Where
AND
AND
-Infinity
0
Severity
6.9
AV:L/AC:M/Au:N/C:C/I:C/A:C

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.26, 4.1.34, 4.2.26, and 4.3.14 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-2487.

First published (updated )
Severity
4.4
AV:L/AC:M/Au:N/C:P/I:P/A:P

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.1.34, 4.2.26, and 4.3.12 allows local users to affect confidentiality, integrity, and availability via vectors related to Graphics driver (WDDM) for Windows guests.

First published (updated )
Severity
4.4
AV:L/AC:M/Au:N/C:P/I:P/A:P

VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium server via crafted Chromium network pointer in a (1) CRMESSAGEREADBACK or (2) CRMESSAGEWRITEBACK message to the VBoxSharedCrOpenGL service, which triggers an arbitrary pointer dereference and memory corruption. NOTE: this issue was MERGED with CVE-2014-0982 because it is the same type of vulnerability affecting the same set of versions. All CVE users should reference CVE-2014-0981 instead of CVE-2014-0982.

First published (updated )
Severity
6.9
AV:L/AC:M/Au:N/C:C/I:C/A:C

Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/serverdispatch.py in Oracle VirtualBox 4.2.x through 4.2.20 and 4.3.x before 4.3.8, when using 3D Acceleration, allow local guest OS users to execute arbitrary code on the Chromium server via certain CRMESSAGEOPCODES messages with a crafted index, which are not properly handled by the (1) CRVERTEXATTRIB4NUBARBOPCODE to the crServerDispatchVertexAttrib4NubARB function, (2) CRVERTEXATTRIB1DARBOPCODE to the crServerDispatchVertexAttrib1dARB function, (3) CRVERTEXATTRIB1FARBOPCODE to the crServerDispatchVertexAttrib1fARB function, (4) CRVERTEXATTRIB1SARBOPCODE to the crServerDispatchVertexAttrib1sARB function, (5) CRVERTEXATTRIB2DARBOPCODE to the crServerDispatchVertexAttrib2dARB function, (6) CRVERTEXATTRIB2FARBOPCODE to the crServerDispatchVertexAttrib2fARB function, (7) CRVERTEXATTRIB2SARBOPCODE to the crServerDispatchVertexAttrib2sARB function, (8) CRVERTEXATTRIB3DARBOPCODE to the crServerDispatchVertexAttrib3dARB function, (9) CRVERTEXATTRIB3FARBOPCODE to the crServerDispatchVertexAttrib3fARB function, (10) CRVERTEXATTRIB3SARBOPCODE to the crServerDispatchVertexAttrib3sARB function, (11) CRVERTEXATTRIB4DARBOPCODE to the crServerDispatchVertexAttrib4dARB function, (12) CRVERTEXATTRIB4FARBOPCODE to the crServerDispatchVertexAttrib4fARB function, and (13) CRVERTEXATTRIB4SARBOPCODE to the crServerDispatchVertexAttrib4sARB function.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203