<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">python-virtualbox-5.1.10-2.5 on GA media</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2024:10020-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2024-06-15T00:00:00Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-06-15T00:00:00Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-06-15T00:00:00Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">python-virtualbox-5.1.10-2.5 on GA media</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">These are all security issues fixed in the python-virtualbox-5.1.10-2.5 package on the GA media of openSUSE Tumbleweed.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-Tumbleweed-2024-10020</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-0224/</URL>
      <Description>SUSE CVE CVE-2014-0224 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6588/</URL>
      <Description>SUSE CVE CVE-2014-6588 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6589/</URL>
      <Description>SUSE CVE CVE-2014-6589 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6590/</URL>
      <Description>SUSE CVE CVE-2014-6590 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6595/</URL>
      <Description>SUSE CVE CVE-2014-6595 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-0377/</URL>
      <Description>SUSE CVE CVE-2015-0377 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-0418/</URL>
      <Description>SUSE CVE CVE-2015-0418 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-0427/</URL>
      <Description>SUSE CVE CVE-2015-0427 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-3456/</URL>
      <Description>SUSE CVE CVE-2015-3456 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-4813/</URL>
      <Description>SUSE CVE CVE-2015-4813 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-4896/</URL>
      <Description>SUSE CVE CVE-2015-4896 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-0678/</URL>
      <Description>SUSE CVE CVE-2016-0678 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-5501/</URL>
      <Description>SUSE CVE CVE-2016-5501 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-5538/</URL>
      <Description>SUSE CVE CVE-2016-5538 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-5605/</URL>
      <Description>SUSE CVE CVE-2016-5605 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-5608/</URL>
      <Description>SUSE CVE CVE-2016-5608 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-5610/</URL>
      <Description>SUSE CVE CVE-2016-5610 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-5611/</URL>
      <Description>SUSE CVE CVE-2016-5611 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-561313/</URL>
      <Description>SUSE CVE CVE-2016-561313 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Tumbleweed">
      <Branch Type="Product Name" Name="openSUSE Tumbleweed">
        <FullProductName ProductID="openSUSE Tumbleweed" CPE="cpe:/o:opensuse:tumbleweed">openSUSE Tumbleweed</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="python-virtualbox-5.1.10-2.5">
      <FullProductName ProductID="python-virtualbox-5.1.10-2.5">python-virtualbox-5.1.10-2.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-5.1.10-2.5">
      <FullProductName ProductID="virtualbox-5.1.10-2.5">virtualbox-5.1.10-2.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-devel-5.1.10-2.5">
      <FullProductName ProductID="virtualbox-devel-5.1.10-2.5">virtualbox-devel-5.1.10-2.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-guest-desktop-icons-5.1.10-2.5">
      <FullProductName ProductID="virtualbox-guest-desktop-icons-5.1.10-2.5">virtualbox-guest-desktop-icons-5.1.10-2.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5">
      <FullProductName ProductID="virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5">virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5">
      <FullProductName ProductID="virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5">virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-guest-tools-5.1.10-2.5">
      <FullProductName ProductID="virtualbox-guest-tools-5.1.10-2.5">virtualbox-guest-tools-5.1.10-2.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-guest-x11-5.1.10-2.5">
      <FullProductName ProductID="virtualbox-guest-x11-5.1.10-2.5">virtualbox-guest-x11-5.1.10-2.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5">
      <FullProductName ProductID="virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5">virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5">
      <FullProductName ProductID="virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5">virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-host-source-5.1.10-2.5">
      <FullProductName ProductID="virtualbox-host-source-5.1.10-2.5">virtualbox-host-source-5.1.10-2.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-qt-5.1.10-2.5">
      <FullProductName ProductID="virtualbox-qt-5.1.10-2.5">virtualbox-qt-5.1.10-2.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-websrv-5.1.10-2.5">
      <FullProductName ProductID="virtualbox-websrv-5.1.10-2.5">virtualbox-websrv-5.1.10-2.5</FullProductName>
    </Branch>
    <Relationship ProductReference="python-virtualbox-5.1.10-2.5" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:python-virtualbox-5.1.10-2.5">python-virtualbox-5.1.10-2.5 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-5.1.10-2.5" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:virtualbox-5.1.10-2.5">virtualbox-5.1.10-2.5 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-devel-5.1.10-2.5" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:virtualbox-devel-5.1.10-2.5">virtualbox-devel-5.1.10-2.5 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-guest-desktop-icons-5.1.10-2.5" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:virtualbox-guest-desktop-icons-5.1.10-2.5">virtualbox-guest-desktop-icons-5.1.10-2.5 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5">virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5">virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-guest-tools-5.1.10-2.5" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:virtualbox-guest-tools-5.1.10-2.5">virtualbox-guest-tools-5.1.10-2.5 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-guest-x11-5.1.10-2.5" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:virtualbox-guest-x11-5.1.10-2.5">virtualbox-guest-x11-5.1.10-2.5 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5">virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5">virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-host-source-5.1.10-2.5" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:virtualbox-host-source-5.1.10-2.5">virtualbox-host-source-5.1.10-2.5 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-qt-5.1.10-2.5" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:virtualbox-qt-5.1.10-2.5">virtualbox-qt-5.1.10-2.5 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-websrv-5.1.10-2.5" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:virtualbox-websrv-5.1.10-2.5">virtualbox-websrv-5.1.10-2.5 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.</Note>
