imPC@ndo EN

Vulnerabilità VMware

956 CVE

CVE-2018-1259
Alta 7.5

Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying lib…

broadcom spring_data_commons · pivotal_software spring_data_rest · vmware spring_data_rest · xmlbeam xmlbeam
0.05EPSS
CVE-2024-37081
Alta 7.8

The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.

vmware cloud_foundation · vmware vcenter_server
0.05EPSS
CVE-2017-4916
Media 6.5

VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Successful exploitation of this issue may allow host users with normal user privileges to trigger a denial-of-service in a Windows host machine.

vmware workstation_player · vmware workstation_pro
0.05EPSS
CVE-2009-3547
Alta 7.0

Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathname.

canonical ubuntu_linux · fedoraproject fedora · linux linux_kernel · novell linux_desktop · e altri 10
0.05EPSS
CVE-2017-4918
Critica 9.8

VMware Horizon View Client (2.x, 3.x and 4.x prior to 4.5.0) contains a command injection vulnerability in the service startup script. Successful exploitation of this issue may allow unprivileged users to escalate their privileges to root on the Mac OSX system…

vmware horizon_view
0.05EPSS
CVE-2022-22946
Media 5.5

In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services w…

oracle commerce_guided_search · oracle communications_cloud_native_core_binding_support_function · oracle communications_cloud_native_core_console · oracle communications_cloud_native_core_network_repository_function · e altri 2
0.05EPSS
CVE-2022-29901
Media 5.6

Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary …

debian debian_linux · fedoraproject fedora · intel core_i3-6100_firmware · intel core_i3-6100e_firmware · e altri 125
0.05EPSS
CVE-2021-22045
Alta 7.8

VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A malicious actor with access to a virtual machine…

vmware cloud_foundation · vmware esxi · vmware fusion · vmware workstation
0.05EPSS
CVE-2013-1662
Media 6.9

vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host OS privileges via a crafted lsb_release binary in a directory in the PATH, related to use of the popen library…

vmware player · vmware workstation
0.05EPSS
CVE-2009-0909
Alta 9.3

Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware Server 2.0.x before 2.0.1 build 156745 allows remote attac…

vmware ace · vmware player · vmware server · vmware workstation
0.05EPSS
CVE-2009-0778
Alta 7.1

The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Destination Cache (aka DST) in some situations involving transmission of an ICMP Hos…

linux linux_kernel · vmware esx · vmware server · vmware vcenter · e altri 2
0.05EPSS
CVE-2011-2732
Media 4.3

CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the spring-security-red…

vmware springsource_spring_security
0.05EPSS
CVE-2021-21980
Alta 7.5

The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.

vmware cloud_foundation · vmware vcenter_server
0.05EPSS
CVE-2020-5413
Critica 9.8

Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default options, all unregistered classes are resolved on demand. This leads to the "deserialization gadgets" exploit wh…

oracle banking_corporate_lending_process_management · oracle banking_credit_facilities_process_management · oracle banking_supply_chain_finance · oracle banking_virtual_account_management · e altri 4
0.04EPSS
CVE-2016-7087
Media 5.3

Directory traversal vulnerability in the Connection Server in VMware Horizon View 5.x before 5.3.7, 6.x before 6.2.3, and 7.x before 7.0.1 allows remote attackers to obtain sensitive information via unspecified vectors.

vmware horizon_view
0.04EPSS
CVE-2014-8370
Media 6.4

VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, VMware Fusion 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allow host OS users to gain host OS privileges or cause a denial of service (arbitrary write to a file) by modifying a config…

vmware esxi · vmware fusion · vmware player · vmware workstation
0.04EPSS
CVE-2019-5515
Alta 8.8

VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) and Fusion (11.x before 11.0.3, 10.x before 10.1.6) updates address an out-of-bounds write vulnerability in the e1000 and e1000e virtual network adapters. Exploitation of this issue may lead to code e…

vmware fusion · vmware workstation
0.04EPSS
CVE-2019-5524
Alta 8.8

VMware Workstation (14.x before 14.1.6) and Fusion (10.x before 10.1.6) contain an out-of-bounds write vulnerability in the e1000 virtual network adapter. This issue may allow a guest to execute code on the host.

vmware fusion · vmware workstation
0.04EPSS
CVE-2023-34034
Critica 9.1

Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.

vmware spring_security
0.04EPSS
CVE-2017-4952
Alta 7.5

VMware Xenon 1.x, prior to 1.5.4-CR7_1, 1.5.7_7, 1.5.4-CR6_2, 1.3.7-CR1_2, 1.1.0-CR0-3, 1.1.0-CR3_1,1.4.2-CR4_1, and 1.5.4_8, contains an authentication bypass vulnerability due to insufficient access controls for utility endpoints. Successful exploitation of …

vmware xenon
0.04EPSS
CVE-2008-3691
Alta 10.0

Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware A…

vmware ace · vmware player · vmware server · vmware workstation
0.04EPSS
CVE-2008-2097
Alta 9.0

Buffer overflow in the openwsman management service in VMware ESXi 3.5 and ESX 3.5 allows remote authenticated users to gain privileges via an "invalid Content-Length."

vmware esx · vmware esxi
0.04EPSS
CVE-2010-4251
Alta 7.5

The socket implementation in net/core/sock.c in the Linux kernel before 2.6.34 does not properly manage a backlog of received packets, which allows remote attackers to cause a denial of service (memory consumption) by sending a large amount of network traffic,…

linux linux_kernel · redhat enterprise_linux · vmware esx
0.04EPSS
CVE-2012-3288
Alta 9.3

VMware Workstation 7.x before 7.1.6 and 8.x before 8.0.4, VMware Player 3.x before 3.1.6 and 4.x before 4.0.4, VMware Fusion 4.x before 4.1.3, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 allow user-assisted remote attackers to execute arbitrary…

vmware esx · vmware esxi · vmware fusion · vmware player · e altri 1
0.04EPSS
CVE-2014-4241
Media 4.3

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect integrity via vectors related to WLS - Web Services.

oracle fusion_middleware · vmware esxi · vmware vcenter_server · vmware vcenter_server_appliance
0.04EPSS