Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Workstation Player HIGH 7.8
CVE-2016-7084

tpview.dll in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual p…

No fix yet
Fix from $1,950 2016-12-29
Workstation Player HIGH 7.8
CVE-2016-7085

Untrusted search path vulnerability in the installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on…

Mitigation only
Fix from $1,950 2016-12-29
Workstation Player HIGH 7.8
CVE-2016-7086

The installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows allows local users to gain pri…

Mitigation only
Fix from $1,950 2016-12-29
Vcenter Server HIGH 7.7
CVE-2016-7459

VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distribu…

Patch available
Fix from $1,950 2016-12-29
Spring Framework HIGH 7.5
CVE-2016-9878EPSS 6%

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet …

Fix: after 3.2.0
Fix from $1,950 2016-12-29
Vsphere Client MEDIUM 5.8
CVE-2016-7458

VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document c…

Mitigation only
Fix from $1,600 2016-12-29
Tools MEDIUM 5.5
CVE-2016-5328

VMware Tools 9.x and 10.x before 10.1.0 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory add…

Fix: after 10.0.8
Fix from $1,600 2016-12-29
Fusion MEDIUM 5.5
CVE-2016-5329

VMware Fusion 8.x before 8.5 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and …

Mitigation only
Fix from $1,600 2016-12-29
Esxi MEDIUM 5.4
CVE-2016-7463

Cross-site scripting (XSS) vulnerability in the Host Client in VMware vSphere Hypervisor (aka ESXi) 5.5 and 6.0 allows remote authenticated users to …

Patch available
Fix from $1,600 2016-12-29
Identity Manager MEDIUM 5.3
CVE-2016-5334

VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF fil…

Fix: 2.7.1 / 7.2.0+
Fix from $1,600 2016-12-29
Horizon View MEDIUM 5.3
CVE-2016-7087

Directory traversal vulnerability in the Connection Server in VMware Horizon View 5.x before 5.3.7, 6.x before 6.2.3, and 7.x before 7.0.1 allows rem…

Patch available
Fix from $1,600 2016-12-29
Vrealize Automation CRITICAL 9.8
CVE-2016-5336

VMware vRealize Automation 7.0.x before 7.1 allows remote attackers to execute arbitrary code via unspecified vectors.

Patch available
Fix from $2,300 2016-08-31
Identity Manager HIGH 7.8
CVE-2016-5335

VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to obtain root access via unspecified vectors.

Fix: 2.7 / 7.1+
Fix from $1,950 2016-08-31
Photon Os CRITICAL 9.8
CVE-2016-5333

VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH acces…

Fix: after 1.0
Fix from $2,300 2016-08-31
Vrealize Log Insight MEDIUM 5.3
CVE-2016-5332

Directory traversal vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.6.0 allows remote attackers to read arbitrary files via unspeci…

Patch available
Fix from $1,600 2016-08-31
Vcenter Server MEDIUM 6.1
CVE-2016-5331

CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct…

Fix: after 6.0
Fix from $1,600 2016-08-08
Workstation Player HIGH 7.8
CVE-2016-5330EPSS 18%

Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware Workstatio…

Fix: 8.1.1 / 12.1.1+
Fix from $1,950 2016-08-08
Spring Framework MEDIUM 5.5
CVE-2015-3192

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which …

Mitigation only
Fix from $1,600 2016-07-12
Vrealize Log Insight HIGH 8.8
CVE-2016-2082

Cross-site request forgery (CSRF) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to hijack the authent…

Patch available
Fix from $1,950 2016-07-03
Vrealize Log Insight MEDIUM 6.1
CVE-2016-2081

Cross-site scripting (XSS) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to inject arbitrary web scri…

Patch available
Fix from $1,600 2016-07-03
Nsx Edge MEDIUM 5.9
CVE-2016-2079

VMware NSX Edge 6.1 before 6.1.7 and 6.2 before 6.2.3 and vCNS Edge 5.5 before 5.5.4.3, when the SSL-VPN feature is configured, allow remote attacker…

Patch available
Fix from $1,600 2016-07-03
Vcenter Server MEDIUM 6.1
CVE-2015-6931

Cross-site scripting (XSS) vulnerability in the vSphere Web Client in VMware vCenter Server 5.0 before U3g, 5.1 before U3d, and 5.5 before U2d allows…

Patch available
Fix from $1,600 2016-07-03
Vcenter Server MEDIUM 6.1
CVE-2016-2078

Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5.1 before update 3d, 5.5 before update 3d, and 6.0 before update…

No fix yet
Fix from $1,600 2016-06-08
Player CRITICAL 9.8
CVE-2016-2077

VMware Workstation 11.x before 11.1.3 and VMware Player 7.x before 7.1.3 on Windows incorrectly access an executable file, which allows host OS users…

Mitigation only
Fix from $2,300 2016-05-18
Vcenter Server HIGH 7.6
CVE-2016-2076

Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Iden…

Fix: after 6.0
Fix from $1,950 2016-04-15
Vrealize Business Advanced And Enterprise MEDIUM 5.4
CVE-2016-2075

Cross-site scripting (XSS) vulnerability in VMware vRealize Business Advanced and Enterprise 8.x before 8.2.5 on Linux allows remote authenticated us…

Mitigation only
Fix from $1,600 2016-03-16
Vrealize Automation MEDIUM 5.4
CVE-2015-2344

Cross-site scripting (XSS) vulnerability in VMware vRealize Automation 6.x before 6.2.4 on Linux allows remote authenticated users to inject arbitrar…

Mitigation only
Fix from $1,600 2016-03-16
Player MEDIUM 6.3
CVE-2015-6933

The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2, VMware Fusion 7.x…

Patch available
Fix from $1,600 2016-01-09
Vcenter Orchestrator HIGH 7.3
CVE-2015-6934EPSS 5%

Serialized-object interfaces in VMware vRealize Orchestrator 6.x, vCenter Orchestrator 5.x, vRealize Operations 6.x, vCenter Operations 5.x, and vCen…

Mitigation only
Fix from $1,950 2015-12-21
Vcenter Server HIGH 10.0
CVE-2015-2342EPSS 89%

The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBean…

Patch available
Fix from $1,950 2015-10-12