imPC@ndo EN

Vulnerabilità VMware

956 CVE

CVE-2021-21990
Media 6.1

VMware Workspace one UEM console (2102 prior to 21.2.0.8, 2101 prior to 21.1.0.14, 2011 prior to 20.11.0.27, 2010 prior to 20.10.0.16,2008 prior to 20.8.0.28, 2007 prior to 20.7.0.14,2006 prior to 20.6.0.19, 2005 prior to 20.5.0.46, 2004 prior to 20.4.0.21, 20…

vmware workspace_one_unified_endpoint_management
0.01EPSS
CVE-2019-11291
Media 4.8

Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input.…

broadcom rabbitmq_server · redhat openstack · vmware rabbitmq
0.01EPSS
CVE-2022-31708
Media 4.9

vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.4.

vmware vrealize_operations
0.01EPSS
CVE-2019-5518
Media 6.8

VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 10.1.6) contain an out-of-bounds read/write vulnerability in t…

vmware esxi · vmware fusion · vmware workstation
0.01EPSS
CVE-2015-1043
Bassa 3.3

The Host Guest File System (HGFS) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, and VMware Fusion 6.x before 6.0.5 and 7.x before 7.0.1 allows guest OS users to cause a guest OS denial of service via unspecified vectors.

vmware fusion · vmware player · vmware workstation
0.01EPSS
CVE-2012-1666
Media 6.9

Untrusted search path vulnerability in VMware Tools in VMware Workstation before 8.0.4, VMware Player before 4.0.4, VMware Fusion before 4.1.2, VMware View before 5.1, and VMware ESX 4.1 before U3 and 5.0 before P03 allows local users to gain privileges via a …

vmware esx · vmware fusion · vmware player · vmware view · e altri 1
0.01EPSS
CVE-2022-22939
Media 4.9

VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text within multiple log files on the SDDC Manager. A malicious actor with root access on VMware Cloud Foundation SDDC Manager may be able to view c…

vmware cloud_foundation
0.01EPSS
CVE-2022-38652
Critica 9.9

A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authenticated user to run arbitrary code or malware within a Hyperic Agent instance and its host operating system with…

vmware hyperic_agent
0.01EPSS
CVE-2017-4926
Media 5.4

VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which will get executed when other VC users access the page.

vmware vcenter_server
0.01EPSS
CVE-2022-23825
Media 6.5

Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.

amd a10-9600p_firmware · amd a10-9630p_firmware · amd a12-9700p_firmware · amd a12-9730p_firmware · e altri 122
0.01EPSS
CVE-2020-3954
Media 6.1

Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.

vmware vrealize_log_insight
0.01EPSS
CVE-2016-2081
Media 6.1

Cross-site scripting (XSS) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

vmware vrealize_log_insight
0.01EPSS
CVE-2015-6931
Media 6.1

Cross-site scripting (XSS) vulnerability in the vSphere Web Client in VMware vCenter Server 5.0 before U3g, 5.1 before U3d, and 5.5 before U2d allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

vmware vcenter_server
0.01EPSS
CVE-2022-38651
Critica 9.8

A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some authentication requirements when issuing requests to Hyperic Server. NOTE: This vulnerability only affects pro…

vmware hyperic_server
0.01EPSS
CVE-2015-5258
Alta 8.8

Cross-site request forgery (CSRF) vulnerability in springframework-social before 1.1.3.

fedoraproject fedora · vmware spring_social
0.01EPSS
CVE-2022-22953
Media 6.5

VMware HCX update addresses an information disclosure vulnerability. A malicious actor with network user access to the VMware HCX appliance may be able to gain access to sensitive information.

vmware vmware_hcx
0.01EPSS
CVE-2015-2337
Media 5.8

TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, w…

vmware fusion · vmware horizon_client · vmware horizon_view_client · vmware player · e altri 1
0.01EPSS
CVE-2015-2336
Media 5.8

TPView.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, …

vmware fusion · vmware horizon_client · vmware horizon_view_client · vmware player · e altri 1
0.01EPSS
CVE-2023-31131
Alta 7.4

Greenplum Database (GPDB) is an open source data warehouse based on PostgreSQL. In versions prior to 6.22.3 Greenplum Database used an unsafe methods to extract tar files within GPPKGs. greenplum-db is vulnerable to path traversal leading to arbitrary file wri…

vmware greenplum_database
0.01EPSS
CVE-2021-22047
Media 5.3

In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that c…

vmware spring_data_rest
0.01EPSS
CVE-2015-6932
Media 5.8

VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

vmware vcenter_server
0.01EPSS
CVE-2026-40982
Critica 9.1

Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack. Sprin…

vmware spring_cloud_config
0.01EPSS
CVE-2020-5425
Alta 7.9

Single Sign-On for Vmware Tanzu all versions prior to 1.11.3 ,1.12.x versions prior to 1.12.4 and 1.13.x prior to 1.13.1 are vulnerable to user impersonation attack.If two users are logged in to the SSO operator dashboard at the same time, with the same userna…

vmware single_sign-on_for_tanzu
0.01EPSS
CVE-2021-22040
Media 6.7

VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process runn…

vmware cloud_foundation · vmware esxi · vmware fusion · vmware workstation_player · e altri 1
0.01EPSS
CVE-2020-5426
Critica 9.8

Scheduler for TAS prior to version 1.4.0 was permitting plaintext transmission of UAA client token by sending it over a non-TLS connection. This also depended on the configuration of the MySQL server which is used to cache a UAA client token used by the servic…

vmware pivotal_scheduler
0.01EPSS