Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Horizon View HIGH 7.8
CVE-2017-4912

VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in TrueTyp…

Mitigation only
Fix from $1,950 2017-06-08
Horizon View HIGH 7.8
CVE-2017-4913

VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain an integer-overflow vulnerability in the True Type Fon…

Mitigation only
Fix from $1,950 2017-06-08
Workstation Player HIGH 8.8
CVE-2017-4898

VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a…

Patch available
Fix from $1,950 2017-06-07
Workstation Player HIGH 8.8
CVE-2017-4902

VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fus…

Fix: 8.5.6 / 12.5.5+
Fix from $1,950 2017-06-07
Workstation Player HIGH 8.8
CVE-2017-4903

VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 with…

Fix: 8.5.6 / 12.5.5+
Fix from $1,950 2017-06-07
Fusion HIGH 8.8
CVE-2017-4904

The XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-20…

Fix: 8.5.6 / 12.5.5+
Fix from $1,950 2017-06-07
Workstation Player MEDIUM 5.5
CVE-2017-4900

VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SVGA driver. Successful exploit…

Patch available
Fix from $1,600 2017-06-07
Fusion MEDIUM 5.5
CVE-2017-4905

VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 with…

Fix: 8.5.6 / 12.5.5+
Fix from $1,600 2017-06-07
Vsphere Data Protection CRITICAL 9.8
CVE-2017-4914EPSS 9%

VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote a…

Patch available
Fix from $2,300 2017-06-07
Vsphere Data Protection CRITICAL 9.8
CVE-2017-4917

VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue…

Patch available
Fix from $2,300 2017-06-07
Horizon Daas MEDIUM 5.5
CVE-2017-4897

VMware Horizon DaaS before 7.0.0 contains a vulnerability that exists due to insufficient validation of data. An attacker may exploit this issue by t…

Fix: after 6.1.6
Fix from $1,600 2017-05-31
Spring Security CRITICAL 9.8
CVE-2014-3527

When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authent…

Mitigation only
Fix from $2,300 2017-05-25
Spring Framework CRITICAL 9.6
CVE-2015-5211

Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflect…

No fix yet
Fix from $2,300 2017-05-25
Spring Framework HIGH 8.8
CVE-2014-0225

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not d…

Mitigation only
Fix from $1,950 2017-05-25
Spring Framework HIGH 7.5
CVE-2016-5007

Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for m…

Mitigation only
Fix from $1,950 2017-05-25
Spring Security HIGH 7.3
CVE-2014-0097

The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows…

Mitigation only
Fix from $1,950 2017-05-25
Workstation Player HIGH 7.8
CVE-2017-4915EPSS 5%

VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation o…

Patch available
Fix from $1,950 2017-05-22
Workstation Player MEDIUM 6.5
CVE-2017-4916

VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Successful exploitation of this iss…

Patch available
Fix from $1,600 2017-05-22
Airwatch Agent HIGH 8.8
CVE-2017-4895

Airwatch Agent for Android contains a vulnerability that may allow a device to bypass root detection. Successful exploitation of this issue may resul…

Patch available
Fix from $1,950 2017-05-10
Spring Security HIGH 7.5
CVE-2016-9879

An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. Spring Security does not consider URL p…

Mitigation only
Fix from $1,950 2017-01-06
Vrealize Operations CRITICAL 10.0
CVE-2016-7457

VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to gain privileges, or halt and remove virtual machines, vi…

Mitigation only
Fix from $2,300 2016-12-29
Vsphere Data Protection CRITICAL 9.8
CVE-2016-7456EPSS 33%

VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which makes it easier for remote attac…

Mitigation only
Fix from $2,300 2016-12-29
Vrealize Automation CRITICAL 9.1
CVE-2016-7460

The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attacker…

Mitigation only
Fix from $2,300 2016-12-29
Fusion HIGH 8.8
CVE-2016-7461

The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion …

Mitigation only
Fix from $1,950 2016-12-29
Vrealize Operations HIGH 8.5
CVE-2016-7462

The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files o…

Mitigation only
Fix from $1,950 2016-12-29
Tools HIGH 7.8
CVE-2016-7079

The graphic acceleration functions in VMware Tools 9.x and 10.x before 10.0.9 on OS X allow local users to gain privileges or cause a denial of servi…

Fix: after 10.0.8
Fix from $1,950 2016-12-29
Tools HIGH 7.8
CVE-2016-7080

The graphic acceleration functions in VMware Tools 9.x and 10.x before 10.0.9 on OS X allow local users to gain privileges or cause a denial of servi…

Fix: after 10.0.8
Fix from $1,950 2016-12-29
Workstation Player HIGH 7.8
CVE-2016-7081

Multiple heap-based buffer overflows in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when C…

Mitigation only
Fix from $1,950 2016-12-29
Workstation Player HIGH 7.8
CVE-2016-7082

VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is ena…

Mitigation only
Fix from $1,950 2016-12-29
Workstation Player HIGH 7.8
CVE-2016-7083

VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is ena…

No fix yet
Fix from $1,950 2016-12-29