imPC@ndo EN

Vulnerabilità VMware

956 CVE

CVE-2023-46120
Media 4.9

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. `maxBodyLebgth` was not used when receiving Message objects. Attackers could send a very large Message causing a memory overflow and trigge…

vmware rabbitmq_java_client
0.01EPSS
CVE-2020-5427
Alta 7.2

In Spring Cloud Data Flow, versions 2.6.x prior to 2.6.5, versions 2.5.x prior 2.5.4, an application is vulnerable to SQL injection when requesting task execution.

vmware spring_cloud_data_flow
0.01EPSS
CVE-2021-22043
Alta 7.5

VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled. A malicious actor with access to settingsd, may exploit this issue to escalate their privileges by writing arbitrary files.

vmware esxi · vmware fusion
0.01EPSS
CVE-2024-22233
Alta 7.5

In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the ap…

vmware spring_framework
0.01EPSS
CVE-2019-5520
Media 5.9

VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before 10.1.6) updates address an out-of-bounds read vulnerability. Exploitation of thi…

vmware esxi · vmware fusion · vmware workstation
0.01EPSS
CVE-2020-3946
Alta 7.5

InstallBuilder AutoUpdate tool and regular installers enabling <checkForUpdates> built with versions earlier than 19.11 are vulnerable to Billion laughs attack (denial-of-service).

vmware installbuilder
0.01EPSS
CVE-2017-4929
Media 6.1

VMware NSX Edge (6.2.x before 6.2.9 and 6.3.x before 6.3.5) contains a moderate Cross-Site Scripting (XSS) issue which may lead to information disclosure.

vmware nsx_edge
0.01EPSS
CVE-2022-31690
Alta 8.1

Spring Security, versions 5.7 prior to 5.7.5, and 5.6 prior to 5.6.9, and older unsupported versions could be susceptible to a privilege escalation under certain conditions. A malicious user or attacker can modify a request initiated by the Client (via the bro…

netapp active_iq_unified_manager · vmware spring_security
0.01EPSS
CVE-2021-22024
Alta 7.5

The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log file resulting in sensitive information dis…

vmware cloud_foundation · vmware vrealize_operations_manager · vmware vrealize_suite_lifecycle_manager
0.01EPSS
CVE-2021-22114
Media 5.3

Addresses partial fix in CVE-2018-1263. Spring-integration-zip, versions prior to 1.0.4, exposes an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), …

vmware spring_integration_zip
0.01EPSS
CVE-2021-22097
Media 6.5

In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object. It is possible to construct a malicious java.util…

vmware spring_advanced_message_queuing_protocol
0.01EPSS
CVE-2021-22095
Media 6.5

In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size. This can cause an OOM Error with a large message

vmware spring_advanced_message_queuing_protocol
0.01EPSS
CVE-2020-5406
Media 6.5

VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x versions prior to 2.8.5, includes a version of PCF Autoscaling that writes database connection properties to its log, including database usernam…

vmware tanzu_application_service_for_vms
0.01EPSS
CVE-2018-11077
Media 6.7

'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 is affected by an OS command injection vulnerability. A mali…

dell emc_avamar · dell emc_integrated_data_protection_appliance · vmware vsphere_data_protection
0.01EPSS
CVE-2019-5519
Media 6.8

VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 10.1.6) contain a Time-of-check Time-of-use (TOCTOU) vulnerabi…

vmware esxi · vmware fusion · vmware workstation
0.01EPSS
CVE-2023-20878
Alta 7.2

VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system.

vmware cloud_foundation · vmware vrealize_operations
0.01EPSS
CVE-2021-22023
Alta 7.2

The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to vRealize Operations Manager API may be able to modify other users information leading to an account takeover.

vmware cloud_foundation · vmware vrealize_operations_manager · vmware vrealize_suite_lifecycle_manager
0.01EPSS
CVE-2008-3761
Media 4.9

hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 1.0.x before 1.0.9 build 156507 and 2.0.x before 2.0.1 build 156745 uses the METHOD_NEITHER communication method for IOCTLs, whi…

vmware vmware_workstation
0.01EPSS
CVE-2024-22275
Media 4.9

The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.

vmware cloud_foundation · vmware vcenter_server
0.01EPSS
CVE-2021-22003
Alta 7.5

VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based…

vmware cloud_foundation · vmware identity_manager · vmware vrealize_suite_lifecycle_manager · vmware workspace_one_access
0.01EPSS
CVE-2009-3621
Media 5.5

net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing a series o…

canonical ubuntu_linux · fedoraproject fedora · linux linux_kernel · opensuse opensuse · e altri 4
0.01EPSS
CVE-2021-21992
Media 6.5

The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-administrative user access to the vCenter Server vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash) may exploit t…

vmware cloud_foundation · vmware vcenter_server
0.01EPSS
CVE-2021-22034
Alta 7.5

Releases prior to VMware vRealize Operations Tenant App 8.6 contain an Information Disclosure Vulnerability.

vmware vrealize_operations_tenant
0.01EPSS
CVE-2023-20861
Media 6.5

In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.

vmware spring_framework
0.01EPSS
CVE-2013-1406
Alta 7.2

The Virtual Machine Communication Interface (VMCI) implementation in vmci.sys in VMware Workstation 8.x before 8.0.5 and 9.x before 9.0.1 on Windows, VMware Fusion 4.1 before 4.1.4 and 5.0 before 5.0.2, VMware View 4.x before 4.6.2 and 5.x before 5.1.2 on Wind…

vmware esx · vmware esxi · vmware fusion · vmware view · e altri 1
0.01EPSS