Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2015-1047 vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartb… Vcenter Server Patch available Fix from $1,6002015-10-12 MEDIUM 5.8 CVE-2015-6932 VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attack… Vcenter Server Mitigation only Fix from $1,6002015-09-18 HIGH 7.2 CVE-2015-3650 vmware-vmx.exe in VMware Workstation 7.x through 10.x before 10.0.7 and 11.x before 11.1.1, VMware Player 5.x and 6.x before 6.0.7 and 7.x before 7.1… Player Patch available Fix from $1,9502015-07-10 HIGH 7.8 CVE-2015-2341 VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.6, and VMware Fusion 6.x before 6.0.6 and 7.x before 7.0.1 allow attackers to cau… Fusion Patch available Fix from $1,9502015-06-13 MEDIUM 6.1 CVE-2015-2340 TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Cl… Horizon Client Patch available Fix from $1,6002015-06-13 MEDIUM 6.1 CVE-2015-2339 TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon C… Horizon Client Patch available Fix from $1,6002015-06-13 MEDIUM 6.1 CVE-2015-2338 TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon C… Horizon Client Patch available Fix from $1,6002015-06-13 MEDIUM 5.8 CVE-2015-2336 TPView.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon C… Fusion Patch available Fix from $1,6002015-06-13 MEDIUM 5.8 CVE-2015-2337 TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Cl… Fusion Mitigation only Fix from $1,6002015-06-13 MEDIUM 5.0 CVE-2015-0201 The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messag… Spring Framework Mitigation only Fix from $1,6002015-03-10 MEDIUM 6.4 CVE-2014-8370 VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, VMware Fusion 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allow host OS … Player Patch available Fix from $1,6002015-01-29 HIGH 9.0 CVE-2014-8373 The VMware Remote Console (VMRC) function in VMware vCloud Automation Center (vCAC) 6.0.1 through 6.1.1 allows remote authenticated users to gain pri… Vcloud Automation Center No fix yet Fix from $1,9502014-12-11 MEDIUM 5.0 CVE-2014-3625EPSS 10% Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows re… Spring Framework 3.2.12 / 4.0.8+ Fix from $1,6002014-11-20 MEDIUM 5.0 CVE-2014-3796 VMware NSX 6.0 before 6.0.6, and vCloud Networking and Security (vCNS) 5.1 before 5.1.4.2 and 5.5 before 5.5.3, does not properly validate input, whi… Nsx Patch available Fix from $1,6002014-09-15 MEDIUM 6.3 CVE-2014-4199 vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to write to arbitrary f… Tools after 10.0.3 Fix from $1,6002014-08-28 HIGH 9.0 CVE-2014-3790 Ruby vSphere Console (RVC) in VMware vCenter Server Appliance allows remote authenticated users to execute arbitrary commands as root by escaping fro… Vcenter Server Appliance Mitigation only Fix from $1,9502014-06-01 MEDIUM 5.8 CVE-2014-3793 VMware Tools in VMware Workstation 10.x before 10.0.2, VMware Player 6.x before 6.0.2, VMware Fusion 6.x before 6.0.3, and VMware ESXi 5.0 through 5.… Fusion No fix yet Fix from $1,6002014-05-31 MEDIUM 6.8 CVE-2014-0054EPSS 91% The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resol… Spring Framework after 3.2.7 Fix from $1,6002014-04-17 HIGH 9.3 CVE-2014-1209 VMware vSphere Client 4.0, 4.1, 5.0 before Update 3, and 5.1 before Update 2 does not properly validate updates to Client files, which allows remote … Vsphere Client Mitigation only Fix from $1,9502014-04-11 MEDIUM 5.8 CVE-2014-1210 VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which allows man-in-the-middle attac… Vsphere Client Mitigation only Fix from $1,6002014-04-11 MEDIUM 6.8 CVE-2013-6429EPSS 90% The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolut… Spring Framework after 3.2.4 Fix from $1,6002014-01-26 MEDIUM 6.8 CVE-2013-7315EPSS 5% The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactor… Spring Framework after 3.2.3 Fix from $1,6002014-01-23 MEDIUM 6.8 CVE-2013-4152EPSS 26% The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allow… Spring Framework after 3.2.3 Fix from $1,6002014-01-23 MEDIUM 6.8 CVE-2014-1211 Cross-site request forgery (CSRF) vulnerability in VMware vCloud Director 5.1.x before 5.1.3 allows remote attackers to hijack the authentication of … Vcloud Director Mitigation only Fix from $1,6002014-01-17 HIGH 7.9 CVE-2013-3519 lgtosync.sys in VMware Workstation 9.x before 9.0.3, VMware Player 5.x before 5.0.3, VMware Fusion 5.x before 5.0.4, VMware ESXi 4.0 through 5.1, and… Esxi Mitigation only Fix from $1,9502013-12-04 HIGH 7.2 CVE-2013-5972 VMware Workstation 9.x before 9.0.3 and VMware Player 5.x before 5.0.3 on Linux do not properly handle shared libraries, which allows host OS users t… Workstation Patch available Fix from $1,9502013-11-18 MEDIUM 6.5 CVE-2013-6366EPSS 7% The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary code via a Runtime.getRuntime().… Hyperic Hq No fix yet Fix from $1,6002013-11-04 HIGH 7.1 CVE-2013-5970 hostd-vmdb in VMware ESXi 4.0 through 5.0 and ESX 4.0 through 4.1 allows remote attackers to cause a denial of service (hostd-vmdb service outage) by… Esx Mitigation only Fix from $1,9502013-10-21 MEDIUM 6.8 CVE-2013-5971 Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web se… Vcenter Server after 5.0 Fix from $1,6002013-10-21 HIGH 9.4 CVE-2013-3658 Directory traversal vulnerability in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to delete arbitrary host OS files via … Esx Mitigation only Fix from $1,9502013-09-10