← Back

Vmware

vmware

958 CVEs • 195 products

Products (195)

Click to collapse
Toggle
Workstation
workstation
Esxi
esxi
Fusion
fusion
Player
player
Esx
esx
Server
server
Ace
ace
Tools
tools
Spring Boot
spring_boot
Spring Ai
spring_ai
Horizon View
horizon_view
One Access
one_access
Virtualcenter
virtualcenter
Vmware Server
vmware_server
Esx Server
esx_server
Vma
vma
Open Vm Tools
open-vm-tools
View
view
Gsx Server
gsx_server
Movie Decoder
movie_decoder
Horizon
horizon
Rabbitmq
rabbitmq
Vmware Player
vmware_player
Vcenter
vcenter
Fusion Pro
fusion_pro
Airwatch
airwatch
Photon Os
photon_os
Horizon Daas
horizon_daas
Studio
studio
Vsphere
vsphere
Ixgben
ixgben
Ace 2
ace_2
Vmware Esx
vmware_esx
Vmware Esxi
vmware_esxi
Vix Api
vix_api
Tc Server
tc_server
Hyperic Hq
hyperic_hq
Vm Support
vm-support
Nsx Edge
nsx_edge
Vsphere Esxi
vsphere_esxi

CVEs (958)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vmware
2Workstation Player
Workstation Pro
May 13, 2026
Jun 7, 2017
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
VMware Workstation Pro/Player 12.x before 12.5.3 contains a security vulnerability that exists in the SVGA driver. An attacker may exploit this issue to crash the VM or trigger an out-of-bound read. Note: This issue can...Show more
VMware Workstation Pro/Player 12.x before 12.5.3 contains a security vulnerability that exists in the SVGA driver. An attacker may exploit this issue to crash the VM or trigger an out-of-bound read. Note: This issue can be triggered only when the host has no graphics card or no graphics drivers are installed.Show less
1Vmware
2Workstation Player
Workstation Pro
May 13, 2026
Jun 7, 2017
N/A· v4
8.8 HIGH· v3
6.9 MEDIUM· v2
VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a path defined in the local environment-variable. Successful exploitatio...Show more
VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a path defined in the local environment-variable. Successful exploitation of this issue may allow normal users to escalate privileges to System in the host machine where VMware Workstation is installed.Show less
1Vmware
1Vsphere Data Protection
May 13, 2026
Jun 7, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained.
1Vmware
1Vsphere Data Protection
May 13, 2026
Jun 7, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance.
1Vmware
1Horizon Daas
May 13, 2026
May 31, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
VMware Horizon DaaS before 7.0.0 contains a vulnerability that exists due to insufficient validation of data. An attacker may exploit this issue by tricking DaaS client users into connecting to a malicious server and sha...Show more
VMware Horizon DaaS before 7.0.0 contains a vulnerability that exists due to insufficient validation of data. An attacker may exploit this issue by tricking DaaS client users into connecting to a malicious server and sharing all their drives and devices. Successful exploitation of this vulnerability requires a victim to download a specially crafted RDP file through DaaS client by clicking on a malicious link.Show less
2Pivotal Software
Vmware
3Spring Framework
Spring FrameworkSpring Security
May 13, 2026
May 25, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for mapping requests to controllers respectively. Differences in the strictn...Show more
Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for mapping requests to controllers respectively. Differences in the strictness of the pattern matching mechanisms, for example with regards to space trimming in path segments, can lead Spring Security to not recognize certain paths as not protected that are in fact mapped to Spring MVC controllers that should be protected. The problem is compounded by the fact that the Spring Framework provides richer features with regards to pattern matching as well as by the fact that pattern matching in each Spring Security and the Spring Framework can easily be customized creating additional differences.Show less
2Debian
Vmware
2Debian Linux
Spring Framework
May 13, 2026
May 25, 2017
N/A· v4
9.6 CRITICAL· v3
9.3 HIGH· v2
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user cra...Show more
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.Show less
1Vmware
1Spring Security
May 13, 2026
May 25, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was not associated. This is due to the fact...Show more
When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was not associated. This is due to the fact that the proxy ticket authentication uses the information from the HttpServletRequest which is populated based upon untrusted information within the HTTP request. This means if there are access control restrictions on which CAS services can authenticate to one another, those restrictions can be bypassed. If users are not using CAS Proxy tickets and not basing access control decisions based upon the CAS Service, then there is no impact to users.Show less
2Pivotal Software
Vmware
2Spring Framework
Spring Framework
May 13, 2026
May 25, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration...Show more
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.Show less
1Vmware
1Spring Security
May 13, 2026
