Skip to main content

Vendor archive

vmware CVEs

Beta · best-effort

1,014 CVEs tagged to vendor vmware145 Critical, 407 High, 418 Medium, 44 Low, 0 Unrated.

CVE-2017-4945

Published Jan 5, 2018

VMware Workstation (14.x and 12.x) and Fusion (10.x and 8.x) contain a guest access control vulnerability. This issue may allow program execution via Unity on locked Windows VMs.…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-4943

Published Dec 20, 2017

VMware vCenter Server Appliance (vCSA) (6.5 before 6.5 U1d) contains a local privilege escalation vulnerability via the 'showlog' plugin. Successful exploitation of this issue cou…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-4940

Published Dec 20, 2017

The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESXi550-201709102-SG) contains a vulnerability that may allow…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-4942

Published Dec 13, 2017

VMware AirWatch Console (AWC) contains a Broken Access Control vulnerability. Successful exploitation of this issue could result in end-user device details being disclosed to an u…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-4920

Published Dec 5, 2017

The implementation of the OSPF protocol in VMware NSX-V Edge 6.2.x prior to 6.2.8 and NSX-V Edge 6.3.x prior to 6.3.3 doesn't correctly handle the link-state advertisement (LSA).…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-4995

Published Nov 27, 2017

An issue was discovered in Pivotal Spring Security 4.2.0.RELEASE through 4.2.2.RELEASE, and Spring Security 5.0.0.M1. When configured to enable default typing, Jackson contained a…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-4939

Published Nov 17, 2017

VMware Workstation (12.x before 12.5.8) installer contains a DLL hijacking issue that exists due to some DLL files loaded by the application improperly. This issue may allow an at…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-4938

Published Nov 17, 2017

VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL pointer dereference vulnerability. Successful exploitation of this issue may allow a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-4937

Published Nov 17, 2017

VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulnerability in JPEG2000 parser in the TPView.dll. On…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-4936

Published Nov 17, 2017

VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulnerability in JPEG2000 parser in the TPView.dll. On…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-4935

Published Nov 17, 2017

VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds write vulnerability in JPEG2000 parser in the TPView.dll. O…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-4934

Published Nov 17, 2017

VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a heap buffer-overflow vulnerability in VMNAT device. This issue may allow a guest to execute code on…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-4929

Published Nov 17, 2017

VMware NSX Edge (6.2.x before 6.2.9 and 6.3.x before 6.3.5) contains a moderate Cross-Site Scripting (XSS) issue which may lead to information disclosure.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-4928

Published Nov 17, 2017

The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRLF injection issues due to impr…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-4927

Published Nov 17, 2017

VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP network packets which may allow for remote denial of service.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-4932

Published Nov 16, 2017

VMware AirWatch Launcher for Android prior to 3.2.2 contains a vulnerability that could allow an escalation of privilege from the launcher UI context menu to native UI functionali…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-4931

Published Nov 16, 2017

VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add malicious data to an enrolled device's log files. Successful…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 651-675 of 1,014 CVEsPage 27 of 41