rpm package
opensuse/virtualbox&distro=openSUSE Leap 15.2
pkg:rpm/opensuse/virtualbox&distro=openSUSE%20Leap%2015.2
Vulnerabilities (64)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-2284 | — | < 6.1.22-lp152.2.24.2 | 6.1.22-lp152.2.24.2 | Apr 22, 2021 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox ex | ||
| CVE-2021-2283 | — | < 6.1.22-lp152.2.24.2 | 6.1.22-lp152.2.24.2 | Apr 22, 2021 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox ex | ||
| CVE-2021-2282 | — | < 6.1.22-lp152.2.24.2 | 6.1.22-lp152.2.24.2 | Apr 22, 2021 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox ex | ||
| CVE-2021-2281 | — | < 6.1.22-lp152.2.24.2 | 6.1.22-lp152.2.24.2 | Apr 22, 2021 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox ex | ||
| CVE-2021-2280 | — | < 6.1.22-lp152.2.24.2 | 6.1.22-lp152.2.24.2 | Apr 22, 2021 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox ex | ||
| CVE-2021-2279 | — | < 6.1.22-lp152.2.24.2 | 6.1.22-lp152.2.24.2 | Apr 22, 2021 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Difficult to exploit vulnerability allows unauthenticated attacker with network access via RDP to compromise Oracle VM VirtualB | ||
| CVE-2021-2266 | — | < 6.1.22-lp152.2.24.2 | 6.1.22-lp152.2.24.2 | Apr 22, 2021 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox ex | ||
| CVE-2021-2264 | — | < 6.1.20-lp152.2.21.1 | 6.1.20-lp152.2.21.1 | Apr 22, 2021 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox exe | ||
| CVE-2021-2250 | — | < 6.1.22-lp152.2.24.2 | 6.1.22-lp152.2.24.2 | Apr 22, 2021 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox ex | ||
| CVE-2021-2145 | — | < 6.1.22-lp152.2.24.2 | 6.1.22-lp152.2.24.2 | Apr 22, 2021 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox | ||
| CVE-2021-2129 | — | < 6.1.18-lp152.2.11.1 | 6.1.18-lp152.2.11.1 | Jan 20, 2021 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.18. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox ex | ||
| CVE-2021-2074 | — | < 6.1.18-lp152.2.11.1 | 6.1.18-lp152.2.11.1 | Jan 20, 2021 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.18. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox ex | ||
| CVE-2020-10781 | — | < 6.1.10-lp152.2.2.1 | 6.1.10-lp152.2.2.1 | Sep 16, 2020 | A flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module, where a user with a local account and the ability to read the /sys/class/zram-control/hot_add file can create ZRAM device nodes in the /dev/ directory. This read allocates kernel memory and is not acco | ||
| CVE-2020-14331 | — | < 6.1.10-lp152.2.2.1 | 6.1.10-lp152.2.2.1 | Sep 15, 2020 | A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when a local attacker attempts to resize the console, calling an ioctl VT_RESIZE, which causes an out-of-bounds write to occur. This flaw allows a local user with access to the VGA cons | ||
| CVE-2020-14356 | — | < 6.1.10-lp152.2.2.1 | 6.1.10-lp152.2.2.1 | Aug 19, 2020 | A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system. | ||
| CVE-2020-16166 | — | < 6.1.10-lp152.2.2.1 | 6.1.10-lp152.2.2.1 | Jul 30, 2020 | The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c. | ||
| CVE-2020-0305 | — | < 6.1.10-lp152.2.2.1 | 6.1.10-lp152.2.2.1 | Jul 17, 2020 | In cdev_get of char_dev.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-15346 | ||
| CVE-2020-15780 | — | < 6.1.10-lp152.2.2.1 | 6.1.10-lp152.2.2.1 | Jul 15, 2020 | An issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI tables via configfs could be used by attackers to bypass lockdown and secure boot restrictions, aka CID-75b0cea7bf30. | ||
| CVE-2020-14715 | — | < 6.1.14-lp152.2.5.1 | 6.1.14-lp152.2.5.1 | Jul 15, 2020 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastr | ||
