imPC@ndo EN

Vulnerabilità VMware

956 CVE

CVE-2022-31691
Critica 9.8

Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39.0 and below all use Snakeyaml library for YAML editing supp…

vmware bosh_editor · vmware cloudfoundry_manifest_yml_support · vmware concourse_ci_pipeline_editor · vmware spring_boot_tools · e altri 1
0.02EPSS
CVE-2020-5397
Media 5.3

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable be…

oracle application_testing_suite · oracle communications_brm_-_elastic_charging_engine · oracle communications_diameter_signaling_router · oracle communications_element_manager · e altri 23
0.02EPSS
CVE-2012-5703
Media 5.0

The vSphere API in VMware ESXi 4.1 and ESX 4.1 allows remote attackers to cause a denial of service (host daemon crash) via an invalid value in a (1) RetrieveProp or (2) RetrievePropEx SOAP request.

vmware esx · vmware esxi
0.02EPSS
CVE-2022-22973
Alta 7.8

VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.

vmware cloud_foundation · vmware identity_manager · vmware vrealize_suite_lifecycle_manager · vmware workspace_one_access
0.02EPSS
CVE-2014-3790
Alta 9.0

Ruby vSphere Console (RVC) in VMware vCenter Server Appliance allows remote authenticated users to execute arbitrary commands as root by escaping from a chroot jail.

vmware vcenter_server_appliance
0.02EPSS
CVE-2020-3943
Critica 9.8

vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is not securely configured. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running,…

vmware vrealize_operations
0.02EPSS
CVE-2022-22976
Media 5.3

Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to…

netapp active_iq_unified_manager · oracle financial_services_crime_and_compliance_management_studio · vmware spring_security
0.02EPSS
CVE-2021-22050
Alta 7.5

ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to create a denial-of-service condition by overwhelming rhttpproxy service with multiple requests.

vmware cloud_foundation · vmware esxi
0.02EPSS
CVE-2017-4927
Alta 7.5

VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP network packets which may allow for remote denial of service.

vmware vcenter_server
0.02EPSS
CVE-2024-22255
Alta 7.1

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.   …

vmware cloud_foundation · vmware esxi · vmware fusion · vmware workstation
0.02EPSS
CVE-2010-1138
Media 5.0

The virtual networking stack in VMware Workstation 7.0 before 7.0.1 build 227600, VMware Workstation 6.5.x before 6.5.4 build 246459 on Windows, VMware Player 3.0 before 3.0.1 build 227600, VMware Player 2.5.x before 2.5.4 build 246459 on Windows, VMware ACE 2…

vmware ace · vmware fusion · vmware player · vmware server · e altri 1
0.02EPSS
CVE-2022-31665
Alta 7.2

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.

vmware identity_manager · vmware identity_manager_connector · vmware one_access
0.02EPSS
CVE-2018-6967
Alta 8.1

VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or m…

vmware esxi · vmware fusion · vmware workstation
0.02EPSS
CVE-2018-6966
Alta 8.1

VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or m…

vmware esxi · vmware fusion · vmware workstation
0.02EPSS
CVE-2023-34040
Media 5.3

In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deser…

vmware spring_for_apache_kafka
0.02EPSS
CVE-2010-0686
Alta 7.5

WebAccess in VMware VirtualCenter 2.0.2 and 2.5, VMware Server 2.0, and VMware ESX 3.0.3 and 3.5 allows remote attackers to leverage proxy-server functionality to spoof the origin of requests via unspecified vectors, related to a "URL forwarding vulnerability.…

vmware esx_server · vmware server · vmware virtualcenter
0.02EPSS
CVE-2007-5617
Alta 10.0

Unspecified vulnerability in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1, prevents it from launching, which has unspecified impact, related to untrusted virtual machine images.

vmware player · vmware workstation
0.02EPSS
CVE-2011-0426
Media 4.3

Directory traversal vulnerability in vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, and VMware VirtualCenter 2.5 before Update 6a, allows remote attackers to read arbitrary files via unspecified vectors.

vmware vcenter · vmware virtualcenter
0.02EPSS
CVE-2016-7460
Critica 9.1

The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML document containing an external entity declar…

vmware vrealize_automation
0.02EPSS
CVE-2022-31658
Alta 7.2

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.

vmware access_connector · vmware identity_manager · vmware identity_manager_connector · vmware one_access
0.02EPSS
CVE-2016-5334
Media 5.3

VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF files via unspecified vectors.

vmware identity_manager · vmware vrealize_automation
0.02EPSS
CVE-2020-3976
Media 5.3

VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective authentication services. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3.

vmware cloud_foundation · vmware esxi · vmware vcenter_server
0.02EPSS
CVE-2019-5536
Media 6.5

VMware ESXi (6.7 before ESXi670-201908101-SG and 6.5 before ESXi650-201910401-SG), Workstation (15.x before 15.5.0) and Fusion (11.x before 11.5.0) contain a denial-of-service vulnerability in the shader functionality. Successful exploitation of this issue may…

vmware esxi · vmware fusion · vmware workstation
0.02EPSS
CVE-2010-2667
Media 6.0

Multiple unspecified vulnerabilities in the Virtual Appliance Management Infrastructure (VAMI) in VMware Studio 2.0 allow remote authenticated users to execute arbitrary commands via vectors involving (1) the Studio virtual appliance or (2) a virtual appliance…

vmware studio
0.02EPSS
CVE-2021-21976
Alta 7.2

vSphere Replication 8.3.x prior to 8.3.1.2, 8.2.x prior to 8.2.1.1, 8.1.x prior to 8.1.2.3 and 6.5.x prior to 6.5.1.5 contain a post-authentication command injection vulnerability which may allow an authenticated admin user to perform a remote code execution.

vmware vsphere_replication
0.02EPSS