imPC@ndo EN

Vulnerabilità VMware

956 CVE

CVE-2021-21989
Media 6.5

VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (TTC Parser). A malicious actor with access to a virtual machine or remote desktop may be …

vmware horizon_client · vmware workstation
0.00EPSS
CVE-2021-21988
Media 6.5

VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (JPEG2000 Parser). A malicious actor with access to a virtual machine or remote desktop ma…

vmware horizon_client · vmware workstation
0.00EPSS
CVE-2018-6982
Media 6.5

VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contain uninitialized stack memory usage in the vmxnet3 virtual network adapter which may lead to an information leak from host to guest.

vmware esxi · vmware fusion · vmware workstation
0.00EPSS
CVE-2018-6983
Alta 8.8

VMware Workstation (15.x before 15.0.2 and 14.x before 14.1.5) and Fusion (11.x before 11.0.2 and 10.x before 10.1.5) contain an integer overflow vulnerability in the virtual network devices. This issue may allow a guest to execute code on the host.

vmware fusion · vmware workstation
0.00EPSS
CVE-2007-5618
Alta 7.2

Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, VMware Server before 1.0.4, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1 might allow local users to gain privi…

vmware player · vmware server · vmware workstation
0.00EPSS
CVE-2020-3958
Media 5.5

VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.5.2) and VMware Fusion (11.x before 11.5.2) contain a denial-of-service vulnerability in the shader functionality. Successful exploitation of …

vmware esxi · vmware fusion · vmware workstation
0.00EPSS
CVE-2024-38832
Alta 7.1

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.

vmware aria_operations · vmware cloud_foundation
0.00EPSS
CVE-2012-1510
Alta 7.2

Buffer overflow in the WDDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges via unspecified vectors.

vmware esx · vmware esxi · vmware view
0.00EPSS
CVE-2007-1744
Media 6.3

Directory traversal vulnerability in the Shared Folders feature for VMware Workstation before 5.5.4, when a folder is shared, allows users on the guest system to write to arbitrary files on the host system via the "Backdoor I/O Port" interface.

vmware workstation
0.00EPSS
CVE-2011-1681
Bassa 3.3

vmware-hgfsmounter in VMware Open Virtual Machine Tools (aka open-vm-tools) 8.4.2-261024 and earlier attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to trigger corruption of this…

vmware open-vm-tools
0.00EPSS
CVE-2019-5525
Alta 8.8

VMware Workstation (15.x before 15.1.0) contains a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) backend. A malicious user with normal user privileges on the guest machine may exploit this issue in conjunction with other issues t…

vmware workstation
0.00EPSS
CVE-2012-1509
Alta 7.2

Buffer overflow in the XPDM display driver in VMware View before 4.6.1 allows guest OS users to gain guest OS privileges via unspecified vectors.

vmware view
0.00EPSS
CVE-2017-4934
Alta 8.8

VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a heap buffer-overflow vulnerability in VMNAT device. This issue may allow a guest to execute code on the host.

vmware fusion · vmware workstation
0.00EPSS
CVE-2026-40981
Alta 7.5

When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclus…

vmware spring_cloud_config
0.00EPSS
CVE-2017-4945
Media 5.5

VMware Workstation (14.x and 12.x) and Fusion (10.x and 8.x) contain a guest access control vulnerability. This issue may allow program execution via Unity on locked Windows VMs. VMware Tools must be updated to 10.2.0 for each VM to resolve CVE-2017-4945. VMwa…

vmware fusion · vmware workstation
0.00EPSS
CVE-2022-31688
Media 6.1

VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.

vmware workspace_one_assist
0.00EPSS
CVE-2010-2492
Alta 7.8

Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash) via unspecified vectors.

avaya aura_communication_manager · avaya aura_presence_services · avaya aura_session_manager · avaya aura_system_manager · e altri 5
0.00EPSS
CVE-2026-41699
Alta 8.1

Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the application exposes a paginated (Connection) f…

vmware spring_for_graphql
0.00EPSS
CVE-2017-4904
Alta 8.8

The XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG; Workstation …

vmware esxi · vmware fusion · vmware fusion_pro · vmware workstation_player · e altri 1
0.00EPSS
CVE-2009-1072
Media 4.9

nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse opensuse · e altri 7
0.00EPSS
CVE-2006-3589
Bassa 3.6

vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the SSL ke…

vmware esx · vmware infrastructure · vmware player · vmware server · e altri 1
0.00EPSS
CVE-2018-6977
Media 6.5

VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a 3D-rendering shader. Successfully exploiting this issue may allow an attacker with normal user privileges…

vmware esxi · vmware fusion · vmware workstation
0.00EPSS
CVE-2019-5539
Alta 7.8

VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to insecure loading of a DLL by Cortado Thinprint. Successful exploitation of this issue may allow atta…

vmware horizon_view_agent · vmware workstation
0.00EPSS
CVE-2010-2524
Alta 7.8

The DNS resolution functionality in the CIFS implementation in the Linux kernel before 2.6.35, when CONFIG_CIFS_DFS_UPCALL is enabled, relies on a user's keyring for the dns_resolver upcall in the cifs.upcall userspace helper, which allows local users to spoof…

canonical ubuntu_linux · linux linux_kernel · suse suse_linux_enterprise_desktop · suse suse_linux_enterprise_server · e altri 1
0.00EPSS
CVE-2008-1363
Alta 7.2

VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges vi…

vmware ace · vmware player · vmware server · vmware workstation
0.00EPSS