Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2016-7084 tpview.dll in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual p… Workstation Player No fix yet Fix from $1,9502016-12-29 HIGH 7.8 CVE-2016-7085 Untrusted search path vulnerability in the installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on… Workstation Player Mitigation only Fix from $1,9502016-12-29 HIGH 7.8 CVE-2016-7086 The installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows allows local users to gain pri… Workstation Player Mitigation only Fix from $1,9502016-12-29 HIGH 7.7 CVE-2016-7459 VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distribu… Vcenter Server Patch available Fix from $1,9502016-12-29 HIGH 7.5 CVE-2016-9878EPSS 6% An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet … Spring Framework after 3.2.0 Fix from $1,9502016-12-29 MEDIUM 5.8 CVE-2016-7458 VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document c… Vsphere Client Mitigation only Fix from $1,6002016-12-29 MEDIUM 5.5 CVE-2016-5328 VMware Tools 9.x and 10.x before 10.1.0 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory add… Tools after 10.0.8 Fix from $1,6002016-12-29 MEDIUM 5.5 CVE-2016-5329 VMware Fusion 8.x before 8.5 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and … Fusion Mitigation only Fix from $1,6002016-12-29 MEDIUM 5.4 CVE-2016-7463 Cross-site scripting (XSS) vulnerability in the Host Client in VMware vSphere Hypervisor (aka ESXi) 5.5 and 6.0 allows remote authenticated users to … Esxi Patch available Fix from $1,6002016-12-29 MEDIUM 5.3 CVE-2016-5334 VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF fil… Identity Manager 2.7.1 / 7.2.0+ Fix from $1,6002016-12-29 MEDIUM 5.3 CVE-2016-7087 Directory traversal vulnerability in the Connection Server in VMware Horizon View 5.x before 5.3.7, 6.x before 6.2.3, and 7.x before 7.0.1 allows rem… Horizon View Patch available Fix from $1,6002016-12-29 CRITICAL 9.8 CVE-2016-5336 VMware vRealize Automation 7.0.x before 7.1 allows remote attackers to execute arbitrary code via unspecified vectors. Vrealize Automation Patch available Fix from $2,3002016-08-31 HIGH 7.8 CVE-2016-5335 VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to obtain root access via unspecified vectors. Identity Manager 2.7 / 7.1+ Fix from $1,9502016-08-31 CRITICAL 9.8 CVE-2016-5333 VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH acces… Photon Os after 1.0 Fix from $2,3002016-08-31 MEDIUM 5.3 CVE-2016-5332 Directory traversal vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.6.0 allows remote attackers to read arbitrary files via unspeci… Vrealize Log Insight Patch available Fix from $1,6002016-08-31 MEDIUM 6.1 CVE-2016-5331 CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct… Vcenter Server after 6.0 Fix from $1,6002016-08-08 HIGH 7.8 CVE-2016-5330EPSS 18% Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware Workstatio… Workstation Player 8.1.1 / 12.1.1+ Fix from $1,9502016-08-08 MEDIUM 5.5 CVE-2015-3192 Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which … Spring Framework Mitigation only Fix from $1,6002016-07-12 HIGH 8.8 CVE-2016-2082 Cross-site request forgery (CSRF) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to hijack the authent… Vrealize Log Insight Patch available Fix from $1,9502016-07-03 MEDIUM 6.1 CVE-2016-2081 Cross-site scripting (XSS) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to inject arbitrary web scri… Vrealize Log Insight Patch available Fix from $1,6002016-07-03 MEDIUM 5.9 CVE-2016-2079 VMware NSX Edge 6.1 before 6.1.7 and 6.2 before 6.2.3 and vCNS Edge 5.5 before 5.5.4.3, when the SSL-VPN feature is configured, allow remote attacker… Nsx Edge Patch available Fix from $1,6002016-07-03 MEDIUM 6.1 CVE-2015-6931 Cross-site scripting (XSS) vulnerability in the vSphere Web Client in VMware vCenter Server 5.0 before U3g, 5.1 before U3d, and 5.5 before U2d allows… Vcenter Server Patch available Fix from $1,6002016-07-03 MEDIUM 6.1 CVE-2016-2078 Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5.1 before update 3d, 5.5 before update 3d, and 6.0 before update… Vcenter Server No fix yet Fix from $1,6002016-06-08 CRITICAL 9.8 CVE-2016-2077 VMware Workstation 11.x before 11.1.3 and VMware Player 7.x before 7.1.3 on Windows incorrectly access an executable file, which allows host OS users… Player Mitigation only Fix from $2,3002016-05-18 HIGH 7.6 CVE-2016-2076 Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Iden… Vcenter Server after 6.0 Fix from $1,9502016-04-15 MEDIUM 5.4 CVE-2016-2075 Cross-site scripting (XSS) vulnerability in VMware vRealize Business Advanced and Enterprise 8.x before 8.2.5 on Linux allows remote authenticated us… Vrealize Business Advanced And Enterprise Mitigation only Fix from $1,6002016-03-16 MEDIUM 5.4 CVE-2015-2344 Cross-site scripting (XSS) vulnerability in VMware vRealize Automation 6.x before 6.2.4 on Linux allows remote authenticated users to inject arbitrar… Vrealize Automation Mitigation only Fix from $1,6002016-03-16 MEDIUM 6.3 CVE-2015-6933 The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2, VMware Fusion 7.x… Player Patch available Fix from $1,6002016-01-09 HIGH 7.3 CVE-2015-6934EPSS 5% Serialized-object interfaces in VMware vRealize Orchestrator 6.x, vCenter Orchestrator 5.x, vRealize Operations 6.x, vCenter Operations 5.x, and vCen… Vcenter Orchestrator Mitigation only Fix from $1,9502015-12-21 HIGH 10.0 CVE-2015-2342EPSS 89% The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBean… Vcenter Server Patch available Fix from $1,9502015-10-12