imPC@ndo EN

Vulnerabilità VMware

956 CVE

CVE-2012-1516
Critica 9.9

The VMX process in VMware ESXi 3.5 through 4.1 and ESX 3.5 through 4.1 does not properly handle RPC commands, which allows guest OS users to cause a denial of service (memory overwrite and process crash) or possibly execute arbitrary code on the host OS via ve…

vmware esx · vmware esxi
0.03EPSS
CVE-2021-22112
Alta 8.8

Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A malicious user cannot cause the bug to h…

oracle communications_element_manager · oracle communications_interactive_session_recorder · oracle communications_unified_inventory_management · oracle hospitality_cruise_shipboard_property_management_system · e altri 4
0.03EPSS
CVE-2016-7457
Critica 10.0

VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to gain privileges, or halt and remove virtual machines, via unspecified vectors.

vmware vrealize_operations
0.03EPSS
CVE-2022-22971
Media 6.5

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

netapp cloud_secure_agent · netapp oncommand_insight · oracle financial_services_crime_and_compliance_management_studio · vmware spring_framework
0.03EPSS
CVE-2017-4941
Alta 8.8

VMware ESXi (6.0 before ESXi600-201711101-SG, 5.5 ESXi550-201709101-SG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could allow an authenticated VNC session to cause a stack overflow via a specific set of VNC p…

vmware esxi · vmware fusion · vmware workstation
0.03EPSS
CVE-2013-3657
Alta 7.5

Buffer overflow in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors.

vmware esx · vmware esxi
0.03EPSS
CVE-2018-1272
Alta 7.5

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote clie…

oracle application_testing_suite · oracle big_data_discovery · oracle communications_converged_application_server · oracle communications_diameter_signaling_router · e altri 21
0.03EPSS
CVE-2008-3697
Media 5.0

An unspecified ISAPI extension in VMware Server before 1.0.7 build 108231 allows remote attackers to cause a denial of service (IIS crash) via a malformed request.

vmware server · vmware vmware_server
0.03EPSS
CVE-2011-1786
Media 5.0

lsassd in Likewise Open /Enterprise 5.3 before build 7845, Open 6.0 before build 8325, and Enterprise 6.0 before build 178, as distributed in VMware ESXi 4.1 and ESX 4.1 and possibly other products, allows remote attackers to cause a denial of service (daemon …

likewise likewise_open · vmware esx · vmware esxi
0.03EPSS
CVE-2005-3618
Alta 7.6

Cross-site request forgery (CSRF) vulnerability in the management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch 1, and 2.x before 2.5.3 patch 2 allows allows remote attackers to perform unauthorized actions as the adminis…

vmware esx
0.03EPSS
CVE-2019-3772
Critica 9.8

Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

oracle retail_customer_management_and_segmentation_foundation · vmware spring_integration
0.03EPSS
CVE-2018-6972
Media 6.5

VMware ESXi (6.7 before ESXi670-201806401-BG, 6.5 before ESXi650-201806401-BG, 6.0 before ESXi600-201806401-BG and 5.5 before ESXi550-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain a denial-of-service vulnerability due…

vmware esxi · vmware fusion · vmware workstation
0.03EPSS
CVE-2018-6965
Alta 8.1

VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or m…

vmware esxi · vmware fusion · vmware workstation
0.03EPSS
CVE-2016-5332
Media 5.3

Directory traversal vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.6.0 allows remote attackers to read arbitrary files via unspecified vectors.

vmware vrealize_log_insight
0.03EPSS
CVE-2022-22958
Alta 7.2

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malici…

vmware cloud_foundation · vmware identity_manager · vmware vrealize_automation · vmware vrealize_suite_lifecycle_manager · e altri 1
0.03EPSS
CVE-2016-5336
Critica 9.8

VMware vRealize Automation 7.0.x before 7.1 allows remote attackers to execute arbitrary code via unspecified vectors.

vmware vrealize_automation
0.03EPSS
CVE-2010-4263
Alta 7.9

The igb_receive_skb function in drivers/net/igb/igb_main.c in the Intel Gigabit Ethernet (aka igb) subsystem in the Linux kernel before 2.6.34, when Single Root I/O Virtualization (SR-IOV) and promiscuous mode are enabled but no VLANs are registered, allows re…

linux linux_kernel · vmware esx · vmware esxi
0.03EPSS
CVE-2020-4001
Critica 9.8

The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orchestrator ships with default passwords for predefined accounts which may lead to to a Pass-the-Hash attack.

vmware sd-wan_orchestrator
0.03EPSS
CVE-2018-1199
Media 5.3

Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters when processing security constraints. By adding a URL path p…

oracle rapid_planning · oracle retail_xstore_point_of_service · redhat fuse · vmware spring_framework · e altri 1
0.03EPSS
CVE-2016-5007
Alta 7.5

Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for mapping requests to controllers respectively. Differences in the strictness of the pattern matching mechanisms, …

pivotal_software spring_framework · vmware spring_framework · vmware spring_security
0.03EPSS
CVE-2009-0910
Media 6.8

Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware Server 2.0.x before 2.0.1 build 156745 allows remote attac…

vmware ace · vmware player · vmware server · vmware workstation
0.03EPSS
CVE-2013-1405
Alta 10.0

VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update 3a, VMware VI-Client 2.5, VMware ESXi 3.5 through 4.1, and VMware ESX 3.5 through 4.1 do not properl…

vmware esx · vmware esxi · vmware vcenter_server · vmware vi-client · e altri 2
0.03EPSS
CVE-2012-5978
Media 5.0

Multiple directory traversal vulnerabilities in the (1) View Connection Server and (2) View Security Server in VMware View 4.x before 4.6.2 and 5.x before 5.1.2 allow remote attackers to read arbitrary files via unspecified vectors.

vmware view
0.03EPSS
CVE-2012-5051
Media 5.0

Directory traversal vulnerability in VMware CapacityIQ 1.5.x allows remote attackers to read arbitrary files via unspecified vectors.

vmware capacityiq
0.03EPSS
CVE-2018-11039
Media 5.9

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an…

debian debian_linux · oracle agile_plm · oracle application_testing_suite · oracle communications_diameter_signaling_router · e altri 29
0.03EPSS