690 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Apr 23, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where | ||
| CVE-2019-2680 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Apr 23, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2679 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Apr 23, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2678 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Apr 23, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2657 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Apr 23, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2656 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Apr 23, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2574 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Apr 23, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-1543 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Mar 6, 2019 | ChaCha20-Poly1305 is an AEAD cipher, and requires a unique nonce input for every encryption operation. RFC 7539 specifies that the nonce value (IV) should be 96 bits (12 bytes). OpenSSL allows a variable nonce length and front pads the nonce with 0 bytes if it is less than 12 byt | ||
| CVE-2019-2556 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2555 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2554 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2527 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.26 and prior to 6.0.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2525 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where | ||
| CVE-2019-2511 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to comprom | ||
| CVE-2019-2509 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2508 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2451 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O | ||
| CVE-2019-2450 | — | < 6.0.10-lp151.2.6.1 | 6.0.10-lp151.2.6.1 | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O |
- CVE-2019-2703Apr 23, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2696Apr 23, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2690Apr 23, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where
- CVE-2019-2680Apr 23, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2679Apr 23, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2678Apr 23, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2657Apr 23, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2656Apr 23, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2574Apr 23, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-1543Mar 6, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
ChaCha20-Poly1305 is an AEAD cipher, and requires a unique nonce input for every encryption operation. RFC 7539 specifies that the nonce value (IV) should be 96 bits (12 bytes). OpenSSL allows a variable nonce length and front pads the nonce with 0 bytes if it is less than 12 byt
- CVE-2019-2556Jan 16, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2555Jan 16, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2554Jan 16, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2527Jan 16, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.26 and prior to 6.0.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2525Jan 16, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where
- CVE-2019-2511Jan 16, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to comprom
- CVE-2019-2509Jan 16, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2508Jan 16, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2451Jan 16, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
- CVE-2019-2450Jan 16, 2019affected < 6.0.10-lp151.2.6.1fixed 6.0.10-lp151.2.6.1
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where O
Page 4 of 5