May 25, 2017
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who suppli...Show more
The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.Show less
1Vmware
2Workstation Player
Workstation Pro
May 13, 2026
May 22, 2017
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Successful exploitation of this issue may allow host users with normal user privileges to trigger a denial...Show more
VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Successful exploitation of this issue may allow host users with normal user privileges to trigger a denial-of-service in a Windows host machine.Show less
1Vmware
2Workstation Player
Workstation Pro
May 13, 2026
May 22, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation of this issue may allow unprivileged host users to escalate their privil...Show more
VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation of this issue may allow unprivileged host users to escalate their privileges to root in a Linux host machine.Show less
1Vmware
2Airwatch Agent
Airwatch Inbox
May 13, 2026
May 10, 2017
N/A· v4
3.8 LOW· v3
2.1 LOW· v2
Airwatch Inbox for Android contains a vulnerability that may allow a rooted device to decrypt the local data used by the application. Successful exploitation of this issue may result in an unauthorized disclosure of conf...Show more
Airwatch Inbox for Android contains a vulnerability that may allow a rooted device to decrypt the local data used by the application. Successful exploitation of this issue may result in an unauthorized disclosure of confidential data.Show less
1Vmware
2Airwatch Agent
Airwatch Inbox
May 13, 2026
May 10, 2017
N/A· v4
8.8 HIGH· v3
4.6 MEDIUM· v2
Airwatch Agent for Android contains a vulnerability that may allow a device to bypass root detection. Successful exploitation of this issue may result in an enrolled device having unrestricted access over local Airwatch...Show more
Airwatch Agent for Android contains a vulnerability that may allow a device to bypass root detection. Successful exploitation of this issue may result in an enrolled device having unrestricted access over local Airwatch security controls and data.Show less
2Fedoraproject
Vmware
2Fedora
Spring Advanced Message Queuing Protocol
May 13, 2026
Apr 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.
2Ibm
Vmware
2Spring Security
Websphere Application Server
May 6, 2026
Jan 6, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. Spring Security does not consider URL path parameters when processing security constraints. By adding a URL pa...Show more
An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. Spring Security does not consider URL path parameters when processing security constraints. By adding a URL path parameter with an encoded "/" to a request, an attacker may be able to bypass a security constraint. The root cause of this issue is a lack of clarity regarding the handling of path parameters in the Servlet Specification. Some Servlet containers include path parameters in the value returned for getPathInfo() and some do not. Spring Security uses the value returned by getPathInfo() as part of the process of mapping requests to security constraints. The unexpected presence of path parameters can cause a constraint to be bypassed. Users of Apache Tomcat (all current versions) are not affected by this vulnerability since Tomcat follows the guidance previously provided by the Servlet Expert group and strips path parameters from the value returned by getContextPath(), getServletPath(), and getPathInfo(). Users of other Servlet containers based on Apache Tomcat may or may not be affected depending on whether or not the handling of path parameters has been modified. Users of IBM WebSphere Application Server 8.5.x are known to be affected. Users of other containers that implement the Servlet specification may be affected.Show less
2Pivotal Software
Vmware
2Spring Framework
Spring Framework
May 6, 2026
Dec 29, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traver...Show more
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.Show less
1Vmware
1Esxi
May 6, 2026
Dec 29, 2016
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the Host Client in VMware vSphere Hypervisor (aka ESXi) 5.5 and 6.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted VM.
1Vmware
1Vrealize Operations
May 6, 2026
Dec 29, 2016
N/A· v4
8.5 HIGH· v3
7.5 HIGH· v2
The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files or rename files via a crafted DiskFileItem in a relay-request payload th...Show more
The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files or rename files via a crafted DiskFileItem in a relay-request payload that is mishandled during deserialization.Show less
1Vmware
4Fusion
Fusion ProWorkstation Player+1 more
May 6, 2026
Dec 29, 2016
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion and Fusion Pro 8.x before 8.5.2 allows guest OS users to execute arbitr...Show more
The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion and Fusion Pro 8.x before 8.5.2 allows guest OS users to execute arbitrary code on the host OS or cause a denial of service (out-of-bounds memory access on the host OS) via unspecified vectors.Show less