imPC@ndo EN

Vulnerabilità VMware

956 CVE

CVE-2010-2942
Media 5.5

The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information …

avaya aura_communication_manager · avaya aura_presence_services · avaya aura_session_manager · avaya aura_system_manager · e altri 9
0.00EPSS
CVE-2024-22256
Media 4.3

VMware Cloud Director contains a partial information disclosure vulnerability. A malicious actor can potentially gather information about organization names based on the behavior of the instance.

vmware cloud_director
0.00EPSS
CVE-2016-7085
Alta 7.8

Untrusted search path vulnerability in the installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.

vmware workstation_player · vmware workstation_pro
0.00EPSS
CVE-2018-6971
Alta 7.8

VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disclosure vulnerability due to insecure logging of credentials in the vmmsi.log file when an account other than the currently logged on user is specified during installation (includin…

vmware horizon_view_agents
0.00EPSS
CVE-2009-3080
Alta 7.2

Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse opensuse · e altri 9
0.00EPSS
CVE-2018-6962
Alta 7.8

VMware Fusion (10.x before 10.1.2) contains a signature bypass vulnerability which may lead to a local privilege escalation.

vmware fusion
0.00EPSS
CVE-2012-1508
Alta 7.2

The XPDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.

vmware esx · vmware esxi · vmware view
0.00EPSS
CVE-2010-2798
Alta 7.8

The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer dereference and …

avaya aura_communication_manager · avaya aura_presence_services · avaya aura_session_manager · avaya aura_system_manager · e altri 11
0.00EPSS
CVE-2022-31655
Media 5.4

VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in alerts.

vmware vrealize_log_insight
0.00EPSS
CVE-2022-31654
Media 5.4

VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in configurations.

vmware vrealize_log_insight
0.00EPSS
CVE-2026-22720
Alta 8.0

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations.  To remediate CVE-2026-22720, …

vmware aria_operations · vmware cloud_foundation · vmware telco_cloud_infrastructure · vmware telco_cloud_platform
0.00EPSS
CVE-2013-5972
Alta 7.2

VMware Workstation 9.x before 9.0.3 and VMware Player 5.x before 5.0.3 on Linux do not properly handle shared libraries, which allows host OS users to gain host OS privileges via unspecified vectors.

vmware player · vmware workstation
0.00EPSS
CVE-2017-4903
Alta 8.8

VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior…

vmware esxi · vmware fusion · vmware fusion_pro · vmware workstation_player · e altri 1
0.00EPSS
CVE-2012-4897
Media 6.9

Untrusted search path vulnerability in the installer in VMware Movie Decoder before 9.0 allows local users to gain privileges via a Trojan horse executable file in the installer directory.

vmware movie_decoder
0.00EPSS
CVE-2017-4948
Alta 7.1

VMware Workstation (14.x before 14.1.0 and 12.x) and Horizon View Client (4.x before 4.7.0) contain an out-of-bounds read vulnerability in TPView.dll. On Workstation, this issue in conjunction with other bugs may allow a guest to leak information from host or …

vmware horizon_view · vmware workstation
0.00EPSS
CVE-2024-38833
Media 6.8

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.

vmware aria_operations · vmware cloud_foundation
0.00EPSS
CVE-2008-4915
Media 6.9

The CPU hardware emulation in VMware Workstation 6.0.5 and earlier and 5.5.8 and earlier; Player 2.0.x through 2.0.5 and 1.0.x through 1.0.8; ACE 2.0.x through 2.0.5 and earlier, and 1.0.x through 1.0.7; Server 1.0.x through 1.0.7; ESX 2.5.4 through 3.5; and E…

vmware ace · vmware esx · vmware esxi · vmware player · e altri 2
0.00EPSS
CVE-2010-3078
Media 5.5

The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc4 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an ioctl cal…

canonical ubuntu_linux · linux linux_kernel · opensuse opensuse · suse suse_linux_enterprise_desktop · e altri 2
0.00EPSS
CVE-2009-0034
Alta 7.8

parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain …

gratisoft sudo · vmware esx
0.00EPSS
CVE-2023-34064
Media 4.6

Workspace ONE Launcher contains a Privilege Escalation Vulnerability. A malicious actor with physical access to Workspace ONE Launcher could utilize the Edge Panel feature to bypass setup to gain access to sensitive information.

vmware workspace_one_launcher
0.00EPSS
CVE-2014-4199
Media 6.3

vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to write to arbitrary files via a symlink attack on a file in /tmp.

vmware tools · vmware vm-support · vmware workstation
0.00EPSS
CVE-2008-2099
Media 6.9

Unspecified vulnerability in VMCI in VMware Workstation 6 before 6.0.4 build 93057, VMware Player 2 before 2.0.4 build 93057, and VMware ACE 2 before 2.0.2 build 93057 on Windows allows guest OS users to execute arbitrary code on the host OS via unspecified ve…

vmware ace_2 · vmware vmware_player_2 · vmware vmware_workstation · vmware workstation
0.00EPSS
CVE-2023-20856
Alta 8.8

VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of the authenticated victim user.

vmware vrealize_operations
0.00EPSS
CVE-2018-6963
Media 5.5

VMware Workstation (14.x before 14.1.2) and Fusion (10.x before 10.1.2) contain multiple denial-of-service vulnerabilities that occur due to NULL pointer dereference issues in the RPC handler. Successful exploitation of these issues may allow an attacker with …

vmware fusion · vmware workstation
0.00EPSS
CVE-2023-34059
Alta 7.4

open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.

debian debian_linux · vmware open_vm_tools
0.00EPSS