| CVE-2020-14714 | — | < 6.1.14-lp152.2.5.1 | 6.1.14-lp152.2.5.1 | Jul 15, 2020 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastr |
- CVE-2021-2284Apr 22, 2021affected < 6.1.22-lp152.2.24.2fixed 6.1.22-lp152.2.24.2
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox ex
- CVE-2021-2283Apr 22, 2021affected < 6.1.22-lp152.2.24.2fixed 6.1.22-lp152.2.24.2
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox ex
- CVE-2021-2282Apr 22, 2021affected < 6.1.22-lp152.2.24.2fixed 6.1.22-lp152.2.24.2
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox ex
- CVE-2021-2281Apr 22, 2021affected < 6.1.22-lp152.2.24.2fixed 6.1.22-lp152.2.24.2
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox ex
- CVE-2021-2280Apr 22, 2021affected < 6.1.22-lp152.2.24.2fixed 6.1.22-lp152.2.24.2
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox ex
- CVE-2021-2279Apr 22, 2021affected < 6.1.22-lp152.2.24.2fixed 6.1.22-lp152.2.24.2
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Difficult to exploit vulnerability allows unauthenticated attacker with network access via RDP to compromise Oracle VM VirtualB
- CVE-2021-2266Apr 22, 2021affected < 6.1.22-lp152.2.24.2fixed 6.1.22-lp152.2.24.2
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox ex
- CVE-2021-2264Apr 22, 2021affected < 6.1.20-lp152.2.21.1fixed 6.1.20-lp152.2.21.1
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox exe
- CVE-2021-2250Apr 22, 2021affected < 6.1.22-lp152.2.24.2fixed 6.1.22-lp152.2.24.2
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox ex
- CVE-2021-2145Apr 22, 2021affected < 6.1.22-lp152.2.24.2fixed 6.1.22-lp152.2.24.2
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox
- CVE-2021-2129Jan 20, 2021affected < 6.1.18-lp152.2.11.1fixed 6.1.18-lp152.2.11.1
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.18. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox ex
- CVE-2021-2074Jan 20, 2021affected < 6.1.18-lp152.2.11.1fixed 6.1.18-lp152.2.11.1
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.18. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox ex
- CVE-2020-10781Sep 16, 2020affected < 6.1.10-lp152.2.2.1fixed 6.1.10-lp152.2.2.1
A flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module, where a user with a local account and the ability to read the /sys/class/zram-control/hot_add file can create ZRAM device nodes in the /dev/ directory. This read allocates kernel memory and is not acco
- CVE-2020-14331Sep 15, 2020affected < 6.1.10-lp152.2.2.1fixed 6.1.10-lp152.2.2.1
A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when a local attacker attempts to resize the console, calling an ioctl VT_RESIZE, which causes an out-of-bounds write to occur. This flaw allows a local user with access to the VGA cons
- CVE-2020-14356Aug 19, 2020affected < 6.1.10-lp152.2.2.1fixed 6.1.10-lp152.2.2.1
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.
- CVE-2020-16166Jul 30, 2020affected < 6.1.10-lp152.2.2.1fixed 6.1.10-lp152.2.2.1
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.
- CVE-2020-0305Jul 17, 2020affected < 6.1.10-lp152.2.2.1fixed 6.1.10-lp152.2.2.1
In cdev_get of char_dev.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-15346
- CVE-2020-15780Jul 15, 2020affected < 6.1.10-lp152.2.2.1fixed 6.1.10-lp152.2.2.1
An issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI tables via configfs could be used by attackers to bypass lockdown and secure boot restrictions, aka CID-75b0cea7bf30.
- CVE-2020-14715Jul 15, 2020affected < 6.1.14-lp152.2.5.1fixed 6.1.14-lp152.2.5.1
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastr
- CVE-2020-14714Jul 15, 2020affected < 6.1.14-lp152.2.5.1fixed 6.1.14-lp152.2.5.1
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastr
Page 2 of 4