Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Single Sign On For Pivotal Cloud Foundry MEDIUM 6.1
CVE-2017-8044

In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3), certain pages allow code to be injected into the…

Mitigation only
Fix from $1,600 2017-11-27
Workstation HIGH 7.8
CVE-2017-4939

VMware Workstation (12.x before 12.5.8) installer contains a DLL hijacking issue that exists due to some DLL files loaded by the application improper…

Mitigation only
Fix from $1,950 2017-11-17
Workstation HIGH 8.8
CVE-2017-4934

VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a heap buffer-overflow vulnerability in VMNAT device. This issue may al…

Patch available
Fix from $1,950 2017-11-17
Workstation HIGH 7.8
CVE-2017-4935

VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds write vulnerability in JPEG20…

Patch available
Fix from $1,950 2017-11-17
Workstation HIGH 7.8
CVE-2017-4936

VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulnerability in JPEG200…

Patch available
Fix from $1,950 2017-11-17
Workstation HIGH 7.8
CVE-2017-4937

VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulnerability in JPEG200…

Patch available
Fix from $1,950 2017-11-17
Vcenter Server HIGH 7.5
CVE-2017-4927

VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP network packets which may allow…

Fix: 6.0_u3c / 6.5_u1+
Fix from $1,950 2017-11-17
Vcenter Server HIGH 7.5
CVE-2017-4928

The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRL…

Patch available
Fix from $1,950 2017-11-17
Workstation MEDIUM 6.5
CVE-2017-4938

VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL pointer dereference vulnerability. Successful exploita…

Patch available
Fix from $1,600 2017-11-17
Nsx Edge MEDIUM 6.1
CVE-2017-4929

VMware NSX Edge (6.2.x before 6.2.9 and 6.3.x before 6.3.5) contains a moderate Cross-Site Scripting (XSS) issue which may lead to information disclo…

Patch available
Fix from $1,600 2017-11-17
Airwatch HIGH 7.8
CVE-2017-4931

VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add malicious data to an enrolled d…

Fix: 9.2.0+
Fix from $1,950 2017-11-16
Airwatch Launcher HIGH 7.8
CVE-2017-4932

VMware AirWatch Launcher for Android prior to 3.2.2 contains a vulnerability that could allow an escalation of privilege from the launcher UI context…

Fix: 3.2.2+
Fix from $1,950 2017-11-16
Airwatch MEDIUM 5.4
CVE-2017-4930

VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add a malicious URL to an enrolled …

Fix: 9.2.0+
Fix from $1,600 2017-11-16
Fusion HIGH 8.8
CVE-2017-4924

VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusion (8.x before 8.5.8) contain an out-of-bounds wr…

Fix: 8.5.8 / 12.5.7+
Fix from $1,950 2017-09-15
Esxi MEDIUM 5.5
CVE-2017-4925

VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Worksta…

Fix: 8.5.4 / 12.5.3+
Fix from $1,600 2017-09-15
Vcenter Server MEDIUM 5.4
CVE-2017-4926

VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user p…

Patch available
Fix from $1,600 2017-09-15
Single Sign On For Pivotal Cloud Foundry MEDIUM 6.5
CVE-2017-8040

In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, an XXE (XML External Entity) attac…

Patch available
Fix from $1,600 2017-09-09
Single Sign On For Pivotal Cloud Foundry MEDIUM 6.1
CVE-2017-8041

In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, a user can execute a XSS attack on…

Patch available
Fix from $1,600 2017-09-09
Vcenter Server CRITICAL 9.8
CVE-2017-4923

VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtain…

Patch available
Fix from $2,300 2017-08-01
Vcenter Server HIGH 8.8
CVE-2017-4921

VMware vCenter Server (6.5 prior to 6.5 U1) contains an insecure library loading issue that occurs due to the use of LD_LIBRARY_PATH variable in an u…

Patch available
Fix from $1,950 2017-08-01
Vcenter Server MEDIUM 6.5
CVE-2017-4922

VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script using world writable directori…

Patch available
Fix from $1,600 2017-08-01
Vcenter Server CRITICAL 9.0
CVE-2017-4919

VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating System…

Mitigation only
Fix from $2,300 2017-07-28
Tools MEDIUM 6.7
CVE-2015-5191

VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. Successful explo…

Fix: after 10.0.8
Fix from $1,600 2017-07-28
Horizon View CRITICAL 9.8
CVE-2017-4918

VMware Horizon View Client (2.x, 3.x and 4.x prior to 4.5.0) contains a command injection vulnerability in the service startup script. Successful exp…

Mitigation only
Fix from $2,300 2017-06-08
Fusion CRITICAL 9.9
CVE-2017-4901EPSS 20%

The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory acc…

Mitigation only
Fix from $2,300 2017-06-08
Horizon View CRITICAL 9.8
CVE-2017-4907

VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.2.4) contain a heap buffer-ov…

Mitigation only
Fix from $2,300 2017-06-08
Horizon View HIGH 7.8
CVE-2017-4908

VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple heap buffer-overflow vulnerabilities in JPEG2…

Mitigation only
Fix from $1,950 2017-06-08
Horizon View HIGH 7.8
CVE-2017-4909

VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain a heap buffer-overflow vulnerability in TrueType Font …

Mitigation only
Fix from $1,950 2017-06-08
Horizon View HIGH 7.8
CVE-2017-4910

VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in JPEG200…

Mitigation only
Fix from $1,950 2017-06-08
Horizon View HIGH 7.8
CVE-2017-4911

VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds write vulnerabilities in JPEG20…

Mitigation only
Fix from $1,950 2017-06-08