CVE-2013-3792 describes an unspecified vulnerability in Oracle VM VirtualBox versions prior to 3.2.18, 4.0.20, 4.1.28, and 4.2.18, allowing local authenticated users to cause a denial of service. The vulnerability has a CVSS score of 3.8, indicating low severity, with high attack complexity and requiring local authentication. While not actively exploited in the wild and not listed in CISA's KEV catalog, an ExploitDB entry exists for a local denial of service via 'tracepath'. Despite its age, the CVE has garnered significant community discussion, with 10 mentions, suggesting continued interest or analysis.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.2.16CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
4.2.0CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:4.2.0:*:*:*:*:*:*:* | ||
4.2.2CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:4.2.2:*:*:*:*:*:*:* | ||
4.2.4CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:4.2.4:*:*:*:*:*:*:* | ||
4.2.6CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:4.2.6:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:H/Au:S/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.