imPC@ndo IT

VMware vulnerabilities

956 CVE

CVE-2020-5396
High 8.8

VMware GemFire versions prior to 9.10.0, 9.9.2, 9.8.7, and 9.7.6, and VMware Tanzu GemFire for VMs versions prior to 1.11.1 and 1.10.2, when deployed without a SecurityManager, contain a JMX service available which contains an insecure default configuration. T…

vmware gemfire · vmware tanzu_gemfire_for_virtual_machines
0.02EPSS
CVE-2016-7459
High 7.7

VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distributed Switch setup, or (3) Content Library XML document containing an external entity declaration in conjunction …

vmware vcenter_server
0.02EPSS
CVE-2019-3795
Medium 5.3

Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest app…

debian debian_linux · vmware spring_security
0.02EPSS
CVE-2008-4281
High 9.3

Directory traversal vulnerability in VMWare ESXi 3.5 before ESXe350-200810401-O-UG and ESX 3.5 before ESX350-200810201-UG allows administrators with the Datastore.FileManagement privilege to gain privileges via unknown vectors.

vmware esx · vmware esxi
0.02EPSS
CVE-2019-5532
High 7.7

VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability due to the logging of credentials in plain-text for virtual machines deployed through OVF. A malicious user with access…

vmware vcenter_server
0.02EPSS
CVE-2017-4923
Critical 9.8

VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtained when using the vCenter Server Appliance file-based backup feature.

vmware vcenter_server
0.02EPSS
CVE-2023-20892
High 8.1

The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execute arbitrar…

vmware vcenter_server
0.02EPSS
CVE-2009-2968
Medium 5.0

Directory traversal vulnerability in a support component in the web interface in VMware Studio 2.0 public beta before build 1017-185256 allows remote attackers to upload files to arbitrary locations via unspecified vectors.

vmware studio
0.02EPSS
CVE-2016-2077
Critical 9.8

VMware Workstation 11.x before 11.1.3 and VMware Player 7.x before 7.1.3 on Windows incorrectly access an executable file, which allows host OS users to gain host OS privileges via unspecified vectors.

vmware player · vmware workstation
0.02EPSS
CVE-2009-3282
High 7.8

Integer overflow in the vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 allows host OS users to cause a denial of service to the host OS via unspecified vectors.

vmware fusion
0.02EPSS
CVE-2013-1659
High 7.6

VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 do not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to exec…

vmware esxi · vmware vcenter_server · vmware vcenter_server_appliance
0.02EPSS
CVE-2008-3514
Medium 5.0

VMware VirtualCenter 2.5 before Update 2 and 2.0.2 before Update 5 relies on client-side "enabled/disabled functionality" for access control, which allows remote attackers to determine valid user names by enabling functionality in the GUI and then making an "a…

vmware virtualcenter
0.02EPSS
CVE-2018-11067
Medium 6.1

Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain an open redirection vulnerability. A remot…

dell emc_avamar · dell emc_integrated_data_protection_appliance · vmware vsphere_data_protection
0.02EPSS
CVE-2014-3527
Critical 9.8

When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was not associated. This is due to the fact that the proxy ticket authentication us…

vmware spring_security
0.02EPSS
CVE-2009-2416
Medium 6.5

Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in …

apple iphone_os · apple mac_os_x · apple mac_os_x_server · apple safari · and 15 more
0.02EPSS
CVE-2014-3797
Medium 4.3

Cross-site scripting (XSS) vulnerability in VMware vCenter Server Appliance (vCSA) 5.1 before Update 3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

vmware vcenter_server_appliance
0.02EPSS
CVE-2022-31703
High 7.5

The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.

vmware vrealize_log_insight
0.02EPSS
CVE-2019-11286
Critical 9.1

VMware GemFire versions prior to 9.10.0, 9.9.1, 9.8.5, and 9.7.5, and VMware Tanzu GemFire for VMs versions prior to 1.11.0, 1.10.1, 1.9.2, and 1.8.2, contain a JMX service available to the network which does not properly restrict input. A remote authenticated…

vmware gemfire · vmware tanzu_gemfire_for_virtual_machines
0.02EPSS
CVE-2010-1454
Medium 6.8

com.springsource.tcserver.serviceability.rmi.JmxSocketListener in VMware SpringSource tc Server Runtime 6.0.19 and 6.0.20 before 6.0.20.D, and 6.0.25.A before 6.0.25.A-SR01, does not properly enforce the requirement for an encrypted (aka s2enc) password, which…

vmware tc_server
0.02EPSS
CVE-2018-6970
Medium 6.5

VMware Horizon 6 (6.x.x before 6.2.7), Horizon 7 (7.x.x before 7.5.1), and Horizon Client (4.x.x and prior before 4.8.1) contain an out-of-bounds read vulnerability in the Message Framework library. Successfully exploiting this issue may allow a less-privilege…

vmware horizon_client · vmware horizon_view
0.02EPSS
CVE-2009-2267
Medium 6.9

VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138, VMware Fusion 2.x before 2.0.6 build …

vmware ace · vmware esx · vmware esxi · vmware fusion · and 3 more
0.02EPSS
CVE-2013-3079
High 9.0

VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to execute arbitrary programs with root privileges by leveraging Virtual Appliance Management Interface (VAMI) access.

vmware vcenter_server_appliance
0.02EPSS
CVE-2008-1340
High 7.1

Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.0.x before 6.0.3, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 allows attackers to cause a denial of service (host OS crash) via crafted VMCI calls that trigger "memo…

vmware ace · vmware player · vmware server · vmware vmware_server · and 2 more
0.02EPSS
CVE-2012-1518
High 8.3

VMware Workstation 8.x before 8.0.2, VMware Player 4.x before 4.0.2, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 use an incorrect ACL for the VMware Tools folder, which allows guest OS users to gain guest OS priv…

vmware esx · vmware esxi · vmware fusion · vmware player · and 1 more
0.02EPSS
CVE-2020-10713
High 8.2

A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verification process. This flaw also allows the bypass of Secure Boot protections. In order to load an untrusted or modified kernel, an attacker…

debian debian_linux · gnu grub2 · opensuse leap · vmware photon_os
0.02EPSS