Vulnerabilities in vmware

238 results
Vexday analysis

VMware apresenta baixo volume de risco imediato com apenas 1 CVE catalogado na base, nenhum sob exploração ativa (KEV). A vulnerabilidade não é crítica e não foi publicada recentemente, reduzindo a urgência de remediação, embora a fraqueza dominante (CWE-640: autenticação fraca) mereça atenção em revisões de segurança preventivas.

CVE-2020-3970VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x beEPSS 0.4%CVE-2017-4950VMware Workstation and Fusion contain an integer overflow vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may leadEPSS 0.4%CVE-2017-4949VMware Workstation and Fusion contain a use-after-free vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may allow aEPSS 0.4%CVE-2017-4910VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities iEPSS 0.4%CVE-2017-4908VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple heap buffer-overflow vulnerabilitiesEPSS 0.4%CVE-2017-4911VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds write vulnerabilities EPSS 0.4%CVE-2017-4912VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities iEPSS 0.4%CVE-2017-4909VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain a heap buffer-overflow vulnerability in TrueTEPSS 0.4%CVE-2017-4938VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL pointer dereference vulnerability. SuccessfulEPSS 0.4%CVE-2020-3966VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x beEPSS 0.4%CVE-2017-4943VMware vCenter Server Appliance (vCSA) (6.5 before 6.5 U1d) contains a local privilege escalation vulnerability via the 'showlog' plugin. SuEPSS 0.4%CVE-2017-4895Airwatch Agent for Android contains a vulnerability that may allow a device to bypass root detection. Successful exploitation of this issue EPSS 0.4%CVE-2024-22250HIGHSession Hijack Vulnerability in Deprecated EAP Browser PluginEPSS 0.3%CVE-2026-22740MEDIUMSpring Framework DoS with Multipart Temp Files in WebFluxEPSS 0.3%CVE-2026-22745MEDIUMCVE-2026-22745 : Denial of service in static resource handling on Windows platformsEPSS 0.3%CVE-2025-22227MEDIUMCVE-2025-22227: Authentication Leak On Redirect With Reactor Netty HTTP ClientEPSS 0.3%CVE-2017-4900VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SVGA driver. SuccessfuEPSS 0.3%CVE-2017-4896Airwatch Inbox for Android contains a vulnerability that may allow a rooted device to decrypt the local data used by the application. SuccesEPSS 0.3%CVE-2020-3971VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201907101-SG), Workstation (15.x before 15.0.2), and Fusion (11.x beforeEPSS 0.3%CVE-2015-5191VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. SuccessEPSS 0.3%