    </Notes>
    <CVE>CVE-2014-0224</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:python-virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-devel-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-desktop-icons-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-tools-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-x11-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-source-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-qt-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-websrv-5.1.10-2.5</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-0224.html</URL>
        <Description>CVE-2014-0224</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1146657</URL>
        <Description>SUSE Bug 1146657</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/880891</URL>
        <Description>SUSE Bug 880891</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/881743</URL>
        <Description>SUSE Bug 881743</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/883126</URL>
        <Description>SUSE Bug 883126</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/885777</URL>
        <Description>SUSE Bug 885777</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/892403</URL>
        <Description>SUSE Bug 892403</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/903703</URL>
        <Description>SUSE Bug 903703</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/905018</URL>
        <Description>SUSE Bug 905018</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/905106</URL>
        <Description>SUSE Bug 905106</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/914447</URL>
        <Description>SUSE Bug 914447</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915913</URL>
        <Description>SUSE Bug 915913</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/916239</URL>
        <Description>SUSE Bug 916239</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.3.20 allows local users to affect integrity and availability via vectors related to VMSVGA virtual graphics device, a different vulnerability than CVE-2014-6589, CVE-2014-6590, CVE-2014-6595, and CVE-2015-0427.</Note>
    </Notes>
    <CVE>CVE-2014-6588</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:python-virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-devel-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-desktop-icons-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-tools-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-x11-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-source-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-qt-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-websrv-5.1.10-2.5</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>3.2</BaseScore>
        <Vector>AV:L/AC:L/Au:S/C:N/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6588.html</URL>
        <Description>CVE-2014-6588</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/914447</URL>
        <Description>SUSE Bug 914447</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.3.20 allows local users to affect integrity and availability via vectors related to VMSVGA virtual graphics device, a different vulnerability than CVE-2014-6588, CVE-2014-6590, CVE-2014-6595, and CVE-2015-0427.</Note>
    </Notes>
    <CVE>CVE-2014-6589</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:python-virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-devel-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-desktop-icons-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-tools-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-x11-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-source-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-qt-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-websrv-5.1.10-2.5</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>3.2</BaseScore>
        <Vector>AV:L/AC:L/Au:S/C:N/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6589.html</URL>
        <Description>CVE-2014-6589</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/914447</URL>
        <Description>SUSE Bug 914447</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.3.20 allows local users to affect integrity and availability via vectors related to VMSVGA virtual graphics device, a different vulnerability than CVE-2014-6588, CVE-2014-6589, CVE-2014-6595, and CVE-2015-0427.</Note>
    </Notes>
    <CVE>CVE-2014-6590</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:python-virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-devel-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-desktop-icons-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-tools-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-x11-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-source-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-qt-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-websrv-5.1.10-2.5</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>3.2</BaseScore>
        <Vector>AV:L/AC:L/Au:S/C:N/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6590.html</URL>
        <Description>CVE-2014-6590</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/914447</URL>
        <Description>SUSE Bug 914447</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.3.20 allows local users to affect integrity and availability via vectors related to VMSVGA virtual graphics device, a different vulnerability than CVE-2014-6588, CVE-2014-6589, CVE-2014-6590, and CVE-2015-0427.</Note>
    </Notes>
    <CVE>CVE-2014-6595</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:python-virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-devel-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-desktop-icons-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-tools-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-x11-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-source-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-qt-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-websrv-5.1.10-2.5</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>3.2</BaseScore>
        <Vector>AV:L/AC:L/Au:S/C:N/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6595.html</URL>
        <Description>CVE-2014-6595</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/914447</URL>
        <Description>SUSE Bug 914447</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.26, 4.0.28, 4.1.36, and 4.2.28 allows local users to affect availability via unknown vectors related to Core, a different vulnerability than CVE-2015-0418.</Note>
    </Notes>
