CVE-2015-4896: Debian Linux

Medium severity, CVSS 5.0. EPSS: 3.7% chance of exploitation in the next 30 days.

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.0.34, 4.1.42, 4.2.34, 4.3.32, and 5.0.8, when a VM has the Remote Display feature (RDP) enabled, allows remote attackers to affect availability via unknown vectors related to Core.

Affected products

  • Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
  • Oracle Vm VirtualBox: from 4.0.0, before 4.0.34 (fixed in 4.0.34); from 4.1.0, before 4.1.42 (fixed in 4.1.42); from 4.2.0, before 4.2.34 (fixed in 4.2.34); from 4.3.0, before 4.3.32 (fixed in 4.3.32); from 5.0.0, before 5.0.8 (fixed in 5.0.8)

Published 2015-10-21. Last modified 2026-06-17.