Vmware
vmware
958 CVEs • 195 products
Products (195)
Click to collapseToggle
Products (195)
Click to collapse
CVEs (958)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Vmware 2Workstation Player Workstation ProMay 13, 2026 Jun 7, 2017 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 VMware Workstation Pro/Player 12.x before 12.5.3 contains a security vulnerability that exists in the SVGA driver. An attacker may exploit this issue to crash the VM or trigger an out-of-bound read. Note: This issue can...Show more |
1Vmware 2Workstation Player Workstation ProMay 13, 2026 Jun 7, 2017 N/A· v4 8.8 HIGH· v3 6.9 MEDIUM· v2 VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a path defined in the local environment-variable. Successful exploitatio...Show more |
1Vmware 1Vsphere Data Protection May 13, 2026 Jun 7, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained. |
1Vmware 1Vsphere Data Protection May 13, 2026 Jun 7, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance. |
VMware Horizon DaaS before 7.0.0 contains a vulnerability that exists due to insufficient validation of data. An attacker may exploit this issue by tricking DaaS client users into connecting to a malicious server and sha...Show more |
2Pivotal Software Vmware3Spring Framework Spring FrameworkSpring SecurityMay 13, 2026 May 25, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for mapping requests to controllers respectively. Differences in the strictn...Show more |
2Debian Vmware2Debian Linux Spring FrameworkMay 13, 2026 May 25, 2017 N/A· v4 9.6 CRITICAL· v3 9.3 HIGH· v2 Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user cra...Show more |
When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was not associated. This is due to the fact...Show more |
2Pivotal Software Vmware2Spring Framework Spring FrameworkMay 13, 2026 May 25, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration...Show more |
The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who suppli...Show more |
1Vmware 2Workstation Player Workstation ProMay 13, 2026 May 22, 2017 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Successful exploitation of this issue may allow host users with normal user privileges to trigger a denial...Show more |
1Vmware 2Workstation Player Workstation ProMay 13, 2026 May 22, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation of this issue may allow unprivileged host users to escalate their privil...Show more |
1Vmware 2Airwatch Agent Airwatch InboxMay 13, 2026 May 10, 2017 N/A· v4 3.8 LOW· v3 2.1 LOW· v2 Airwatch Inbox for Android contains a vulnerability that may allow a rooted device to decrypt the local data used by the application. Successful exploitation of this issue may result in an unauthorized disclosure of conf...Show more |
1Vmware 2Airwatch Agent Airwatch InboxMay 13, 2026 May 10, 2017 N/A· v4 8.8 HIGH· v3 4.6 MEDIUM· v2 Airwatch Agent for Android contains a vulnerability that may allow a device to bypass root detection. Successful exploitation of this issue may result in an enrolled device having unrestricted access over local Airwatch...Show more |
2Fedoraproject Vmware2Fedora Spring Advanced Message Queuing ProtocolMay 13, 2026 Apr 21, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code. |
2Ibm Vmware2Spring Security Websphere Application ServerMay 6, 2026 Jan 6, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. Spring Security does not consider URL path parameters when processing security constraints. By adding a URL pa...Show more |
2Pivotal Software Vmware2Spring Framework Spring FrameworkMay 6, 2026 Dec 29, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traver...Show more |
Cross-site scripting (XSS) vulnerability in the Host Client in VMware vSphere Hypervisor (aka ESXi) 5.5 and 6.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted VM. |
The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files or rename files via a crafted DiskFileItem in a relay-request payload th...Show more |
1Vmware 4Fusion Fusion ProWorkstation Player+1 moreMay 6, 2026 Dec 29, 2016 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion and Fusion Pro 8.x before 8.5.2 allows guest OS users to execute arbitr...Show more |