CVE-2014-0407

high

Description

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0405.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/90369

http://www.securitytracker.com/id/1029610

http://www.securityfocus.com/bid/64913

http://www.securityfocus.com/bid/64758

http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html

http://www.debian.org/security/2014/dsa-2878

http://secunia.com/advisories/56490

http://osvdb.org/102058

Details

Source: Mitre, NVD

Published: 2014-01-15

Updated: 2017-08-29

Risk Information

CVSS v2

Base Score: 3.5

Vector: CVSS2#AV:L/AC:H/Au:S/C:P/I:P/A:P

Severity: Low

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Severity: High