CVE-2008-3431CISA KEVEPSS p93.3%

CVE-2008-3431Oracle VirtualBox Insufficient Input Validation Vulnerability

Oracle / VirtualBox

Description

An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code.

Scoring

EPSS6.93% probability of exploitation · percentile 93.3% · 2026-06-18T12:00:27Z

CISA KEV entry

Added to KEV: 2022-03-03

(incoming)1

TypeTargetConfidenceTier
KEVEntryOracle VirtualBox Insufficient Input Validation Vulnerabilitykev-cve-2008-34310%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-30712
CVE
CVE-2026-21990
CVE
CVE-2025-53028
CVE
CVE-2025-53024
CVE
CVE-2025-62588
CVE
CVE-2025-62641
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.