imPC@ndo EN

Vulnerabilità VMware

956 CVE

CVE-2017-4908
Alta 7.8

VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple heap buffer-overflow vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Ser…

vmware horizon_view · vmware workstation
0.00EPSS
CVE-2010-4296
Alta 7.2

vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2 build 332101 does not properly load libraries, which allows ho…

vmware fusion · vmware player · vmware server · vmware workstation
0.00EPSS
CVE-2007-1876
Alta 7.2

VMware Workstation before 5.5.4, when running a 64-bit Windows guest on a 64-bit host, allows local users to "corrupt the virtual machine's register context" by debugging a local program and stepping into a "syscall instruction."

vmware workstation
0.00EPSS
CVE-2016-7080
Alta 7.8

The graphic acceleration functions in VMware Tools 9.x and 10.x before 10.0.9 on OS X allow local users to gain privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors, a different vulnerability than CVE-2016-7079.

vmware tools
0.00EPSS
CVE-2016-7079
Alta 7.8

The graphic acceleration functions in VMware Tools 9.x and 10.x before 10.0.9 on OS X allow local users to gain privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors, a different vulnerability than CVE-2016-7080.

vmware tools
0.00EPSS
CVE-2011-1788
Bassa 2.1

vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1 allows local users to discover the SOAP session ID via unspecified vectors.

vmware vcenter
0.00EPSS
CVE-2008-4278
Bassa 2.1

VMware VirtualCenter 2.5 before Update 3 build 119838 on Windows displays a user's password in cleartext when the password contains unspecified special characters, which allows physically proximate attackers to steal the password.

vmware virtualcenter
0.00EPSS
CVE-2017-4938
Media 6.5

VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL pointer dereference vulnerability. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.

vmware fusion · vmware workstation
0.00EPSS
CVE-2007-5438
Bassa 1.9

Unspecified vulnerability in a certain ActiveX control in Reconfig.DLL in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build …

vmware ace · vmware vmware_player · vmware vmware_server · vmware vmware_workstation
0.00EPSS
CVE-2022-22938
Media 6.5

VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-service vulnerability in the Cortado ThinPrint component. The issue exists in TrueType font parser. A malicious actor with access to a virtual ma…

vmware horizon · vmware workstation
0.00EPSS
CVE-2003-0739
Media 4.6

VMware Workstation 4.0.1 for Linux, build 5289 and earlier, allows local users to delete arbitrary files via a symlink attack.

vmware workstation
0.00EPSS
CVE-2010-2928
Bassa 2.1

The vCenter Tomcat Management Application in VMware vCenter Server 4.1 before Update 1 stores log-on credentials in a configuration file, which allows local users to gain privileges by reading this file.

vmware vcenter_server
0.00EPSS
CVE-2020-3966
Alta 7.5

VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a heap-overflow due to a race condition issue in the USB 2.0 contr…

vmware cloud_foundation · vmware esxi · vmware fusion · vmware workstation
0.00EPSS
CVE-2026-41851
Media 5.3

Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth. Affected versions: Spring Framework 7.0.0 throu…

vmware spring_framework
0.00EPSS
CVE-2026-41850
Alta 7.5

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluati…

vmware spring_framework
0.00EPSS
CVE-2026-22733
Alta 8.2

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Sec…

vmware spring_boot
0.00EPSS
CVE-2023-34047
Bassa 3.1

A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context with values, including security context values, from a different session. An application is vulnerable if it provides a DataLoaderOptions i…

vmware spring_for_graphql
0.00EPSS
CVE-2008-1362
Alta 7.2

VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges or…

vmware ace · vmware player · vmware server · vmware vmware_server · e altri 2
0.00EPSS
CVE-2020-3974
Alta 7.8

VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior before 11.2.0 ) and Horizon Client for Mac (5.x and prior before 5.4.3) contain a privilege escalation vulnerability due to improper XPC Client validation. Successful exploitatio…

vmware fusion · vmware horizon_client · vmware remote_console
0.00EPSS
CVE-2007-1271
Media 6.6

Buffer overflow in VMware ESX Server 3.0.0 and 3.0.1 might allow attackers to gain privileges or cause a denial of service (application crash) via unspecified vectors.

vmware esx
0.00EPSS
CVE-2008-0967
Media 6.9

Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware Player 1.x before 1.0.7 build 91707 and 2.x before 2.0.4 build 93057, and VMware Server before 1.0.6 build 91891 on …

vmware esx · vmware esx_server · vmware esxi · vmware player · e altri 4
0.00EPSS
CVE-2017-4943
Alta 7.8

VMware vCenter Server Appliance (vCSA) (6.5 before 6.5 U1d) contains a local privilege escalation vulnerability via the 'showlog' plugin. Successful exploitation of this issue could result in a low privileged user gaining root level privileges over the applian…

vmware vcenter_server
0.00EPSS
CVE-2009-1146
Media 4.9

Unspecified vulnerability in an ioctl in hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 1.0.x before 1.0.9 build 156507 and 2.0.x before 2.0.1 build 156745 allows local users …

vmware ace · vmware player · vmware server · vmware workstation
0.00EPSS
CVE-2022-22945
Alta 7.8

VMware NSX Edge contains a CLI shell injection vulnerability. A malicious actor with SSH access to an NSX-Edge appliance can execute arbitrary commands on the operating system as root.

vmware cloud_foundation · vmware nsx_data_center
0.00EPSS
CVE-2026-41705
Alta 8.6

Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs. Spring AI 1.0.x: affected from 1.0.0 through latest 1.0.x; upgrade to 1.0.7 or greater. Spring AI 1.1.x: affected from 1.1.0 …

vmware spring_ai
0.00EPSS