imPC@ndo IT

VMware vulnerabilities

956 CVE

CVE-2021-21990
Medium 6.1

VMware Workspace one UEM console (2102 prior to 21.2.0.8, 2101 prior to 21.1.0.14, 2011 prior to 20.11.0.27, 2010 prior to 20.10.0.16,2008 prior to 20.8.0.28, 2007 prior to 20.7.0.14,2006 prior to 20.6.0.19, 2005 prior to 20.5.0.46, 2004 prior to 20.4.0.21, 20…

vmware workspace_one_unified_endpoint_management
0.01EPSS
CVE-2019-11291
Medium 4.8

Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input.…

broadcom rabbitmq_server · redhat openstack · vmware rabbitmq
0.01EPSS
CVE-2022-31708
Medium 4.9

vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.4.

vmware vrealize_operations
0.01EPSS
CVE-2019-5518
Medium 6.8

VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 10.1.6) contain an out-of-bounds read/write vulnerability in t…

vmware esxi · vmware fusion · vmware workstation
0.01EPSS
CVE-2015-1043
Low 3.3

The Host Guest File System (HGFS) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, and VMware Fusion 6.x before 6.0.5 and 7.x before 7.0.1 allows guest OS users to cause a guest OS denial of service via unspecified vectors.

vmware fusion · vmware player · vmware workstation
0.01EPSS
CVE-2012-1666
Medium 6.9

Untrusted search path vulnerability in VMware Tools in VMware Workstation before 8.0.4, VMware Player before 4.0.4, VMware Fusion before 4.1.2, VMware View before 5.1, and VMware ESX 4.1 before U3 and 5.0 before P03 allows local users to gain privileges via a …

vmware esx · vmware fusion · vmware player · vmware view · and 1 more
0.01EPSS
CVE-2022-22939
Medium 4.9

VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text within multiple log files on the SDDC Manager. A malicious actor with root access on VMware Cloud Foundation SDDC Manager may be able to view c…

vmware cloud_foundation
0.01EPSS
CVE-2022-38652
Critical 9.9

A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authenticated user to run arbitrary code or malware within a Hyperic Agent instance and its host operating system with…

vmware hyperic_agent
0.01EPSS
CVE-2017-4926
Medium 5.4

VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which will get executed when other VC users access the page.

vmware vcenter_server
0.01EPSS
CVE-2022-23825
Medium 6.5

Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.

amd a10-9600p_firmware · amd a10-9630p_firmware · amd a12-9700p_firmware · amd a12-9730p_firmware · and 122 more
0.01EPSS
CVE-2020-3954
Medium 6.1

Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.

vmware vrealize_log_insight
0.01EPSS
CVE-2016-2081
Medium 6.1

Cross-site scripting (XSS) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

vmware vrealize_log_insight
0.01EPSS
CVE-2015-6931
Medium 6.1

Cross-site scripting (XSS) vulnerability in the vSphere Web Client in VMware vCenter Server 5.0 before U3g, 5.1 before U3d, and 5.5 before U2d allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

vmware vcenter_server
0.01EPSS
CVE-2022-38651
Critical 9.8

A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some authentication requirements when issuing requests to Hyperic Server. NOTE: This vulnerability only affects pro…

vmware hyperic_server
0.01EPSS
CVE-2015-5258
High 8.8

Cross-site request forgery (CSRF) vulnerability in springframework-social before 1.1.3.

fedoraproject fedora · vmware spring_social
0.01EPSS
CVE-2022-22953
Medium 6.5

VMware HCX update addresses an information disclosure vulnerability. A malicious actor with network user access to the VMware HCX appliance may be able to gain access to sensitive information.

vmware vmware_hcx
0.01EPSS
CVE-2015-2337
Medium 5.8

TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, w…

vmware fusion · vmware horizon_client · vmware horizon_view_client · vmware player · and 1 more
0.01EPSS
CVE-2015-2336
Medium 5.8

TPView.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, …

vmware fusion · vmware horizon_client · vmware horizon_view_client · vmware player · and 1 more
0.01EPSS
CVE-2023-31131
High 7.4

Greenplum Database (GPDB) is an open source data warehouse based on PostgreSQL. In versions prior to 6.22.3 Greenplum Database used an unsafe methods to extract tar files within GPPKGs. greenplum-db is vulnerable to path traversal leading to arbitrary file wri…

vmware greenplum_database
0.01EPSS
CVE-2021-22047
Medium 5.3

In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that c…

vmware spring_data_rest
0.01EPSS
CVE-2015-6932
Medium 5.8

VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

vmware vcenter_server
0.01EPSS
CVE-2026-40982
Critical 9.1

Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack. Sprin…

vmware spring_cloud_config
0.01EPSS
CVE-2020-5425
High 7.9

Single Sign-On for Vmware Tanzu all versions prior to 1.11.3 ,1.12.x versions prior to 1.12.4 and 1.13.x prior to 1.13.1 are vulnerable to user impersonation attack.If two users are logged in to the SSO operator dashboard at the same time, with the same userna…

vmware single_sign-on_for_tanzu
0.01EPSS
CVE-2021-22040
Medium 6.7

VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process runn…

vmware cloud_foundation · vmware esxi · vmware fusion · vmware workstation_player · and 1 more
0.01EPSS
CVE-2020-5426
Critical 9.8

Scheduler for TAS prior to version 1.4.0 was permitting plaintext transmission of UAA client token by sending it over a non-TLS connection. This also depended on the configuration of the MySQL server which is used to cache a UAA client token used by the servic…

vmware pivotal_scheduler
0.01EPSS