imPC@ndo EN

Vulnerabilità VMware

956 CVE

CVE-2021-22009
Alta 7.5

The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit these issues to create a denial of service condition due to excessive memory c…

vmware cloud_foundation · vmware vcenter_server
0.01EPSS
CVE-2016-2076
Alta 7.6

Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which allows remote attackers to hijack session…

vmware vcenter_server · vmware vcloud_automation_identity_appliance · vmware vcloud_director
0.01EPSS
CVE-2021-22116
Alta 7.5

RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection endpoint. A malicious user can exploit the vulnerability by sending malicious AMQP messages to the target Rabbit…

debian debian_linux · vmware rabbitmq
0.01EPSS
CVE-2020-3945
Alta 7.5

vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) contains an information disclosure vulnerability due to incorrect pairing implementation between the vRealize Operations for Horizon Adapter and Horizon View. An unauthenti…

vmware vrealize_operations
0.01EPSS
CVE-2021-22012
Alta 7.5

The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.

vmware cloud_foundation · vmware vcenter_server
0.01EPSS
CVE-2019-11272
Alta 7.3

Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a nul…

debian debian_linux · vmware spring_security
0.01EPSS
CVE-2023-20895
Alta 8.1

The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass authentication.

vmware vcenter_server
0.01EPSS
CVE-2006-6410
Media 4.6

Buffer overflow in an ActiveX control in VMWare 5.5.1 allows local users to execute arbitrary code via a long VmdbDb parameter to the Initialize function.

vmware workstation
0.01EPSS
CVE-2021-21982
Critica 9.1

VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud Workload appliance to obtain a valid au…

vmware carbon_black_cloud_workload
0.01EPSS
CVE-2012-1514
Media 6.8

Cross-site request forgery (CSRF) vulnerability in VMware vShield Manager (vSM) 1.0.1 before Update 2 and 4.1.0 before Update 2 allows remote attackers to hijack the authentication of arbitrary users.

vmware vshield_manager
0.01EPSS
CVE-2023-34060
Critica 9.8

VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance was upgraded to 10.5 from an older version. On an upgraded version of VMware Cloud Director Appliance 10.5, a malicious actor with network a…

vmware cloud_director
0.01EPSS
CVE-2017-4939
Alta 7.8

VMware Workstation (12.x before 12.5.8) installer contains a DLL hijacking issue that exists due to some DLL files loaded by the application improperly. This issue may allow an attacker to load a DLL file of the attacker's choosing that could execute arbitrary…

vmware workstation
0.01EPSS
CVE-2015-6933
Media 6.3

The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2, VMware Fusion 7.x before 7.1.2, and VMware ESXi 5.0 through 6.0 allows Windows guest OS users to gain guest OS privileges or cau…

vmware esxi · vmware fusion · vmware player · vmware workstation
0.01EPSS
CVE-2012-6326
Alta 7.8

VMware vCenter Server 4.1 before Update 3 and 5.0 before Update 2, and vCSA 5.0 before Update 2, allows remote attackers to cause a denial of service (disk consumption) via vectors that trigger large log entries.

vmware vcenter_server · vmware vcenter_server_appliance
0.01EPSS
CVE-2017-4922
Media 6.5

VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script using world writable directories as temporary storage for critical information. Successful exploitation of this issue may allow unprivileged …

vmware vcenter_server
0.01EPSS
CVE-2018-6981
Alta 8.8

VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMware ESXi 6.0 without ESXi600-201811401-BG, VMware Workstation 15, VMware Workstation 14.1.3 or below, VMware Fusion 11, VMware Fusion 10.1.3 or below contain unin…

vmware esxi · vmware fusion · vmware workstation
0.01EPSS
CVE-2022-31657
Critica 9.8

VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect an authenticated user to an arbitrary domain.

vmware access_connector · vmware identity_manager · vmware identity_manager_connector · vmware one_access
0.01EPSS
CVE-2020-3955
Critica 9.3

ESXi 6.5 without patch ESXi650-201912104-SG and ESXi 6.7 without patch ESXi670-202004103-SG do not properly neutralize script-related HTML when viewing virtual machines attributes. VMware has evaluated the severity of this issue to be in the Important severity…

vmware esxi
0.01EPSS
CVE-2014-1211
Media 6.8

Cross-site request forgery (CSRF) vulnerability in VMware vCloud Director 5.1.x before 5.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout.

vmware vcloud_director
0.01EPSS
CVE-2020-3998
Media 6.5

VMware Horizon Client for Windows (5.x prior to 5.5.0) contains an information disclosure vulnerability. A malicious attacker with local privileges on the machine where Horizon Client for Windows is installed may be able to retrieve hashed credentials if the c…

vmware horizon_client
0.01EPSS
CVE-2018-1261
Media 4.7

Spring-integration-zip versions prior to 1.0.1 exposes an arbitrary file write vulnerability, which can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z) that holds path traversal filenames. So wh…

vmware spring_integration_zip
0.01EPSS
CVE-2022-22979
Alta 7.5

In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provided lookup functionality to cause a denial-of-service condition due to the caching issue in the Function Catalog component of the framework.

vmware spring_cloud_function
0.01EPSS
CVE-2021-22096
Media 4.3

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.

netapp active_iq_unified_manager · netapp management_services_for_element_software_and_netapp_hci · netapp metrocluster_tiebreaker · netapp snap_creator_framework · e altri 4
0.01EPSS
CVE-2018-11087
Media 5.9

Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerability due to lack of hostname validation. A malicious user that has the ability to intercept traffic would be able to view data in transit.

pivotal_software spring_advanced_message_queuing_protocol · vmware rabbitmq_java_client
0.01EPSS
CVE-2023-20855
Alta 8.8

VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sen…

vmware vrealize_automation · vmware vrealize_orchestrator
0.01EPSS