Skip to main content

Vendor archive

vmware CVEs

Beta · best-effort

1,014 CVEs tagged to vendor vmware145 Critical, 407 High, 418 Medium, 44 Low, 0 Unrated.

CVE-2017-4930

Published Nov 16, 2017

VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add a malicious URL to an enrolled device's 'Links' page. Success…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-4926

Published Sep 15, 2017

VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-4924

Published Sep 15, 2017

VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusion (8.x before 8.5.8) contain an out-of-bounds write vulnerability in SVGA devi…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-4923

Published Aug 1, 2017

VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtained when using the vCenter Serv…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-4922

Published Aug 1, 2017

VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script using world writable directories as temporary storage for cr…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-4921

Published Aug 1, 2017

VMware vCenter Server (6.5 prior to 6.5 U1) contains an insecure library loading issue that occurs due to the use of LD_LIBRARY_PATH variable in an unsafe manner. Successful explo…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-4919

Published Jul 28, 2017

VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating Systems without the need to authenti…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-5191

Published Jul 28, 2017

VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. Successful exploitation of this issue may resu…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-4918

Published Jun 8, 2017

VMware Horizon View Client (2.x, 3.x and 4.x prior to 4.5.0) contains a command injection vulnerability in the service startup script. Successful exploitation of this issue may al…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-4913

Published Jun 8, 2017

VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain an integer-overflow vulnerability in the True Type Font parser in the TPView.dll. On…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-4912

Published Jun 8, 2017

VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in TrueType Font (TTF) parser in the TPV…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-4911

Published Jun 8, 2017

VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds write vulnerabilities in JPEG2000 parser in the TPView.dll. O…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-4910

Published Jun 8, 2017

VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in JPEG2000 parser in the TPView.dll. On…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-4909

Published Jun 8, 2017

VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain a heap buffer-overflow vulnerability in TrueType Font (TTF) parser in the TPView.dll…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-4908

Published Jun 8, 2017

VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple heap buffer-overflow vulnerabilities in JPEG2000 parser in the TPView.dll.…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-4901

Published Jun 8, 2017

The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may al…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort
Showing 676-700 of 1,014 CVEsPage 28 of 41