imPC@ndo EN

Vulnerabilità VMware

956 CVE

CVE-2023-20877
Alta 8.8

VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation.

vmware cloud_foundation · vmware vrealize_operations
0.01EPSS
CVE-2021-21997
Media 5.5

VMware Tools for Windows (11.x.y prior to 11.3.0) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious actor with local user privileges in the Windows guest operating system, where VMware Tools is installed, can trigger a PANIC in the V…

vmware tools
0.01EPSS
CVE-2023-20862
Media 6.3

In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly sa…

netapp active_iq_unified_manager · vmware spring_security
0.01EPSS
CVE-2024-22253
Critica 9.3

VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process runn…

vmware cloud_foundation · vmware esxi · vmware fusion · vmware workstation
0.01EPSS
CVE-2020-3994
Alta 7.4

VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session hijack vulnerability in the vCenter Server Appliance Management Interface update function due to a lack of certificate validation. A malicious actor with network positioning between…

vmware cloud_foundation · vmware vcenter_server
0.01EPSS
CVE-2023-20891
Media 6.5

The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials in hex encoding in platform system audit logs. A malicious non-admin user who has access to the platform system…

vmware isolation_segment · vmware tanzu_application_service_for_virtual_machines
0.01EPSS
CVE-2020-3947
Alta 8.8

VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerability in vmnetdhcp. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to create a denial-of-ser…

vmware fusion · vmware workstation
0.01EPSS
CVE-2023-20899
Alta 7.5

VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagnostic bundle of the application under VMware SD-WAN Management.

vmware sd-wan_edge_firmware
0.01EPSS
CVE-2016-2082
Alta 8.8

Cross-site request forgery (CSRF) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

vmware vrealize_log_insight
0.01EPSS
CVE-2022-31672
Alta 7.2

VMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network access can escalate privileges to root.

vmware vrealize_operations
0.01EPSS
CVE-2022-31674
Media 4.3

VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can access log files that lead to information disclosure.

vmware vrealize_operations
0.01EPSS
CVE-2022-31682
Media 4.9

VMware Aria Operations contains an arbitrary file read vulnerability. A malicious actor with administrative privileges may be able to read arbitrary files containing sensitive data.

vmware vrealize_operations
0.01EPSS
CVE-2014-4632
Media 4.3

VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly verify X.509 certificates from vCenter Server SSL servers, which…

vmware vsphere_data_protection
0.01EPSS
CVE-2024-38820
Bassa 3.1

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.

vmware spring_framework
0.01EPSS
CVE-2024-22240
Media 4.9

Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading to unauthorized access to sensitive information.

vmware aria_operations_for_networks
0.01EPSS
CVE-2017-4924
Alta 8.8

VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusion (8.x before 8.5.8) contain an out-of-bounds write vulnerability in SVGA device. This issue may allow a guest to execute code on the host.

vmware esxi · vmware fusion · vmware workstation_pro
0.01EPSS
CVE-2021-22033
Bassa 2.7

Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability.

vmware cloud_foundation · vmware vrealize_operations · vmware vrealize_suite_lifecycle_manager
0.01EPSS
CVE-2012-5459
Alta 7.9

Untrusted search path vulnerability in VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows allows host OS users to gain host OS privileges via a Trojan horse DLL in a "system folder."

vmware player · vmware workstation
0.01EPSS
CVE-2008-2100
Alta 7.2

Multiple buffer overflows in VIX API 1.1.x before 1.1.4 build 93057 on VMware Workstation 5.x and 6.x, VMware Player 1.x and 2.x, VMware ACE 2.x, VMware Server 1.x, VMware Fusion 1.x, VMware ESXi 3.5, and VMware ESX 3.0.1 through 3.5 allow guest OS users to ex…

vmware ace · vmware esx · vmware esx_server · vmware esxi · e altri 4
0.01EPSS
CVE-2014-8371
Media 4.3

VMware vCenter Server Appliance (vCSA) 5.5 before Update 2, 5.1 before Update 3, and 5.0 before Update 3c does not properly validate certificates when connecting to a CIM Server on an ESXi host, which allows man-in-the-middle attackers to spoof CIM servers via…

vmware vcenter_server_appliance
0.01EPSS
CVE-2020-3965
Media 5.5

VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain an information leak in the XHCI USB controller. A malicious actor …

vmware cloud_foundation · vmware esxi · vmware fusion · vmware workstation
0.01EPSS
CVE-2022-27772
Alta 7.8

spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking. This vulnerability impacted the org.springframework.boot.web.server.AbstractConfigurableWebServerFactory.createTempDir method. NOTE: This vulnerability only …

vmware spring_boot
0.01EPSS
CVE-2021-22041
Media 6.7

VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process runnin…

vmware cloud_foundation · vmware esxi · vmware fusion · vmware workstation
0.01EPSS
CVE-2021-22035
Media 4.3

VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analytics export function. An authenticated malicious actor with non-administrative privileges may be able to embed untrusted data prior…

vmware cloud_foundation · vmware vrealize_log_insight · vmware vrealize_suite_lifecycle_manager
0.01EPSS
CVE-2020-3962
Alta 8.2

VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain a use-after-free vulnerability in the SVGA device. A malicious act…

vmware cloud_foundation · vmware esxi · vmware fusion · vmware workstation
0.01EPSS