imPC@ndo IT

VMware vulnerabilities

956 CVE

CVE-2010-1141
High 8.5

VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 203138; VMware Fusion 2.x before 2.0.6 build 246742; VMware ESXi…

vmware ace · vmware esx · vmware esxi · vmware fusion · and 3 more
0.04EPSS
CVE-2014-1209
High 9.3

VMware vSphere Client 4.0, 4.1, 5.0 before Update 3, and 5.1 before Update 2 does not properly validate updates to Client files, which allows remote attackers to trigger the downloading and execution of an arbitrary program via unspecified vectors.

vmware vsphere_client
0.04EPSS
CVE-2017-4907
Critical 9.8

VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.2.4) contain a heap buffer-overflow vulnerability which may allow a remote attacker to execute code on the security gateway.

vmware horizon_view · vmware unified_access_gateway
0.04EPSS
CVE-2013-3658
High 9.4

Directory traversal vulnerability in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to delete arbitrary host OS files via unspecified vectors.

vmware esx · vmware esxi
0.04EPSS
CVE-2005-4583
Medium 4.3

Unspecified vulnerability in the Management Interface in VMware ESX Server 2.x up to 2.5.x before 24 December 2005 allows "remote code execution in the Web browser" via unspecified attack vectors, probably related to cross-site scripting (XSS).

vmware esx
0.04EPSS
CVE-2017-4933
High 8.8

VMware ESXi (6.5 before ESXi650-201710401-BG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could allow an authenticated VNC session to cause a heap overflow via a specific set of VNC packets resulting in heap co…

vmware esxi · vmware fusion · vmware workstation_pro
0.04EPSS
CVE-2008-3696
High 10.0

Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware A…

vmware ace · vmware player · vmware server · vmware workstation
0.04EPSS
CVE-2014-8373
High 9.0

The VMware Remote Console (VMRC) function in VMware vCloud Automation Center (vCAC) 6.0.1 through 6.1.1 allows remote authenticated users to gain privileges via vectors involving the "Connect (by) Using VMRC" function.

vmware vcloud_automation_center
0.04EPSS
CVE-2008-3692
High 10.0

Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware A…

vmware ace · vmware player · vmware server · vmware workstation
0.04EPSS
CVE-2008-3693
High 10.0

Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware A…

vmware ace · vmware player · vmware server · vmware workstation
0.04EPSS
CVE-2008-3694
High 10.0

Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware A…

vmware ace · vmware player · vmware server · vmware workstation
0.04EPSS
CVE-2008-3695
High 10.0

Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware A…

vmware ace · vmware player · vmware server · vmware workstation
0.04EPSS
CVE-2024-22252
Critical 9.3

VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process runn…

vmware esxi · vmware fusion · vmware workstation
0.04EPSS
CVE-2010-3081
High 7.8

The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory required for the 32-bit compatibility layer, which allows local users to gain privi…

linux linux_kernel · suse suse_linux_enterprise_desktop · suse suse_linux_enterprise_server · vmware esx
0.04EPSS
CVE-2023-20860
High 7.5

Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security…

vmware spring_framework
0.04EPSS
CVE-2012-2448
High 7.5

VMware ESXi 3.5 through 5.0 and ESX 3.5 through 4.1 allow remote attackers to execute arbitrary code or cause a denial of service (memory overwrite) via NFS traffic.

vmware esx · vmware esxi
0.04EPSS
CVE-2019-5514
High 8.8

VMware VMware Fusion (11.x before 11.0.3) contains a security vulnerability due to certain unauthenticated APIs accessible through a web socket. An attacker may exploit this issue by tricking the host user to execute a JavaScript to perform unauthorized functi…

vmware fusion
0.03EPSS
CVE-2014-4258
Medium 6.5

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SRINFOSC.

debian debian_linux · mariadb mariadb · opensuse_project suse_linux_enterprise_desktop · opensuse_project suse_linux_enterprise_server · and 8 more
0.03EPSS
CVE-2010-1143
Medium 4.3

Cross-site scripting (XSS) vulnerability in VMware View (formerly Virtual Desktop Manager or VDM) 3.1.x before 3.1.3 build 252693 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

vmware view_manager
0.03EPSS
CVE-2022-31692
Critical 9.8

Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an application is vulnerable when all of the following are true: The application expec…

netapp active_iq_unified_manager · vmware spring_security
0.03EPSS
CVE-2011-1785
High 7.8

VMware ESXi 4.0 and 4.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (socket exhaustion) via unspecified network traffic.

vmware esx · vmware esxi
0.03EPSS
CVE-2015-1047
Medium 5.0

vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartbeat message.

vmware vcenter_server
0.03EPSS
CVE-2019-5523
Critical 9.8

VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerability in the Tenant and Provider Portals. Successful exploitation of this issue may allow a malicious actor to access the Tenant or Provider Por…

vmware vcloud_director
0.03EPSS
CVE-2018-11040
High 7.5

Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and Map…

debian debian_linux · oracle agile_product_lifecycle_management · oracle application_testing_suite · oracle communications_network_integrity · and 24 more
0.03EPSS
CVE-2018-1257
Medium 6.5

Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious …

oracle agile_product_lifecycle_management · oracle application_testing_suite · oracle big_data_discovery · oracle communications_converged_application_server · and 26 more
0.03EPSS