imPC@ndo EN

Vulnerabilità VMware

956 CVE

CVE-2018-6959
Critica 9.8

VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs. Exploitation of this issue may lead to the hijacking of a valid vRA user's session.

vmware vrealize_automation
0.02EPSS
CVE-2016-7462
Alta 8.5

The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files or rename files via a crafted DiskFileItem in a relay-request payload that is mishandled during deserialization.…

vmware vrealize_operations
0.02EPSS
CVE-2008-1364
Alta 7.8

Unspecified vulnerability in the DHCP service in VMware Workstation 5.5.x before 5.5.6, VMware Player 1.0.x before 1.0.6, VMware ACE 1.0.x before 1.0.5, VMware Server 1.0.x before 1.0.5, and VMware Fusion 1.1.x before 1.1.1 allows attackers to cause a denial o…

vmware ace · vmware player · vmware server · vmware vmware_server · e altri 2
0.02EPSS
CVE-2017-4919
Critica 9.0

VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating Systems without the need to authenticate.

vmware vcenter_server
0.02EPSS
CVE-2023-20869
Alta 8.2

VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.

vmware fusion · vmware workstation
0.02EPSS
CVE-2019-5098
Alta 8.6

An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.29010. A specially crafted pixel shader can cause out-of-bounds memory read. An attacker can provide a specially crafted shader file to trigger this vulnerab…

amd radeon_550_firmware · amd radeon_rx_550_firmware · vmware workstation
0.02EPSS
CVE-2013-5971
Media 6.8

Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web sessions and gain privileges via unspecified vectors.

vmware vcenter_server
0.02EPSS
CVE-2009-1244
Media 6.8

Unspecified vulnerability in the virtual machine display function in VMware Workstation 6.5.1 and earlier; VMware Player 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 1.x before 1.0.9 build 156507 and 2.x before 2.0.1 build 156745; VMware Fusi…

vmware ace · vmware esx · vmware esxi · vmware fusion · e altri 3
0.02EPSS
CVE-2012-1511
Media 4.3

Cross-site scripting (XSS) vulnerability in View Manager Portal in VMware View before 4.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

vmware view
0.02EPSS
CVE-2011-0355
Alta 7.8

Cisco Nexus 1000V Virtual Ethernet Module (VEM) 4.0(4) SV1(1) through SV1(3b), as used in VMware ESX 4.0 and 4.1 and ESXi 4.0 and 4.1, does not properly handle dropped packets, which allows guest OS users to cause a denial of service (ESX or ESXi host OS crash…

cisco 1000v_virtual_ethernet_module_\(vem\) · vmware esx · vmware esxi
0.02EPSS
CVE-2007-1069
Alta 7.8

The memory management in VMware Workstation before 5.5.4 allows attackers to cause a denial of service (Windows virtual machine crash) by triggering certain general protection faults (GPF).

vmware workstation
0.02EPSS
CVE-2021-21984
Critica 9.8

VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point. A malicious actor with network access may exploit this issue causing unauthorised remote code execution on vRealize Business …

vmware vrealize_business_for_cloud
0.02EPSS
CVE-2013-3107
Media 4.3

VMware vCenter Server 5.1 before Update 1, when anonymous LDAP binding for Active Directory is enabled, allows remote attackers to bypass authentication by providing a valid username in conjunction with an empty password.

vmware vcenter_server_appliance
0.02EPSS
CVE-2018-1274
Alta 7.5

Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against…

broadcom spring_data_commons · pivotal_software spring_data_rest · vmware spring_data_rest
0.02EPSS
CVE-2022-22970
Media 5.3

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

netapp active_iq_unified_manager · netapp brocade_san_navigator · netapp cloud_secure_agent · netapp oncommand_insight · e altri 2
0.02EPSS
CVE-2012-5050
Media 4.3

Cross-site scripting (XSS) vulnerability in the server in VMware vCenter Operations (aka vCOps) before 5.0.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

vmware vcenter_operations
0.02EPSS
CVE-2021-22015
Alta 7.8

The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administrative privilege may exploit these issues to elevate their privileges to root on …

vmware cloud_foundation · vmware vcenter_server
0.02EPSS
CVE-2012-5055
Media 5.0

DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate…

vmware springsource_spring_security
0.02EPSS
CVE-2007-1337
Alta 7.8

The virtual machine process (VMX) in VMware Workstation before 5.5.4 does not properly read state information when moving from the ACPI sleep state to the run state, which allows attackers to cause a denial of service (virtual machine reboot) via unknown vecto…

vmware workstation
0.02EPSS
CVE-2012-1512
Media 4.3

Cross-site scripting (XSS) vulnerability in the internal browser in vSphere Client in VMware vSphere 4.1 before Update 2 and 5.0 before Update 1 allows remote attackers to inject arbitrary web script or HTML via a crafted log-file entry.

vmware vsphere
0.02EPSS
CVE-2015-2341
Alta 7.8

VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.6, and VMware Fusion 6.x before 6.0.6 and 7.x before 7.0.1 allow attackers to cause a denial of service against a 32-bit guest OS or 64-bit host OS via a crafted RPC command.

vmware fusion · vmware player · vmware workstation
0.02EPSS
CVE-2012-1472
Media 6.4

VMware vCenter Chargeback Manager (aka CBM) before 2.0.1 does not properly handle XML API requests, which allows remote attackers to read arbitrary files or cause a denial of service via unspecified vectors.

vmware vcenter_chargeback_manager
0.02EPSS
CVE-2016-5331
Media 6.1

CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

vmware esxi · vmware vcenter_server
0.02EPSS
CVE-2015-0201
Media 5.0

The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.

pivotal_software spring_framework · vmware spring_framework
0.02EPSS
CVE-2011-1789
Media 5.0

The self-extracting installer in the vSphere Client Installer package in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, VMware ESXi 4.x before 4.1 Update 1, and VMware ESX 4.x before 4.1 Update 1 does not have a digital signature, which might make…

vmware esx · vmware esxi · vmware vcenter
0.02EPSS