imPC@ndo EN

Vulnerabilità VMware

956 CVE

CVE-2019-16919
Alta 7.5

Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or pull access permissions to a project they don't have access or control for. The …

linuxfoundation harbor · vmware cloud_foundation · vmware harbor_container_registry
0.02EPSS
CVE-2023-20865
Alta 7.2

VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root.

vmware aria_operations_for_logs · vmware cloud_foundation
0.02EPSS
CVE-2019-5528
Media 5.3

VMware ESXi 6.5 suffers from partial denial of service vulnerability in hostd process. Patch ESXi650-201907201-UG for this issue is available.

vmware esxi
0.02EPSS
CVE-2014-0225
Alta 8.8

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

pivotal_software spring_framework · vmware spring_framework
0.02EPSS
CVE-2021-22008
Alta 7.5

The vCenter Server contains an information disclosure vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by sending a specially crafted json-rpc message to gain access to sens…

vmware cloud_foundation · vmware vcenter_server
0.02EPSS
CVE-2021-22049
Critica 9.8

The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by accessing a URL request out…

vmware vcenter_server
0.02EPSS
CVE-2010-3700
Media 5.0

VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter.

acegisecurity acegi-security · ibm websphere_application_server · vmware springsource_spring_security
0.02EPSS
CVE-2017-4921
Alta 8.8

VMware vCenter Server (6.5 prior to 6.5 U1) contains an insecure library loading issue that occurs due to the use of LD_LIBRARY_PATH variable in an unsafe manner. Successful exploitation of this issue may allow unprivileged host users to load a shared library …

vmware vcenter_server
0.02EPSS
CVE-2017-4942
Media 4.9

VMware AirWatch Console (AWC) contains a Broken Access Control vulnerability. Successful exploitation of this issue could result in end-user device details being disclosed to an unauthorized administrator.

vmware airwatch_console
0.02EPSS
CVE-2019-5516
Media 6.8

VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before 10.1.6) updates address an out-of-bounds vulnerability with the vertex shader fu…

vmware esxi · vmware fusion · vmware workstation
0.02EPSS
CVE-2012-3289
Alta 7.8

VMware Workstation 8.x before 8.0.4, VMware Player 4.x before 4.0.4, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 allow remote attackers to cause a denial of service (guest OS crash) via crafted traffic from a remote virtual device.

vmware esx · vmware esxi · vmware player · vmware workstation
0.02EPSS
CVE-2010-1193
Media 4.3

Cross-site scripting (XSS) vulnerability in WebAccess in VMware Server 2.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to JSON error messages.

vmware server
0.02EPSS
CVE-2009-2277
Media 4.3

Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "context data."

vmware esx_server · vmware virtualcenter
0.02EPSS
CVE-2021-22013
Alta 7.5

The vCenter Server contains a file path traversal vulnerability leading to information disclosure in the appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive informatio…

vmware cloud_foundation · vmware vcenter_server
0.02EPSS
CVE-2010-1142
Alta 8.5

VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 203138; VMware Fusion 2.x before 2.0.6 build 246742; VMware ESXi…

vmware ace · vmware esx · vmware esxi · vmware fusion · e altri 3
0.02EPSS
CVE-2022-31673
Alta 8.8

VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can create and leak hex dumps, leading to information disclosure. Successful exploitation can lead to a remote code execution.

vmware vrealize_operations
0.02EPSS
CVE-2021-22010
Alta 7.5

The vCenter Server contains a denial-of-service vulnerability in VPXD service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to create a denial of service condition due to excessive memory consumption by VPXD servic…

vmware cloud_foundation · vmware vcenter_server
0.02EPSS
CVE-2019-5521
Critica 9.6

VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6) and Fusion (11.x before 11.0.3 and 10.x before 10.1.6) contain an out-of-bounds read vulnerability in the pixel shader funct…

vmware esxi · vmware fusion · vmware workstation
0.02EPSS
CVE-2019-5534
Alta 7.7

VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability where Virtual Machines deployed from an OVF could expose login information via the virtual machine's vAppConfig propert…

vmware vcenter_server
0.02EPSS
CVE-2018-6957
Media 5.3

VMware Workstation (14.x before 14.1.1, 12.x) and Fusion (10.x before 10.1.1 and 8.x) contain a denial-of-service vulnerability which can be triggered by opening a large number of VNC sessions. Note: In order for exploitation to be possible on Workstation and …

vmware fusion · vmware workstation_player · vmware workstation_pro
0.02EPSS
CVE-2021-22019
Alta 7.5

The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 5480 on vCenter Server may exploit this issue by sending a specially crafted jsonrpc message to create a denial of servic…

vmware cloud_foundation · vmware vcenter_server
0.02EPSS
CVE-2022-31702
Critica 9.8

vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the vRNI REST API can execute commands without authentication.

vmware vrealize_network_insight
0.02EPSS
CVE-2007-1877
Alta 7.8

VMware Workstation before 5.5.4 allows attackers to cause a denial of service against the guest OS by causing the virtual machine process (VMX) to store malformed configuration information.

vmware workstation
0.02EPSS
CVE-2020-5408
Media 6.5

Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A malicious …

pivotal_software spring_security · vmware spring_security
0.02EPSS
CVE-2018-1256
Alta 8.1

Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers that are not bound to the SSO service. In PCF deployments with multiple SSO service plans, a remote attacker can authenticate to unbound resou…

vmware spring_cloud_sso_connector
0.02EPSS