Vulnerability index

Browse CVEs

139 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Workstation Player HIGH 7.8
CVE-2016-7085

Untrusted search path vulnerability in the installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on…

Mitigation only
Fix from $1,950 2016-12-29
Workstation Player HIGH 7.8
CVE-2016-7086

The installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows allows local users to gain pri…

Mitigation only
Fix from $1,950 2016-12-29
Vsphere Client MEDIUM 5.8
CVE-2016-7458

VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document c…

Mitigation only
Fix from $1,600 2016-12-29
Fusion MEDIUM 5.5
CVE-2016-5329

VMware Fusion 8.x before 8.5 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and …

Mitigation only
Fix from $1,600 2016-12-29
Spring Framework MEDIUM 5.5
CVE-2015-3192

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which …

Mitigation only
Fix from $1,600 2016-07-12
Vcenter Server MEDIUM 6.1
CVE-2016-2078

Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5.1 before update 3d, 5.5 before update 3d, and 6.0 before update…

No fix yet
Fix from $1,600 2016-06-08
Player CRITICAL 9.8
CVE-2016-2077

VMware Workstation 11.x before 11.1.3 and VMware Player 7.x before 7.1.3 on Windows incorrectly access an executable file, which allows host OS users…

Mitigation only
Fix from $2,300 2016-05-18
Vrealize Business Advanced And Enterprise MEDIUM 5.4
CVE-2016-2075

Cross-site scripting (XSS) vulnerability in VMware vRealize Business Advanced and Enterprise 8.x before 8.2.5 on Linux allows remote authenticated us…

Mitigation only
Fix from $1,600 2016-03-16
Vrealize Automation MEDIUM 5.4
CVE-2015-2344

Cross-site scripting (XSS) vulnerability in VMware vRealize Automation 6.x before 6.2.4 on Linux allows remote authenticated users to inject arbitrar…

Mitigation only
Fix from $1,600 2016-03-16
Vcenter Orchestrator HIGH 7.3
CVE-2015-6934EPSS 5%

Serialized-object interfaces in VMware vRealize Orchestrator 6.x, vCenter Orchestrator 5.x, vRealize Operations 6.x, vCenter Operations 5.x, and vCen…

Mitigation only
Fix from $1,950 2015-12-21
Vcenter Server MEDIUM 5.8
CVE-2015-6932

VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attack…

Mitigation only
Fix from $1,600 2015-09-18
Fusion MEDIUM 5.8
CVE-2015-2337

TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Cl…

Mitigation only
Fix from $1,600 2015-06-13
Spring Framework MEDIUM 5.0
CVE-2015-0201

The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messag…

Mitigation only
Fix from $1,600 2015-03-10
Vcloud Automation Center HIGH 9.0
CVE-2014-8373

The VMware Remote Console (VMRC) function in VMware vCloud Automation Center (vCAC) 6.0.1 through 6.1.1 allows remote authenticated users to gain pri…

No fix yet
Fix from $1,950 2014-12-11
Vcenter Server Appliance HIGH 9.0
CVE-2014-3790

Ruby vSphere Console (RVC) in VMware vCenter Server Appliance allows remote authenticated users to execute arbitrary commands as root by escaping fro…

Mitigation only
Fix from $1,950 2014-06-01
Fusion MEDIUM 5.8
CVE-2014-3793

VMware Tools in VMware Workstation 10.x before 10.0.2, VMware Player 6.x before 6.0.2, VMware Fusion 6.x before 6.0.3, and VMware ESXi 5.0 through 5.…

No fix yet
Fix from $1,600 2014-05-31
Vsphere Client HIGH 9.3
CVE-2014-1209

VMware vSphere Client 4.0, 4.1, 5.0 before Update 3, and 5.1 before Update 2 does not properly validate updates to Client files, which allows remote …

Mitigation only
Fix from $1,950 2014-04-11
Vsphere Client MEDIUM 5.8
CVE-2014-1210

VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which allows man-in-the-middle attac…

Mitigation only
Fix from $1,600 2014-04-11
Vcloud Director MEDIUM 6.8
CVE-2014-1211

Cross-site request forgery (CSRF) vulnerability in VMware vCloud Director 5.1.x before 5.1.3 allows remote attackers to hijack the authentication of …

Mitigation only
Fix from $1,600 2014-01-17
Esxi HIGH 7.9
CVE-2013-3519

lgtosync.sys in VMware Workstation 9.x before 9.0.3, VMware Player 5.x before 5.0.3, VMware Fusion 5.x before 5.0.4, VMware ESXi 4.0 through 5.1, and…

Mitigation only
Fix from $1,950 2013-12-04
Hyperic Hq MEDIUM 6.5
CVE-2013-6366EPSS 7%

The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary code via a Runtime.getRuntime().…

No fix yet
Fix from $1,600 2013-11-04
Esx HIGH 7.1
CVE-2013-5970

hostd-vmdb in VMware ESXi 4.0 through 5.0 and ESX 4.0 through 4.1 allows remote attackers to cause a denial of service (hostd-vmdb service outage) by…

Mitigation only
Fix from $1,950 2013-10-21
Esx HIGH 9.4
CVE-2013-3658

Directory traversal vulnerability in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to delete arbitrary host OS files via …

Mitigation only
Fix from $1,950 2013-09-10
Esx HIGH 7.5
CVE-2013-3657

Buffer overflow in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to execute arbitrary code or cause a denial of service v…

Mitigation only
Fix from $1,950 2013-09-10
Workstation MEDIUM 6.9
CVE-2013-1662

vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host…

Mitigation only
Fix from $1,600 2013-08-24
Vcenter Server Appliance HIGH 9.0
CVE-2013-3079

VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to execute arbitrary programs with root privileges by le…

Mitigation only
Fix from $1,950 2013-05-01
Vcenter Server Appliance HIGH 9.0
CVE-2013-3080

VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to create or overwrite arbitrary files, and consequently…

Mitigation only
Fix from $1,950 2013-05-01
Vcenter Server HIGH 7.6
CVE-2013-1659

VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 d…

Mitigation only
Fix from $1,950 2013-02-22
Vcenter Server HIGH 10.0
CVE-2013-1405

VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 bef…

Mitigation only
Fix from $1,950 2013-02-15
Workstation HIGH 7.2
CVE-2013-1406

The Virtual Machine Communication Interface (VMCI) implementation in vmci.sys in VMware Workstation 8.x before 8.0.5 and 9.x before 9.0.1 on Windows,…

Mitigation only
Fix from $1,950 2013-02-11