imPC@ndo IT

VMware vulnerabilities

956 CVE

CVE-2010-2942
Medium 5.5

The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information …

avaya aura_communication_manager · avaya aura_presence_services · avaya aura_session_manager · avaya aura_system_manager · and 9 more
0.00EPSS
CVE-2024-22256
Medium 4.3

VMware Cloud Director contains a partial information disclosure vulnerability. A malicious actor can potentially gather information about organization names based on the behavior of the instance.

vmware cloud_director
0.00EPSS
CVE-2016-7085
High 7.8

Untrusted search path vulnerability in the installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.

vmware workstation_player · vmware workstation_pro
0.00EPSS
CVE-2018-6971
High 7.8

VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disclosure vulnerability due to insecure logging of credentials in the vmmsi.log file when an account other than the currently logged on user is specified during installation (includin…

vmware horizon_view_agents
0.00EPSS
CVE-2009-3080
High 7.2

Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse opensuse · and 9 more
0.00EPSS
CVE-2018-6962
High 7.8

VMware Fusion (10.x before 10.1.2) contains a signature bypass vulnerability which may lead to a local privilege escalation.

vmware fusion
0.00EPSS
CVE-2012-1508
High 7.2

The XPDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.

vmware esx · vmware esxi · vmware view
0.00EPSS
CVE-2010-2798
High 7.8

The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer dereference and …

avaya aura_communication_manager · avaya aura_presence_services · avaya aura_session_manager · avaya aura_system_manager · and 11 more
0.00EPSS
CVE-2022-31655
Medium 5.4

VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in alerts.

vmware vrealize_log_insight
0.00EPSS
CVE-2022-31654
Medium 5.4

VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in configurations.

vmware vrealize_log_insight
0.00EPSS
CVE-2026-22720
High 8.0

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations.  To remediate CVE-2026-22720, …

vmware aria_operations · vmware cloud_foundation · vmware telco_cloud_infrastructure · vmware telco_cloud_platform
0.00EPSS
CVE-2013-5972
High 7.2

VMware Workstation 9.x before 9.0.3 and VMware Player 5.x before 5.0.3 on Linux do not properly handle shared libraries, which allows host OS users to gain host OS privileges via unspecified vectors.

vmware player · vmware workstation
0.00EPSS
CVE-2017-4903
High 8.8

VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior…

vmware esxi · vmware fusion · vmware fusion_pro · vmware workstation_player · and 1 more
0.00EPSS
CVE-2012-4897
Medium 6.9

Untrusted search path vulnerability in the installer in VMware Movie Decoder before 9.0 allows local users to gain privileges via a Trojan horse executable file in the installer directory.

vmware movie_decoder
0.00EPSS
CVE-2017-4948
High 7.1

VMware Workstation (14.x before 14.1.0 and 12.x) and Horizon View Client (4.x before 4.7.0) contain an out-of-bounds read vulnerability in TPView.dll. On Workstation, this issue in conjunction with other bugs may allow a guest to leak information from host or …

vmware horizon_view · vmware workstation
0.00EPSS
CVE-2024-38833
Medium 6.8

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.

vmware aria_operations · vmware cloud_foundation
0.00EPSS
CVE-2008-4915
Medium 6.9

The CPU hardware emulation in VMware Workstation 6.0.5 and earlier and 5.5.8 and earlier; Player 2.0.x through 2.0.5 and 1.0.x through 1.0.8; ACE 2.0.x through 2.0.5 and earlier, and 1.0.x through 1.0.7; Server 1.0.x through 1.0.7; ESX 2.5.4 through 3.5; and E…

vmware ace · vmware esx · vmware esxi · vmware player · and 2 more
0.00EPSS
CVE-2010-3078
Medium 5.5

The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc4 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an ioctl cal…

canonical ubuntu_linux · linux linux_kernel · opensuse opensuse · suse suse_linux_enterprise_desktop · and 2 more
0.00EPSS
CVE-2009-0034
High 7.8

parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain …

gratisoft sudo · vmware esx
0.00EPSS
CVE-2023-34064
Medium 4.6

Workspace ONE Launcher contains a Privilege Escalation Vulnerability. A malicious actor with physical access to Workspace ONE Launcher could utilize the Edge Panel feature to bypass setup to gain access to sensitive information.

vmware workspace_one_launcher
0.00EPSS
CVE-2014-4199
Medium 6.3

vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to write to arbitrary files via a symlink attack on a file in /tmp.

vmware tools · vmware vm-support · vmware workstation
0.00EPSS
CVE-2008-2099
Medium 6.9

Unspecified vulnerability in VMCI in VMware Workstation 6 before 6.0.4 build 93057, VMware Player 2 before 2.0.4 build 93057, and VMware ACE 2 before 2.0.2 build 93057 on Windows allows guest OS users to execute arbitrary code on the host OS via unspecified ve…

vmware ace_2 · vmware vmware_player_2 · vmware vmware_workstation · vmware workstation
0.00EPSS
CVE-2023-20856
High 8.8

VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of the authenticated victim user.

vmware vrealize_operations
0.00EPSS
CVE-2018-6963
Medium 5.5

VMware Workstation (14.x before 14.1.2) and Fusion (10.x before 10.1.2) contain multiple denial-of-service vulnerabilities that occur due to NULL pointer dereference issues in the RPC handler. Successful exploitation of these issues may allow an attacker with …

vmware fusion · vmware workstation
0.00EPSS
CVE-2023-34059
High 7.4

open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.

debian debian_linux · vmware open_vm_tools
0.00EPSS