Skip to main content

Vendor archive

vmware CVEs

Beta · best-effort

1,014 CVEs tagged to vendor vmware145 Critical, 407 High, 418 Medium, 44 Low, 0 Unrated.

CVE-2013-3657

Published Sep 10, 2013

Buffer overflow in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-1661

Published Sep 4, 2013

VMware ESXi 4.0 through 5.1, and ESX 4.0 and 4.1, does not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to cause a denial of s…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1662

Published Aug 24, 2013

vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host OS privileges via a crafted l…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3520

Published Jun 17, 2013

VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3107

Published May 1, 2013

VMware vCenter Server 5.1 before Update 1, when anonymous LDAP binding for Active Directory is enabled, allows remote attackers to bypass authentication by providing a valid usern…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3080

Published May 1, 2013

VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to create or overwrite arbitrary files, and consequently execute arbitrary code or cau…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-3079

Published May 1, 2013

VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to execute arbitrary programs with root privileges by leveraging Virtual Appliance Man…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6325

Published Dec 21, 2012

VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 does not properly parse XML documents, which allows remote authenticated users to read arbitrary files via unspecified v…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6324

Published Dec 21, 2012

Directory traversal vulnerability in VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 and 5.1 before Patch 1 allows remote authenticated users to read arbitrary files vi…

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-5978

Published Dec 19, 2012

Multiple directory traversal vulnerabilities in the (1) View Connection Server and (2) View Security Server in VMware View 4.x before 4.6.2 and 5.x before 5.1.2 allow remote attac…

CVSS 5.0 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2012-5055

Published Dec 5, 2012

DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, whi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2732

Published Dec 5, 2012

CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 allows remote attackers to inject arbitrary HTT…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2731

Published Dec 5, 2012

Race condition in the RunAsManager mechanism in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 stores the Authentication object in the shared security con…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2899

Published Dec 5, 2012

The monitor perl script in the Sybase database plug-in in SpringSource Hyperic HQ before 4.3 allows local users to obtain the database password by listing the process and its argu…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-5703

Published Nov 20, 2012

The vSphere API in VMware ESXi 4.1 and ESX 4.1 allows remote attackers to cause a denial of service (host daemon crash) via an invalid value in a (1) RetrieveProp or (2) RetrieveP…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-5051

Published Oct 5, 2012

Directory traversal vulnerability in VMware CapacityIQ 1.5.x allows remote attackers to read arbitrary files via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5050

Published Oct 5, 2012

Cross-site scripting (XSS) vulnerability in the server in VMware vCenter Operations (aka vCOps) before 5.0.x allows remote attackers to inject arbitrary web script or HTML via uns…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4897

Published Oct 5, 2012

Untrusted search path vulnerability in the installer in VMware Movie Decoder before 9.0 allows local users to gain privileges via a Trojan horse executable file in the installer d…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 801-825 of 1,014 CVEsPage 33 of 41