imPC@ndo EN

Vulnerabilità VMware

956 CVE

CVE-2002-0814
Alta 7.5

Buffer overflow in VMware Authorization Service for VMware GSX Server 2.0.0 build-2050 allows remote authenticated users to execute arbitrary code via a long GLOBAL argument.

vmware gsx_server
0.14EPSS
CVE-2021-22053
Alta 8.8

Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the resolution of view templates. When a request is made at `/hystrix/monitor;[user-p…

vmware spring_cloud_netflix
0.13EPSS
CVE-2021-21986
Critica 9.8

The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins. A malicious actor with network access to port…

vmware cloud_foundation · vmware vcenter_server
0.13EPSS
CVE-2024-37080
Critica 9.8

vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remo…

vmware vcenter_server
0.12EPSS
CVE-2022-22978
Critica 9.8

In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression a…

netapp active_iq_unified_manager · oracle financial_services_crime_and_compliance_management_studio · vmware spring_security
0.12EPSS
CVE-2009-3707
Media 5.0

VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, V…

vmware ace · vmware player · vmware server · vmware workstation
0.11EPSS
CVE-2020-5421
Media 6.5

In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid pat…

netapp oncommand_insight · netapp snap_creator_framework · netapp snapcenter · oracle commerce_guided_search · e altri 34
0.11EPSS
CVE-2021-21998
Critica 9.8

VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A malicious actor with network access to the VMware Carbon Black App Control management server might be able to obtain administrative access to t…

vmware carbon_black_app_control
0.11EPSS
CVE-2004-0112
Media 5.0

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SS…

4d webstar · apple mac_os_x · apple mac_os_x_server · avaya converged_communications_server · e altri 61
0.10EPSS
CVE-2020-5412
Media 6.5

Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the dashboar…

vmware spring_cloud_netflix
0.10EPSS
CVE-2014-3625
Media 5.0

Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.

pivotal_software spring_framework · vmware spring_framework
0.10EPSS
CVE-2021-22048
Alta 8.8

The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit this issue to elevate privileges to a highe…

vmware cloud_foundation · vmware vcenter_server
0.10EPSS
CVE-2018-11066
Critica 9.8

Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain a Remote Code Execution vulnerability. A r…

dell emc_avamar · dell emc_integrated_data_protection_appliance · vmware vsphere_data_protection
0.10EPSS
CVE-2004-0079
Alta 7.5

The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.

4d webstar · apple mac_os_x · apple mac_os_x_server · avaya converged_communications_server · e altri 62
0.10EPSS
CVE-2018-15756
Alta 7.5

Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starti…

debian debian_linux · oracle agile_plm · oracle communications_brm_-_elastic_charging_engine · oracle communications_converged_application_server_-_service_controller · e altri 36
0.10EPSS
CVE-2019-5526
Alta 7.8

VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by the application. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to admini…

vmware workstation
0.09EPSS
CVE-2017-4914
Critica 9.8

VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance.

vmware vsphere_data_protection
0.09EPSS
CVE-2009-0177
Media 5.0

vmwarebase.dll, as used in the vmware-authd service (aka vmware-authd.exe), in VMware Workstation 6.5.1 build 126130, 6.5.1 and earlier; VMware Player 2.5.1 build 126130, 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 2.0.x before 2.0.1 build 1…

vmware ace · vmware fusion · vmware server · vmware vmware_player · e altri 1
0.09EPSS
CVE-2017-4947
Critica 9.8

VMware vRealize Automation (7.3 and 7.2) and vSphere Integrated Containers (1.x before 1.3) contain a deserialization vulnerability via Xenon. Successful exploitation of this issue may allow remote attackers to execute arbitrary code on the appliance.

vmware vrealize_automation · vmware vsphere_integrated_containers
0.09EPSS
CVE-2011-2894
Media 6.8

Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and possibly other versions deserialize objects from untrusted sources, which allows remote attackers to bypass intended security restrictions and execute untrus…

vmware spring_framework · vmware spring_security
0.09EPSS
CVE-2022-31678
Critica 9.1

VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.

vmware cloud_foundation · vmware nsx_data_center
0.08EPSS
CVE-2022-22955
Critica 9.8

VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authent…

vmware identity_manager · vmware vrealize_automation · vmware workspace_one_access
0.08EPSS
CVE-2007-0062
Alta 10.0

Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE bef…

vmware ace · vmware player · vmware server · vmware vmware_workstation · e altri 1
0.08EPSS
CVE-2007-4059
Media 5.8

Absolute path traversal vulnerability in a certain ActiveX control in IntraProcessLogging.dll 5.5.3.42958 in EMC VMware allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SetLogFileName method.

vmware workstation
0.07EPSS
CVE-2004-0081
Media 5.0

OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.

4d webstar · apple mac_os_x · apple mac_os_x_server · avaya converged_communications_server · e altri 62
0.07EPSS