CVE-2014-0981
Last modified
CVE-2014-0981 is a vulnerability of currently unknown severity. VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium server via crafted Chromium network pointer in a (1) CR_MESSAGE_READBACK or (2) CR_MESSAGE_WRITEBACK message to the VBoxSharedCrOpenGL service, which triggers an arbitrary pointer dereference and memory corruption. NOTE: this issue was MERGED with CVE-2014-0982 because it is the same type of vulnerability affecting the same set of versions. EPSS estimates a 1.38% chance of exploitation in the next 30 days.
Description
VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium server via crafted Chromium network pointer in a (1) CR_MESSAGE_READBACK or (2) CR_MESSAGE_WRITEBACK message to the VBoxSharedCrOpenGL service, which triggers an arbitrary pointer dereference and memory corruption. NOTE: this issue was MERGED with CVE-2014-0982 because it is the same type of vulnerability affecting the same set of versions. All CVE users should reference CVE-2014-0981 instead of CVE-2014-0982.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Vm Virtualbox | 4.2.0 |
| Oracle | Vm Virtualbox | 4.2.2 |
| Oracle | Vm Virtualbox | 4.2.4 |
| Oracle | Vm Virtualbox | 4.2.6 |
| Oracle | Vm Virtualbox | 4.2.8 |
| Oracle | Vm Virtualbox | 4.2.10 |
| Oracle | Vm Virtualbox | 4.2.12 |
| Oracle | Vm Virtualbox | 4.2.14 |
| Oracle | Vm Virtualbox | 4.2.16 |
| Oracle | Vm Virtualbox | 4.2.18 |
| Oracle | Vm Virtualbox | 4.2.20 |
| Oracle | Vm Virtualbox | 4.3.0 |
| Oracle | Vm Virtualbox | 4.3.2 |
| Oracle | Vm Virtualbox | 4.3.4 |
| Oracle | Vm Virtualbox | 4.3.6 |
References
- http://secunia.com/advisories/57384Vendor Advisory
- http://secunia.com/advisories/57384Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-0981?
How severe is CVE-2014-0981?
How do I fix CVE-2014-0981?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-0973The image_verify function in platform/msm_shared/image_verif…
- CVE-2014-0974The boot_linux_from_mmc function in app/aboot/aboot.c in the…
- CVE-2014-0977Cross-site scripting (XSS) vulnerability in the Rich Text Ed…
- CVE-2014-0978Stack-based buffer overflow in the yyerror function in lib/c…
- CVE-2014-0979The start_authentication function in lightdm-gtk-greeter.c i…
- CVE-2014-0980Buffer overflow in Poster Software PUBLISH-iT 3.6d allows re…
- CVE-2014-0982Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2014-0983Multiple array index errors in programs that are automatical…
- CVE-2014-0984The passwordCheck function in SAP Router 721 patch 117, 720 …
- CVE-2014-0985Stack-based buffer overflow in Advantech WebAccess (formerly…
- CVE-2014-0986Stack-based buffer overflow in Advantech WebAccess (formerly…
- CVE-2014-0987Stack-based buffer overflow in Advantech WebAccess (formerly…
Are you affected by CVE-2014-0981?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