    <CVE>CVE-2015-0377</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:python-virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-devel-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-desktop-icons-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-tools-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-x11-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-source-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-qt-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-websrv-5.1.10-2.5</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.4</BaseScore>
        <Vector>AV:L/AC:M/Au:S/C:N/I:N/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-0377.html</URL>
        <Description>CVE-2015-0377</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/914447</URL>
        <Description>SUSE Bug 914447</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.26, 4.0.28, 4.1.36, and 4.2.28 allows local users to affect availability via unknown vectors related to Core, a different vulnerability than CVE-2015-0377.</Note>
    </Notes>
    <CVE>CVE-2015-0418</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:python-virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-devel-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-desktop-icons-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-tools-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-x11-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-source-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-qt-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-websrv-5.1.10-2.5</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-0418.html</URL>
        <Description>CVE-2015-0418</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/914447</URL>
        <Description>SUSE Bug 914447</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 4.3.20 allows local users to affect integrity and availability via vectors related to VMSVGA virtual graphics device, a different vulnerability than CVE-2014-6588, CVE-2014-6589, CVE-2014-6590, and CVE-2014-6595.</Note>
    </Notes>
    <CVE>CVE-2015-0427</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:python-virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-devel-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-desktop-icons-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-tools-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-x11-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-source-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-qt-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-websrv-5.1.10-2.5</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>3.2</BaseScore>
        <Vector>AV:L/AC:L/Au:S/C:N/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-0427.html</URL>
        <Description>CVE-2015-0427</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/914447</URL>
        <Description>SUSE Bug 914447</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.</Note>
    </Notes>
    <CVE>CVE-2015-3456</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:python-virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-devel-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-desktop-icons-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-tools-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-x11-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-source-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-qt-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-websrv-5.1.10-2.5</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.7</BaseScore>
        <Vector>AV:A/AC:L/Au:S/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-3456.html</URL>
        <Description>CVE-2015-3456</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/929339</URL>
        <Description>SUSE Bug 929339</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/932770</URL>
        <Description>SUSE Bug 932770</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/935900</URL>
        <Description>SUSE Bug 935900</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 4.0.34, 4.1.42, 4.2.34, 4.3.32, and 5.0.8, when using a Windows guest, allows local users to affect availability via unknown vectors related to Core.</Note>
    </Notes>
    <CVE>CVE-2015-4813</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:python-virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-devel-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-desktop-icons-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-tools-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-x11-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-source-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-qt-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-websrv-5.1.10-2.5</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-4813.html</URL>
        <Description>CVE-2015-4813</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/951432</URL>
        <Description>SUSE Bug 951432</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.0.34, 4.1.42, 4.2.34, 4.3.32, and 5.0.8, when a VM has the Remote Display feature (RDP) enabled, allows remote attackers to affect availability via unknown vectors related to Core.</Note>
    </Notes>
    <CVE>CVE-2015-4896</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:python-virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-devel-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-desktop-icons-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-tools-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-x11-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-source-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-qt-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-websrv-5.1.10-2.5</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-4896.html</URL>
        <Description>CVE-2015-4896</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/951432</URL>
        <Description>SUSE Bug 951432</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 5.0.18 allows local users to affect confidentiality, integrity, and availability via vectors related to Core.</Note>
    </Notes>
    <CVE>CVE-2016-0678</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:python-virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-devel-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-desktop-icons-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-tools-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-x11-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-source-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-qt-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-websrv-5.1.10-2.5</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.1</BaseScore>
        <Vector>AV:L/AC:M/Au:S/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-0678.html</URL>
        <Description>CVE-2016-0678</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/976636</URL>
        <Description>SUSE Bug 976636</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="13">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect confidentiality, integrity, and availability via vectors related to Core, a different vulnerability than CVE-2016-5538.</Note>
