imPC@ndo EN

Vulnerabilità VMware

956 CVE

CVE-2006-5990
Media 4.0

VMWare VirtualCenter client 2.x before 2.0.1 Patch 1 (Build 33643) and 1.4.x before 1.4.1 Patch 1 (Build 33425), when server certificate verification is enabled, does not verify the server's X.509 certificate when creating an SSL session, which allows remote m…

vmware virtualcenter
0.01EPSS
CVE-2017-8044
Media 6.1

In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3), certain pages allow code to be injected into the DOM environment through query parameters, leading to XSS attacks.

vmware single_sign-on_for_pivotal_cloud_foundry
0.01EPSS
CVE-2017-8041
Media 6.1

In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, a user can execute a XSS attack on certain Single Sign-On service UI pages by inputting code in the text field for an organization name.

vmware single_sign-on_for_pivotal_cloud_foundry
0.01EPSS
CVE-2006-3547
Media 5.5

EMC VMware Player allows user-assisted attackers to cause a denial of service (unrecoverable application failure) via a long value of the ide1:0.fileName parameter in the .vmx file of a virtual machine. NOTE: third parties have disputed this issue, saying tha…

vmware player
0.01EPSS
CVE-2023-20872
Alta 8.8

VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation.

vmware fusion · vmware workstation
0.01EPSS
CVE-2021-22060
Media 4.3

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against addi…

oracle communications_cloud_native_core_console · oracle communications_cloud_native_core_service_communication_proxy · vmware spring_framework
0.01EPSS
CVE-2017-4917
Critica 9.8

VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained.

vmware vsphere_data_protection
0.01EPSS
CVE-2015-2344
Media 5.4

Cross-site scripting (XSS) vulnerability in VMware vRealize Automation 6.x before 6.2.4 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

vmware vrealize_automation
0.01EPSS
CVE-2020-3982
Alta 7.7

VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds write vulnerability due to a time-of-check time-of-use issue in ACPI de…

vmware cloud_foundation · vmware esxi · vmware fusion · vmware workstation · e altri 1
0.01EPSS
CVE-2018-11076
Media 6.5

Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0 and 7.4.1 and Dell EMC Integrated Data Protection Appliance (IDPA) 2.0 are affected by an information exposure vulnerability. Avamar Java management console's SSL/TLS private key may be leaked i…

dell emc_avamar · dell emc_integrated_data_protection_appliance · vmware vsphere_data_protection
0.01EPSS
CVE-2022-22961
Media 5.3

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Successful exploitation …

vmware cloud_foundation · vmware identity_manager · vmware vrealize_automation · vmware vrealize_suite_lifecycle_manager · e altri 1
0.01EPSS
CVE-2017-4951
Alta 8.8

VMware AirWatch Console (9.2.x before 9.2.2 and 9.1.x before 9.1.5) contains a Cross Site Request Forgery vulnerability when accessing the App Catalog. An attacker may exploit this issue by tricking users into installing a malicious application on their device…

vmware airwatch
0.01EPSS
CVE-2016-2075
Media 5.4

Cross-site scripting (XSS) vulnerability in VMware vRealize Business Advanced and Enterprise 8.x before 8.2.5 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

vmware vrealize_business_advanced_and_enterprise
0.01EPSS
CVE-2007-4497
Media 5.5

Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server be…

canonical ubuntu_linux · vmware ace · vmware player · vmware server · e altri 1
0.01EPSS
CVE-2015-1044
Bassa 3.3

vmware-authd (aka the Authorization process) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allows attackers to cause a host OS denial of service via unspecified vectors.

vmware esxi · vmware player · vmware workstation
0.01EPSS
CVE-2022-31689
Critica 9.8

VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token.

vmware workspace_one_assist
0.01EPSS
CVE-2022-31687
Critica 9.8

VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.

vmware workspace_one_assist
0.01EPSS
CVE-2022-38650
Critica 10.0

A remote unauthenticated insecure deserialization vulnerability exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to run arbitrary code or malware within Hyperic Server and the host operating system with the pr…

vmware hyperic_server
0.01EPSS
CVE-2021-22113
Media 5.3

Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sensitive Headers” restriction when executing requests with specially constructed URLs. Applications that use Spri…

vmware spring_cloud_netflix_zuul
0.01EPSS
CVE-2012-1515
Alta 8.3

VMware ESXi 3.5, 4.0, and 4.1 and ESX 3.5, 4.0, and 4.1 do not properly implement port-based I/O operations, which allows guest OS users to gain guest OS privileges by overwriting memory locations in a read-only memory block associated with the Virtual DOS Mac…

vmware esx · vmware esxi
0.01EPSS
CVE-2021-22025
Alta 7.5

The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can add new nodes to exis…

vmware cloud_foundation · vmware vrealize_operations_manager · vmware vrealize_suite_lifecycle_manager
0.01EPSS
CVE-2022-31675
Alta 7.5

VMware vRealize Operations contains an authentication bypass vulnerability. An unauthenticated malicious actor with network access may be able to create a user with administrative privileges.

vmware vrealize_operations
0.01EPSS
CVE-2020-3981
Media 5.8

VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds read vulnerability due to a time-of-check time-of-use issue in ACPI dev…

vmware cloud_foundation · vmware esxi · vmware fusion · vmware workstation
0.01EPSS
CVE-2020-3940
Media 5.9

VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability.

vmware workspace_one_boxer · vmware workspace_one_content · vmware workspace_one_intelligent_hub · vmware workspace_one_notebook · e altri 5
0.01EPSS
CVE-2022-22977
Alta 7.1

VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative local user privileges in the Windows guest OS, where VMware Tools is installed, may exploit this issue leading to…

vmware tools
0.01EPSS