imPC@ndo IT

VMware vulnerabilities

956 CVE

CVE-2006-5990
Medium 4.0

VMWare VirtualCenter client 2.x before 2.0.1 Patch 1 (Build 33643) and 1.4.x before 1.4.1 Patch 1 (Build 33425), when server certificate verification is enabled, does not verify the server's X.509 certificate when creating an SSL session, which allows remote m…

vmware virtualcenter
0.01EPSS
CVE-2017-8044
Medium 6.1

In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3), certain pages allow code to be injected into the DOM environment through query parameters, leading to XSS attacks.

vmware single_sign-on_for_pivotal_cloud_foundry
0.01EPSS
CVE-2017-8041
Medium 6.1

In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, a user can execute a XSS attack on certain Single Sign-On service UI pages by inputting code in the text field for an organization name.

vmware single_sign-on_for_pivotal_cloud_foundry
0.01EPSS
CVE-2006-3547
Medium 5.5

EMC VMware Player allows user-assisted attackers to cause a denial of service (unrecoverable application failure) via a long value of the ide1:0.fileName parameter in the .vmx file of a virtual machine. NOTE: third parties have disputed this issue, saying tha…

vmware player
0.01EPSS
CVE-2023-20872
High 8.8

VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation.

vmware fusion · vmware workstation
0.01EPSS
CVE-2021-22060
Medium 4.3

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against addi…

oracle communications_cloud_native_core_console · oracle communications_cloud_native_core_service_communication_proxy · vmware spring_framework
0.01EPSS
CVE-2017-4917
Critical 9.8

VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained.

vmware vsphere_data_protection
0.01EPSS
CVE-2015-2344
Medium 5.4

Cross-site scripting (XSS) vulnerability in VMware vRealize Automation 6.x before 6.2.4 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

vmware vrealize_automation
0.01EPSS
CVE-2020-3982
High 7.7

VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds write vulnerability due to a time-of-check time-of-use issue in ACPI de…

vmware cloud_foundation · vmware esxi · vmware fusion · vmware workstation · and 1 more
0.01EPSS
CVE-2018-11076
Medium 6.5

Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0 and 7.4.1 and Dell EMC Integrated Data Protection Appliance (IDPA) 2.0 are affected by an information exposure vulnerability. Avamar Java management console's SSL/TLS private key may be leaked i…

dell emc_avamar · dell emc_integrated_data_protection_appliance · vmware vsphere_data_protection
0.01EPSS
CVE-2022-22961
Medium 5.3

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Successful exploitation …

vmware cloud_foundation · vmware identity_manager · vmware vrealize_automation · vmware vrealize_suite_lifecycle_manager · and 1 more
0.01EPSS
CVE-2017-4951
High 8.8

VMware AirWatch Console (9.2.x before 9.2.2 and 9.1.x before 9.1.5) contains a Cross Site Request Forgery vulnerability when accessing the App Catalog. An attacker may exploit this issue by tricking users into installing a malicious application on their device…

vmware airwatch
0.01EPSS
CVE-2016-2075
Medium 5.4

Cross-site scripting (XSS) vulnerability in VMware vRealize Business Advanced and Enterprise 8.x before 8.2.5 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

vmware vrealize_business_advanced_and_enterprise
0.01EPSS
CVE-2007-4497
Medium 5.5

Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server be…

canonical ubuntu_linux · vmware ace · vmware player · vmware server · and 1 more
0.01EPSS
CVE-2015-1044
Low 3.3

vmware-authd (aka the Authorization process) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allows attackers to cause a host OS denial of service via unspecified vectors.

vmware esxi · vmware player · vmware workstation
0.01EPSS
CVE-2022-31689
Critical 9.8

VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token.

vmware workspace_one_assist
0.01EPSS
CVE-2022-31687
Critical 9.8

VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.

vmware workspace_one_assist
0.01EPSS
CVE-2022-38650
Critical 10.0

A remote unauthenticated insecure deserialization vulnerability exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to run arbitrary code or malware within Hyperic Server and the host operating system with the pr…

vmware hyperic_server
0.01EPSS
CVE-2021-22113
Medium 5.3

Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sensitive Headers” restriction when executing requests with specially constructed URLs. Applications that use Spri…

vmware spring_cloud_netflix_zuul
0.01EPSS
CVE-2012-1515
High 8.3

VMware ESXi 3.5, 4.0, and 4.1 and ESX 3.5, 4.0, and 4.1 do not properly implement port-based I/O operations, which allows guest OS users to gain guest OS privileges by overwriting memory locations in a read-only memory block associated with the Virtual DOS Mac…

vmware esx · vmware esxi
0.01EPSS
CVE-2021-22025
High 7.5

The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can add new nodes to exis…

vmware cloud_foundation · vmware vrealize_operations_manager · vmware vrealize_suite_lifecycle_manager
0.01EPSS
CVE-2022-31675
High 7.5

VMware vRealize Operations contains an authentication bypass vulnerability. An unauthenticated malicious actor with network access may be able to create a user with administrative privileges.

vmware vrealize_operations
0.01EPSS
CVE-2020-3981
Medium 5.8

VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds read vulnerability due to a time-of-check time-of-use issue in ACPI dev…

vmware cloud_foundation · vmware esxi · vmware fusion · vmware workstation
0.01EPSS
CVE-2020-3940
Medium 5.9

VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability.

vmware workspace_one_boxer · vmware workspace_one_content · vmware workspace_one_intelligent_hub · vmware workspace_one_notebook · and 5 more
0.01EPSS
CVE-2022-22977
High 7.1

VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative local user privileges in the Windows guest OS, where VMware Tools is installed, may exploit this issue leading to…

vmware tools
0.01EPSS