    </Notes>
    <CVE>CVE-2016-5501</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:python-virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-devel-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-desktop-icons-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-tools-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-x11-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-source-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-qt-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-websrv-5.1.10-2.5</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.2</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5501.html</URL>
        <Description>CVE-2016-5501</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1005621</URL>
        <Description>SUSE Bug 1005621</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="14">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect confidentiality, integrity, and availability via vectors related to Core, a different vulnerability than CVE-2016-5501.</Note>
    </Notes>
    <CVE>CVE-2016-5538</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:python-virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-devel-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-desktop-icons-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-tools-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-x11-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-source-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-qt-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-websrv-5.1.10-2.5</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.2</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5538.html</URL>
        <Description>CVE-2016-5538</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1005621</URL>
        <Description>SUSE Bug 1005621</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="15">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component before 5.1.4 in Oracle Virtualization allows remote attackers to affect confidentiality and integrity via vectors related to VRDE.</Note>
    </Notes>
    <CVE>CVE-2016-5605</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:python-virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-devel-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-desktop-icons-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-tools-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-x11-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-source-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-qt-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-websrv-5.1.10-2.5</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.4</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5605.html</URL>
        <Description>CVE-2016-5605</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1005621</URL>
        <Description>SUSE Bug 1005621</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="16">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect availability via vectors related to Core, a different vulnerability than CVE-2016-5613.</Note>
    </Notes>
    <CVE>CVE-2016-5608</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:python-virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-devel-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-desktop-icons-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-tools-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-x11-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-source-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-qt-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-websrv-5.1.10-2.5</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5608.html</URL>
        <Description>CVE-2016-5608</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1005621</URL>
        <Description>SUSE Bug 1005621</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="17">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect confidentiality, integrity, and availability via vectors related to Core.</Note>
    </Notes>
    <CVE>CVE-2016-5610</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:python-virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-devel-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-desktop-icons-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-tools-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-x11-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-source-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-qt-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-websrv-5.1.10-2.5</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.6</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5610.html</URL>
        <Description>CVE-2016-5610</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1005621</URL>
        <Description>SUSE Bug 1005621</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="18">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect confidentiality via vectors related to Core.</Note>
    </Notes>
    <CVE>CVE-2016-5611</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:python-virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-devel-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-desktop-icons-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-tools-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-x11-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-source-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-qt-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-websrv-5.1.10-2.5</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5611.html</URL>
        <Description>CVE-2016-5611</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1005621</URL>
        <Description>SUSE Bug 1005621</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="19">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">unknown</Note>
    </Notes>
    <CVE>CVE-2016-561313</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:python-virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-devel-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-desktop-icons-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-tools-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-guest-x11-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-default-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-kmp-pae-5.1.10_k4.8.13_1-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-host-source-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-qt-5.1.10-2.5</ProductID>
        <ProductID>openSUSE Tumbleweed:virtualbox-websrv-5.1.10-2.5</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-561313.html</URL>
        <Description>CVE-2016-561313</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1005621</URL>
        <Description>SUSE Bug 1005621</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
