Skip to main content

Vendor archive

vmware CVEs

Beta · best-effort

1,014 CVEs tagged to vendor vmware145 Critical, 407 High, 418 Medium, 44 Low, 0 Unrated.

CVE-2018-6962

Published May 22, 2018

VMware Fusion (10.x before 10.1.2) contains a signature bypass vulnerability which may lead to a local privilege escalation.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-1263

Published May 15, 2018

Addresses partial fix in CVE-2018-1261. Pivotal spring-integration-zip, versions prior to 1.0.2, exposes an arbitrary file write vulnerability, that can be achieved using a specia…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1261

Published May 11, 2018

Spring-integration-zip versions prior to 1.0.1 exposes an arbitrary file write vulnerability, which can be achieved using a specially crafted zip archive (affects other archives a…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1256

Published May 7, 2018

Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers that are not bound to the SSO service. In PCF deployments wit…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-4952

Published May 2, 2018

VMware Xenon 1.x, prior to 1.5.4-CR7_1, 1.5.7_7, 1.5.4-CR6_2, 1.3.7-CR1_2, 1.1.0-CR0-3, 1.1.0-CR3_1,1.4.2-CR4_1, and 1.5.4_8, contains an authentication bypass vulnerability due t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6960

Published Apr 20, 2018

VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow an attacker to bypass two-factor authentication. Note: In order to exploit thi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6959

Published Apr 13, 2018

VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs. Exploitation of this issue may lead to the hijacking of a valid vRA user's…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-6958

Published Apr 13, 2018

VMware vRealize Automation (vRA) prior to 7.3.1 contains a vulnerability that may allow for a DOM-based cross-site scripting (XSS) attack. Exploitation of this issue may lead to t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0898

Published Mar 29, 2018

MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the sys…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1196

Published Mar 19, 2018

Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d linux service. The script included with Spring Boot 1.5.9 and…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-4951

Published Jan 29, 2018

VMware AirWatch Console (9.2.x before 9.2.2 and 9.1.x before 9.1.5) contains a Cross Site Request Forgery vulnerability when accessing the App Catalog. An attacker may exploit thi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 626-650 of 1,014 CVEsPage 26 of 41