Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2017-4912 VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in TrueTyp… Horizon View Mitigation only Fix from $1,9502017-06-08 HIGH 7.8 CVE-2017-4913 VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain an integer-overflow vulnerability in the True Type Fon… Horizon View Mitigation only Fix from $1,9502017-06-08 HIGH 8.8 CVE-2017-4898 VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a… Workstation Player Patch available Fix from $1,9502017-06-07 HIGH 8.8 CVE-2017-4902 VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fus… Workstation Player 8.5.6 / 12.5.5+ Fix from $1,9502017-06-07 HIGH 8.8 CVE-2017-4903 VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 with… Workstation Player 8.5.6 / 12.5.5+ Fix from $1,9502017-06-07 HIGH 8.8 CVE-2017-4904 The XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-20… Fusion 8.5.6 / 12.5.5+ Fix from $1,9502017-06-07 MEDIUM 5.5 CVE-2017-4900 VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SVGA driver. Successful exploit… Workstation Player Patch available Fix from $1,6002017-06-07 MEDIUM 5.5 CVE-2017-4905 VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 with… Fusion 8.5.6 / 12.5.5+ Fix from $1,6002017-06-07 CRITICAL 9.8 CVE-2017-4914EPSS 9% VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote a… Vsphere Data Protection Patch available Fix from $2,3002017-06-07 CRITICAL 9.8 CVE-2017-4917 VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue… Vsphere Data Protection Patch available Fix from $2,3002017-06-07 MEDIUM 5.5 CVE-2017-4897 VMware Horizon DaaS before 7.0.0 contains a vulnerability that exists due to insufficient validation of data. An attacker may exploit this issue by t… Horizon Daas after 6.1.6 Fix from $1,6002017-05-31 CRITICAL 9.8 CVE-2014-3527 When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authent… Spring Security Mitigation only Fix from $2,3002017-05-25 CRITICAL 9.6 CVE-2015-5211 Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflect… Spring Framework No fix yet Fix from $2,3002017-05-25 HIGH 8.8 CVE-2014-0225 When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not d… Spring Framework Mitigation only Fix from $1,9502017-05-25 HIGH 7.5 CVE-2016-5007 Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for m… Spring Framework Mitigation only Fix from $1,9502017-05-25 HIGH 7.3 CVE-2014-0097 The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows… Spring Security Mitigation only Fix from $1,9502017-05-25 HIGH 7.8 CVE-2017-4915EPSS 5% VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation o… Workstation Player Patch available Fix from $1,9502017-05-22 MEDIUM 6.5 CVE-2017-4916 VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Successful exploitation of this iss… Workstation Player Patch available Fix from $1,6002017-05-22 HIGH 8.8 CVE-2017-4895 Airwatch Agent for Android contains a vulnerability that may allow a device to bypass root detection. Successful exploitation of this issue may resul… Airwatch Agent Patch available Fix from $1,9502017-05-10 HIGH 7.5 CVE-2016-9879 An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. Spring Security does not consider URL p… Spring Security Mitigation only Fix from $1,9502017-01-06 CRITICAL 10.0 CVE-2016-7457 VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to gain privileges, or halt and remove virtual machines, vi… Vrealize Operations Mitigation only Fix from $2,3002016-12-29 CRITICAL 9.8 CVE-2016-7456EPSS 33% VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which makes it easier for remote attac… Vsphere Data Protection Mitigation only Fix from $2,3002016-12-29 CRITICAL 9.1 CVE-2016-7460 The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attacker… Vrealize Automation Mitigation only Fix from $2,3002016-12-29 HIGH 8.8 CVE-2016-7461 The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion … Fusion Mitigation only Fix from $1,9502016-12-29 HIGH 8.5 CVE-2016-7462 The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files o… Vrealize Operations Mitigation only Fix from $1,9502016-12-29 HIGH 7.8 CVE-2016-7079 The graphic acceleration functions in VMware Tools 9.x and 10.x before 10.0.9 on OS X allow local users to gain privileges or cause a denial of servi… Tools after 10.0.8 Fix from $1,9502016-12-29 HIGH 7.8 CVE-2016-7080 The graphic acceleration functions in VMware Tools 9.x and 10.x before 10.0.9 on OS X allow local users to gain privileges or cause a denial of servi… Tools after 10.0.8 Fix from $1,9502016-12-29 HIGH 7.8 CVE-2016-7081 Multiple heap-based buffer overflows in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when C… Workstation Player Mitigation only Fix from $1,9502016-12-29 HIGH 7.8 CVE-2016-7082 VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is ena… Workstation Player Mitigation only Fix from $1,9502016-12-29 HIGH 7.8 CVE-2016-7083 VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is ena… Workstation Player No fix yet Fix from $1,9502016-12-29