imPC@ndo EN

Vulnerabilità VMware

956 CVE

CVE-2014-3796
Media 5.0

VMware NSX 6.0 before 6.0.6, and vCloud Networking and Security (vCNS) 5.1 before 5.1.4.2 and 5.5 before 5.5.3, does not properly validate input, which allows attackers to obtain sensitive information via unspecified vectors.

vmware nsx · vmware vcloud_networking_and_security
0.02EPSS
CVE-2011-0527
Media 5.0

VMware vFabric tc Server (aka SpringSource tc Server) 2.0.x before 2.0.6.RELEASE and 2.1.x before 2.1.2.RELEASE accepts obfuscated passwords during JMX authentication, which makes it easier for context-dependent attackers to obtain access by leveraging an abil…

vmware tc_server
0.02EPSS
CVE-2021-22056
Alta 7.5

VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response.

vmware identity_manager · vmware vrealize_automation · vmware workspace_one_access
0.02EPSS
CVE-2023-22602
Alta 7.5

When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP request may cause an authentication bypass. The authentication bypass occurs when Shiro and Spring Boot are using different pattern-matching techniques. Both Shiro …

apache shiro · vmware spring_boot
0.02EPSS
CVE-2022-31705
Alta 8.2

VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's …

vmware esxi · vmware fusion · vmware workstation
0.02EPSS
CVE-2020-4002
Alta 7.2

The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 handles system parameters in an insecure way. An authenticated SD-WAN Orchestrator user with high privileges may be able to execute arbitrary code on the underlying…

vmware sd-wan_orchestrator
0.02EPSS
CVE-2013-5970
Alta 7.1

hostd-vmdb in VMware ESXi 4.0 through 5.0 and ESX 4.0 through 4.1 allows remote attackers to cause a denial of service (hostd-vmdb service outage) by modifying management traffic.

vmware esx · vmware esxi
0.02EPSS
CVE-2023-34050
Media 5.0

In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class names were added to Spring AMQP, allowing users to lock down deserialization of data in messages from untrusted sources; however by default, w…

vmware spring_advanced_message_queuing_protocol
0.02EPSS
CVE-2021-22014
Alta 7.2

The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure). An authenticated VAMI user with network access to port 5480 on vCenter Server may exploit this issue to execute code on the underly…

vmware cloud_foundation · vmware vcenter_server
0.02EPSS
CVE-2016-7084
Alta 7.8

tpview.dll in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enabled, allows guest OS users to execute arbitrary code on the host OS or cause a denial of service…

vmware workstation_player · vmware workstation_pro
0.02EPSS
CVE-2022-22952
Critica 9.1

VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload vulnerability. A malicious actor with administrative access to the VMware App Control administration interface m…

vmware carbon_black_app_control
0.02EPSS
CVE-2016-7083
Alta 7.8

VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enabled, allow guest OS users to execute arbitrary code on the host OS or cause a denial of service (host OS memor…

vmware workstation_player · vmware workstation_pro
0.01EPSS
CVE-2020-3944
Alta 8.6

vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) has an improper trust store configuration leading to authentication bypass. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horiz…

vmware vrealize_operations
0.01EPSS
CVE-2022-31710
Alta 7.5

vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrusted data which could result in a denial of service.

vmware vrealize_log_insight
0.01EPSS
CVE-2021-21999
Alta 7.8

VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.10 and 4 prior to 2103) contain a local privilege escalation vulnerability. An attacker with normal access to a …

vmware app_volumes · vmware remote_console · vmware tools
0.01EPSS
CVE-2012-6324
Media 4.0

Directory traversal vulnerability in VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 and 5.1 before Patch 1 allows remote authenticated users to read arbitrary files via unspecified vectors.

vmware vcenter_server_appliance
0.01EPSS
CVE-2018-6980
Alta 7.2

VMware vRealize Log Insight (4.7.x before 4.7.1 and 4.6.x before 4.6.2) contains a vulnerability due to improper authorization in the user registration method. Successful exploitation of this issue may allow Admin users with view only permission to perform cer…

vmware vrealize_log_insight
0.01EPSS
CVE-2021-32718
Bassa 3.1

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via management UI could lead to the user's bane being rendered in a confirmation message without proper `<script>` tag sanitization, potentially a…

vmware rabbitmq
0.01EPSS
CVE-2018-1263
Media 4.7

Addresses partial fix in CVE-2018-1261. Pivotal spring-integration-zip, versions prior to 1.0.2, exposes an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpi…

vmware spring_integration_zip
0.01EPSS
CVE-2005-3619
Media 6.8

Cross-site scripting (XSS) vulnerability in the management interface for VMware ESX 2.5.x before 2.5.2 upgrade patch 2, 2.1.x before 2.1.2 upgrade patch 6, and 2.0.x before 2.0.1 upgrade patch 6 allows remote attackers to inject arbitrary web script or HTML vi…

vmware esx
0.01EPSS
CVE-2021-32719
Bassa 3.1

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper <script>…

vmware rabbitmq
0.01EPSS
CVE-2016-9879
Alta 7.5

An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. Spring Security does not consider URL path parameters when processing security constraints. By adding a URL path parameter with an encoded "/" to a re…

ibm websphere_application_server · vmware spring_security
0.01EPSS
CVE-2019-5541
Critica 9.1

VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in the e1000e virtual network adapter. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow…

vmware fusion · vmware workstation
0.01EPSS
CVE-2016-0898
Critica 10.0

MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were not exposed outside the Service Backup VM.

vmware pivotal_software_mysql
0.01EPSS
CVE-2020-3985
Alta 8.8

The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 allows an access to set arbitrary authorization levels leading to a privilege escalation issue. An authenticated SD-WAN Orchestrator user may exploit an application weakness and call a vu…

vmware sd-wan_orchestrator
0.01EPSS