imPC@ndo EN

Vulnerabilità VMware

956 CVE

CVE-2022-22943
Media 6.7

VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malicious actor with local administrative privileges in the Windows guest OS, where VMware Tools is installed, may be able to execute code with s…

vmware tools
0.01EPSS
CVE-2017-4931
Alta 7.8

VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add malicious data to an enrolled device's log files. Successful exploitation of this issue could result in an unsuspecting AWC user opening a CSV…

vmware airwatch
0.01EPSS
CVE-2023-20893
Alta 8.1

The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hos…

vmware vcenter_server
0.01EPSS
CVE-2011-2731
Media 5.1

Race condition in the RunAsManager mechanism in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 stores the Authentication object in the shared security context, which allows attackers to gain privileges via a crafted thread.

vmware springsource_spring_security
0.01EPSS
CVE-2009-0908
Media 6.4

Unspecified vulnerability in the ACE shared folders implementation in the VMware Host Guest File System (HGFS) shared folders feature in VMware ACE 2.5.1 and earlier allows attackers to enable a disabled shared folder.

vmware ace
0.01EPSS
CVE-2017-4928
Alta 7.5

The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRLF injection issues due to improper neutralization of URLs. An attacker may exploit these issues by sending a PO…

vmware vcenter_server
0.01EPSS
CVE-2018-1196
Media 5.9

Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d linux service. The script included with Spring Boot 1.5.9 and earlier and 2.0.0.M1 through 2.0.0.M7 is susceptible to a symlink attack which al…

vmware spring_boot
0.01EPSS
CVE-2019-5513
Media 5.3

VMware Horizon Connection Server (7.x before 7.8, 7.5.x before 7.5.2, 6.x before 6.2.8) contains an information disclosure vulnerability. Successful exploitation of this issue may allow disclosure of internal domain names, the Connection Server’s internal name…

vmware horizon
0.01EPSS
CVE-2019-5512
Alta 8.8

VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle COM classes appropriately. Successful exploitation of this issue may allow hijacking of COM classes used by the VMX process, on a Windows host, leading to elevation …

vmware workstation
0.01EPSS
CVE-2016-7458
Media 5.8

VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External En…

vmware vsphere_client
0.01EPSS
CVE-2023-34055
Media 5.3

In Spring Boot versions 2.7.0 - 2.7.17, 3.0.0-3.0.12 and 3.1.0-3.1.5, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following…

vmware spring_boot
0.01EPSS
CVE-2014-0097
Alta 7.3

The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.

vmware spring_security
0.01EPSS
CVE-2021-22002
Critica 9.8

VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443 could tamper with host headers to facilit…

vmware cloud_foundation · vmware identity_manager · vmware vrealize_suite_lifecycle_manager · vmware workspace_one_access
0.01EPSS
CVE-2018-6976
Media 5.3

The VMware Content Locker for iOS prior to 4.14 contains a data protection vulnerability in the SQLite database. This vulnerability relates to unencrypted filenames and associated metadata in SQLite database for the Content Locker.

vmware workspace_one
0.01EPSS
CVE-2022-31662
Alta 7.5

VMware Workspace ONE Access, Identity Manager, Connectors and vRealize Automation contain a path traversal vulnerability. A malicious actor with network access may be able to access arbitrary files.

vmware access_connector · vmware identity_manager · vmware identity_manager_connector · vmware one_access
0.01EPSS
CVE-2017-4905
Media 5.5

VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to …

vmware esxi · vmware fusion · vmware fusion_pro · vmware workstation_player · e altri 1
0.01EPSS
CVE-2012-1513
Media 4.0

The Web Configuration tool in VMware vCenter Orchestrator (vCO) 4.0 before Update 4, 4.1 before Update 2, and 4.2 before Update 1 places the vCenter Server password in an HTML document, which allows remote authenticated administrators to obtain sensitive infor…

vmware vcenter_orchestrator
0.01EPSS
CVE-2023-20900
Alta 7.1

A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that targe…

debian debian_linux · fedoraproject fedora · netapp ontap_select_deploy_administration_utility · vmware open_vm_tools · e altri 1
0.01EPSS
CVE-2012-0903
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Desktop 7.1.2 b10978 allow remote attackers to inject arbitrary web script or HTML via the (1) Username or (2) MailBox Name.

vmware zimbra_desktop
0.01EPSS
CVE-2021-22027
Alta 7.5

The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack leadin…

vmware cloud_foundation · vmware vrealize_operations_manager · vmware vrealize_suite_lifecycle_manager
0.01EPSS
CVE-2021-21994
Critica 9.8

SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request.

vmware cloud_foundation · vmware esxi
0.01EPSS
CVE-2007-5025
Alta 9.3

Unspecified vulnerability in EMC VMware ACE before 1.0.3 Build 54075 allows attackers to have an unknown impact via an unspecified manipulation of "images stored in virtual machines downloaded by the user."

vmware ace
0.01EPSS
CVE-2019-5540
Alta 7.7

VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an information disclosure vulnerability in vmnetdhcp. Successful exploitation of this issue may allow an attacker on a guest VM to disclose sensitive information by leaking memory …

vmware fusion · vmware workstation
0.01EPSS
CVE-2023-34053
Media 5.3

In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the appl…

vmware spring_framework
0.01EPSS
CVE-2016-2079
Media 5.9

VMware NSX Edge 6.1 before 6.1.7 and 6.2 before 6.2.3 and vCNS Edge 5.5 before 5.5.4.3, when the SSL-VPN feature is configured, allow remote attackers to obtain sensitive information via unspecified vectors.

vmware nsx_edge · vmware vcloud_networking_and_security_edge
0.01EPSS