imPC@ndo EN

Vulnerabilità VMware

956 CVE

CVE-2009-3731
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware St…

vmware esx_server · vmware lab_manager · vmware server · vmware stage_manager · e altri 6
0.03EPSS
CVE-2014-1207
Media 4.3

VMware ESXi 4.0 through 5.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (NULL pointer dereference) by intercepting and modifying Network File Copy (NFC) traffic.

vmware esx · vmware esxi
0.03EPSS
CVE-2009-4811
Media 5.0

VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, V…

vmware ace · vmware player · vmware server · vmware workstation
0.03EPSS
CVE-2008-1392
Alta 10.0

The default configuration of VMware Workstation 6.0.2, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 makes the console of the guest OS accessible through anonymous VIX API calls, which has unknown impact and attack vectors.

vmware ace · vmware player · vmware vmware_workstation
0.03EPSS
CVE-2022-31659
Alta 7.2

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.

vmware access_connector · vmware identity_manager · vmware identity_manager_connector · vmware one_access
0.03EPSS
CVE-2010-2249
Media 6.5

Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.

apple iphone_os · apple itunes · apple safari · apple tvos · e altri 8
0.03EPSS
CVE-2007-1270
Media 5.0

Double free vulnerability in VMware ESX Server 3.0.0 and 3.0.1 allows attackers to cause a denial of service (crash), obtain sensitive information, or possibly execute arbitrary code via unspecified vectors.

vmware esx · vmware esx_server
0.03EPSS
CVE-2022-22942
Alta 7.8

The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to files opened by other processes on the system through a dangling 'file' pointer.

vmware photon_os
0.03EPSS
CVE-2024-22259
Alta 8.1

Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/def…

netapp active_iq_unified_manager · vmware spring_framework
0.03EPSS
CVE-2018-6960
Alta 8.8

VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow an attacker to bypass two-factor authentication. Note: In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS.

vmware horizon_daas
0.03EPSS
CVE-2015-5211
Critica 9.6

Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extensio…

debian debian_linux · vmware spring_framework
0.03EPSS
CVE-2015-3192
Media 5.5

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafte…

fedoraproject fedora · pivotal_software spring_framework · vmware spring_framework
0.03EPSS
CVE-2017-4995
Alta 8.1

An issue was discovered in Pivotal Spring Security 4.2.0.RELEASE through 4.2.2.RELEASE, and Spring Security 5.0.0.M1. When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution. Jacks…

vmware spring_security
0.03EPSS
CVE-2010-4526
Alta 7.1

Race condition in the sctp_icmp_proto_unreachable function in net/sctp/input.c in Linux kernel 2.6.11-rc2 through 2.6.33 allows remote attackers to cause a denial of service (panic) via an ICMP unreachable message to a socket that is already locked by a user, …

linux linux_kernel · redhat enterprise_mrg · vmware esx
0.03EPSS
CVE-2010-4573
Alta 9.3

The Update Installer in VMware ESXi 4.1, when a modified sfcb.cfg is present, does not properly configure the SFCB authentication mode, which allows remote attackers to obtain access via an arbitrary username and password.

vmware esxi
0.03EPSS
CVE-2012-2449
Alta 9.0

VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x through 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 do not properly configure the virtual floppy device, which allows guest OS users to cause a denial…

vmware esx · vmware esxi · vmware fusion · vmware player · e altri 1
0.03EPSS
CVE-2024-22274
Alta 7.2

The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.

vmware cloud_foundation · vmware vcenter_server
0.03EPSS
CVE-2016-5333
Critica 9.8

VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.

vmware photon_os
0.03EPSS
CVE-2008-3281
Media 6.5

libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.

apple iphone_os · apple safari · canonical ubuntu_linux · debian debian_linux · e altri 7
0.03EPSS
CVE-2012-2450
Alta 9.0

VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 do not properly register SCSI devices, which allows guest OS users to cause a denial of service (in…

vmware esx · vmware esxi · vmware fusion · vmware player · e altri 1
0.02EPSS
CVE-2013-3080
Alta 9.0

VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to create or overwrite arbitrary files, and consequently execute arbitrary code or cause a denial of service, by leveraging Virtual Appliance Management Interface (VAM…

vmware vcenter_server_appliance
0.02EPSS
CVE-2012-1517
Alta 9.0

The VMX process in VMware ESXi 4.1 and ESX 4.1 does not properly handle RPC commands, which allows guest OS users to cause a denial of service (memory overwrite and process crash) or possibly execute arbitrary code on the host OS via vectors involving function…

vmware esx · vmware esxi
0.02EPSS
CVE-2021-26987
Critica 9.8

Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to Remote Code Execution. All versions of Element Plug-in for vCe…

netapp element_plug-in_for_vcenter_server · netapp management_services_for_element_software_and_netapp_hci · netapp solidfire_\&_hci_management_node · vmware spring_boot
0.02EPSS
CVE-2010-1137
Media 4.3

Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5, and the Server Console in VMware Server 1.0, allows remote attackers to inject arbitrary web script or HTML via the name of a virtual mach…

vmware esx_server · vmware server · vmware virtualcenter
0.02EPSS
CVE-2018-1258
Alta 8.8

Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.

netapp oncommand_insight · netapp oncommand_unified_manager · netapp oncommand_workflow_automation · netapp snapcenter · e altri 38
0.02EPSS