Vmware
vmware
1,027 CVEs • 198 products
Products (198)
Click to collapseToggle
Products (198)
Click to collapse
CVEs (1,027)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2 build 332101 does not...Show more |
Race condition in the mounting process in vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion...Show more |
1Vmware 4Movie Decoder PlayerServer+1 moreApr 29, 2026 Dec 6, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 The frame decompression functionality in the VMnc media codec in VMware Movie Decoder before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548, VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 b...Show more |
6Canonical LinuxOpensuse+3 more8Enterprise Linux EsxiLinux Enterprise Desktop+5 moreApr 21, 2026 Dec 6, 2010 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allo...Show more |
3Acegisecurity IbmVmware3Acegi Security Springsource Spring SecurityWebsphere Application ServerApr 29, 2026 Oct 29, 2010 N/A· v4 N/A· v3 5.0 MEDIUM· v2 VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security...Show more |
4Avaya CanonicalLinux+1 more10Aura Communication Manager Aura Presence ServicesAura Session Manager+7 moreApr 29, 2026 Sep 30, 2010 N/A· v4 8.1 HIGH· v3 6.4 MEDIUM· v2 The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk bl...Show more |
The installer in VMware Workstation 7.x before 7.1.2 build 301548 and VMware Player 3.x before 3.1.2 build 301548 renders an index.htm file if present in the installation directory, which might allow local users to trigg...Show more |
3Linux SuseVmware4Esx Linux KernelSuse Linux Enterprise Desktop+1 moreApr 29, 2026 Sep 24, 2010 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory required for the 32-bit compatibility layer...Show more |
5Canonical LinuxOpensuse+2 more6Esx Linux KernelOpensuse+3 moreApr 29, 2026 Sep 21, 2010 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc4 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information f...Show more |
6Avaya CanonicalLinux+3 more13Aura Communication Manager Aura Presence ServicesAura Session Manager+10 moreApr 29, 2026 Sep 21, 2010 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to o...Show more |
7Avaya CanonicalDebian+4 more15Aura Communication Manager Aura Presence ServicesAura Session Manager+12 moreApr 29, 2026 Sep 8, 2010 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial o...Show more |
4Canonical LinuxSuse+1 more5Esx Linux KernelSuse Linux Enterprise Desktop+2 moreApr 29, 2026 Sep 8, 2010 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The DNS resolution functionality in the CIFS implementation in the Linux kernel before 2.6.35, when CONFIG_CIFS_DFS_UPCALL is enabled, relies on a user's keyring for the dns_resolver upcall in the cifs.upcall userspace h...Show more |
3Avaya LinuxVmware9Aura Communication Manager Aura Presence ServicesAura Session Manager+6 moreApr 29, 2026 Sep 8, 2010 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash)...Show more |
4Canonical LinuxSuse+1 more6Esx Linux Enterprise High Availability ExtensionLinux Kernel+3 moreApr 29, 2026 Sep 8, 2010 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a MOVE_EXT ioctl call that specifies this file as a donor. |
4Apple OpenldapOpensuse+1 more5Esxi Mac Os XMac Os X Server+2 moreApr 29, 2026 Jul 28, 2010 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and po...Show more |
Multiple unspecified vulnerabilities in the Virtual Appliance Management Infrastructure (VAMI) in VMware Studio 2.0 allow remote authenticated users to execute arbitrary commands via vectors involving (1) the Studio virt...Show more |
VMware Studio 2.0 does not properly write to temporary files, which allows local users to gain privileges via unspecified vectors. |
8Apple CanonicalDebian+5 more12Debian Linux FedoraIphone Os+9 moreApr 29, 2026 Jun 30, 2010 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Sca...Show more |
10Apple CanonicalDebian+7 more17Chrome Debian LinuxFedora+14 moreApr 29, 2026 Jun 30, 2010 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data r...Show more |
com.springsource.tcserver.serviceability.rmi.JmxSocketListener in VMware SpringSource tc Server Runtime 6.0.19 and 6.0.20 before 6.0.20.D, and 6.0.25.A before 6.0.25.A-SR01, does not properly enforce the requirement for...Show more |