Skip to main content

Vendor archive

vmware CVEs

Beta · best-effort

1,014 CVEs tagged to vendor vmware145 Critical, 407 High, 418 Medium, 44 Low, 0 Unrated.

CVE-2014-3790

Published Jun 1, 2014

Ruby vSphere Console (RVC) in VMware vCenter Server Appliance allows remote authenticated users to execute arbitrary commands as root by escaping from a chroot jail.

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-2384

Published Apr 15, 2014

vmx86.sys in VMware Workstation 10.0.1 build 1379776 and VMware Player 6.0.1 build 1379776 on Windows might allow local users to cause a denial of service (read access violation a…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1210

Published Apr 11, 2014

VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1209

Published Apr 11, 2014

VMware vSphere Client 4.0, 4.1, 5.0 before Update 3, and 5.1 before Update 2 does not properly validate updates to Client files, which allows remote attackers to trigger the downl…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-1211

Published Jan 17, 2014

Cross-site request forgery (CSRF) vulnerability in VMware vCloud Director 5.1.x before 5.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1207

Published Jan 17, 2014

VMware ESXi 4.0 through 5.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (NULL pointer dereference) by intercepting and modifying Network File Copy (NFC…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5973

Published Dec 23, 2013

VMware ESXi 4.0 through 5.5 and ESX 4.0 and 4.1 allow local users to read or modify arbitrary files by leveraging the Virtual Machine Power User or Resource Pool Administrator rol…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5972

Published Nov 18, 2013

VMware Workstation 9.x before 9.0.3 and VMware Player 5.x before 5.0.3 on Linux do not properly handle shared libraries, which allows host OS users to gain host OS privileges via…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6366

Published Nov 4, 2013

The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary code via a Runtime.getRuntime().exec call.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5971

Published Oct 21, 2013

Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web sessions and gain privileges via…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5970

Published Oct 21, 2013

hostd-vmdb in VMware ESXi 4.0 through 5.0 and ESX 4.0 through 4.1 allows remote attackers to cause a denial of service (hostd-vmdb service outage) by modifying management traffic.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3658

Published Sep 10, 2013

Directory traversal vulnerability in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to delete arbitrary host OS files via unspecified vectors.

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort
Showing 776-800 of 1,014 CVEsPage 32 of 41