imPC@ndo EN

Vulnerabilità VMware

956 CVE

CVE-2020-3969
Alta 7.8

VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an off-by-one heap-overflow vulnerability in the SVGA device. A ma…

vmware cloud_foundation · vmware esxi · vmware fusion · vmware workstation
0.00EPSS
CVE-2017-4946
Alta 7.8

The VMware V4H and V4PA desktop agents (6.x before 6.5.1) contain a privilege escalation vulnerability. Successful exploitation of this issue could result in a low privileged windows user escalating their privileges to SYSTEM.

vmware vrealize_operations_for_horizon · vmware vrealize_operations_for_published_applications
0.00EPSS
CVE-2022-22959
Media 4.3

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally validate a malicious JDBC URI.

vmware cloud_foundation · vmware identity_manager · vmware vrealize_automation · vmware vrealize_suite_lifecycle_manager · e altri 1
0.00EPSS
CVE-2018-6973
Alta 8.8

VMware Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds write vulnerability in the e1000 device. This issue may allow a guest to execute code on the host.

vmware fusion · vmware workstation
0.00EPSS
CVE-2026-40976
Critica 9.1

In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and re…

vmware spring_boot
0.00EPSS
CVE-2023-34038
Media 5.3

VMware Horizon Server contains an information disclosure vulnerability. A malicious actor with network access may be able to access information relating to the internal network configuration.

vmware horizon_client
0.00EPSS
CVE-2008-0923
Media 6.9

Directory traversal vulnerability in the Shared Folders feature for VMWare ACE 1.0.2 and 2.0.2, Player 1.0.4 and 2.0.2, and Workstation 5.5.4 and 6.0.2 allows guest OS users to read and write arbitrary files on the host OS via a multibyte string that produces …

vmware ace · vmware player · vmware vmware_player · vmware vmware_workstation · e altri 1
0.00EPSS
CVE-2022-31679
Bassa 3.7

Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older unsupported versions, if an attacker knows about the structure of the underlying domain model, they can craft HTTP requests t…

vmware spring_data_rest
0.00EPSS
CVE-2009-1630
Media 4.4

The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions …

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse opensuse · e altri 1
0.00EPSS
CVE-2019-5535
Media 4.7

VMware Workstation and Fusion contain a network denial-of-service vulnerability due to improper handling of certain IPv6 packets. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.7.

vmware fusion · vmware workstation
0.00EPSS
CVE-2026-22732
Critica 9.1

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP He…

vmware spring_security
0.00EPSS
CVE-2023-34036
Media 5.3

Reactive web applications that use Spring HATEOAS to produce hypermedia-based responses might be exposed to malicious forwarded headers if they are not behind a trusted proxy that ensures correctness of such headers, or if they don't have anything else in pla…

vmware spring_hateoas
0.00EPSS
CVE-2018-6974
Alta 8.8

VMware ESXi (6.7 before ESXi670-201810101-SG, 6.5 before ESXi650-201808401-BG, and 6.0 before ESXi600-201808401-BG), Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds read vulnerability in SVGA device. This issue may all…

vmware esxi · vmware fusion · vmware workstation
0.00EPSS
CVE-2020-3967
Alta 7.5

VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain a heap-overflow vulnerability in the USB 2.0 controller (EHCI). A …

vmware cloud_foundation · vmware esxi · vmware fusion · vmware workstation
0.00EPSS
CVE-2024-22280
Alta 8.5

VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.

vmware aria_automation · vmware cloud_foundation
0.00EPSS
CVE-2020-3964
Media 4.7

VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain an information leak in the EHCI USB controller. A malicious actor …

vmware cloud_foundation · vmware esxi · vmware fusion · vmware workstation
0.00EPSS
CVE-2021-22021
Media 5.4

VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user input validation. An attacker with user privileges may be able to inject a malicious payload via the Log Insight UI which would be executed …

vmware cloud_foundation · vmware vrealize_log_insight
0.00EPSS
CVE-2005-3620
Bassa 2.1

The management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch 1, and 2.x before 2.5.3 patch 2 records passwords in cleartext in URLs that are stored in world-readable web server log files, which allows local users to gain …

vmware esx
0.00EPSS
CVE-2023-34037
Media 5.3

VMware Horizon Server contains a HTTP request smuggling vulnerability. A malicious actor with network access may be able to perform HTTP smuggle requests.

vmware horizon_client
0.00EPSS
CVE-2008-4917
Alta 7.2

Unspecified vulnerability in VMware Workstation 5.5.8 and earlier, and 6.0.5 and earlier 6.x versions; VMware Player 1.0.8 and earlier, and 2.0.5 and earlier 2.x versions; VMware Server 1.0.9 and earlier; VMware ESXi 3.5; and VMware ESX 3.0.2 through 3.5 allow…

vmware esx · vmware esxi · vmware player · vmware server · e altri 1
0.00EPSS
CVE-2008-2098
Media 6.9

Heap-based buffer overflow in the VMware Host Guest File System (HGFS) in VMware Workstation 6 before 6.0.4 build 93057, VMware Player 2 before 2.0.4 build 93057, VMware ACE 2 before 2.0.2 build 93057, and VMware Fusion before 1.1.2 build 87978, when folder sh…

vmware ace_2 · vmware fusion · vmware vmware_player_2 · vmware vmware_workstation · e altri 1
0.00EPSS
CVE-2022-22944
Media 5.4

VMware Workspace ONE Boxer contains a stored cross-site scripting (XSS) vulnerability. Due to insufficient sanitization and validation, in VMware Workspace ONE Boxer calendar event descriptions, a malicious actor can inject script tags to execute arbitrary scr…

vmware workspace_one_boxer
0.00EPSS
CVE-2024-38810
Media 6.5

Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective.

vmware spring_security
0.00EPSS
CVE-2015-3650
Alta 7.2

vmware-vmx.exe in VMware Workstation 7.x through 10.x before 10.0.7 and 11.x before 11.1.1, VMware Player 5.x and 6.x before 6.0.7 and 7.x before 7.1.1, and VMware Horizon Client 5.x local-mode before 5.4.2 on Windows does not provide a valid DACL pointer duri…

vmware horizon_view_client · vmware player · vmware workstation
0.00EPSS
CVE-2008-3698
Alta 7.2

Unspecified vulnerability in the OpenProcess function in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware AC…

vmware ace · vmware player · vmware server · vmware workstation
0.00EPSS