CVE-2008-3693
published 2008-09-03CVE-2008-3693: Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build…
PriorityP339critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.56%
88.0th percentile
Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3691, CVE-2008-3692, CVE-2008-3694, CVE-2008-3695, and CVE-2008-3696.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | ace | >= 1.0 < 1.0.7 | 1.0.7 |
| vmware | ace | >= 2.0 < 2.0.5 | 2.0.5 |
| vmware | player | >= 1.0.0 < 1.0.8 | 1.0.8 |
| vmware | player | >= 2.0 < 2.0.5 | 2.0.5 |
| vmware | server | < 1.0.7 | 1.0.7 |
| vmware | vmware_esxi | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | >= 5.5 < 5.5.8 | 5.5.8 |
| vmware | workstation | >= 6.0 < 6.0.5 | 6.0.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5m38-jjgp-q23x: Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5
ghsa_unreviewed·2022-05-02·CVSS 10.0
CVE-2008-3696 [CRITICAL] GHSA-5m38-jjgp-q23x: Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5
Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3691, CVE-2008-3692, CVE-2008-3693, CVE-2008-3694, and CVE-2008-3695.
GHSA
GHSA-p599-g5cv-9wxc: Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5
ghsa_unreviewed·2022-05-02·CVSS 10.0
CVE-2008-3695 [CRITICAL] GHSA-p599-g5cv-9wxc: Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5
Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3691, CVE-2008-3692, CVE-2008-3693, CVE-2008-3694, and CVE-2008-3696.
GHSA
GHSA-hh56-whf8-c572: Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5
ghsa_unreviewed·2022-05-02·CVSS 10.0
CVE-2008-3691 [CRITICAL] GHSA-hh56-whf8-c572: Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5
Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3692, CVE-2008-3693, CVE-2008-3694, CVE-2008-3695, and CVE-2008-3696.
GHSA
GHSA-cj86-94wr-xfx8: Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5
ghsa_unreviewed·2022-05-02·CVSS 10.0
CVE-2008-3694 [CRITICAL] GHSA-cj86-94wr-xfx8: Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5
Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3691, CVE-2008-3692, CVE-2008-3693, CVE-2008-3695, and CVE-2008-3696.
GHSA
GHSA-78j9-c89m-gjh9: Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5
ghsa_unreviewed·2022-05-02·CVSS 10.0
CVE-2008-3692 [CRITICAL] GHSA-78j9-c89m-gjh9: Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5
Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3691, CVE-2008-3693, CVE-2008-3694, CVE-2008-3695, and CVE-2008-3696.
GHSA
GHSA-889x-p8ww-5fp4: Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5
ghsa_unreviewed·2022-05-02·CVSS 10.0
CVE-2008-3892 [CRITICAL] CWE-119 GHSA-889x-p8ww-5fp4: Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5
Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a call to the GuestInfo method in which there is a long string argument, and an assignment of a long string value to the result of this call. NOTE: this may overlap CVE-2008-3691, CVE-2008-3692, CVE-2008-3693, CVE-2008-3694, CVE-2008-3695, or CVE-2008-3696.
GHSA
GHSA-gw9x-p27g-7vv2: Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5
ghsa_unreviewed·2022-05-02·CVSS 10.0
CVE-2008-3693 [CRITICAL] GHSA-gw9x-p27g-7vv2: Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5
Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3691, CVE-2008-3692, CVE-2008-3694, CVE-2008-3695, and CVE-2008-3696.
VMware
Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX, VMware VCB address information disclosure, privilege escalation and other security issues.
vendor_vmware·2008-08-29·CVSS 1.9
CVE-2007-5269 [LOW] Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX, VMware VCB address information disclosure, privilege escalation and other security issues.
VMSA-2008-0014: Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX, VMware VCB address information disclosure, privilege escalation and other security issues.
I Security Issues a. Setting ActiveX killbit Starting from this release, VMware has set the killbit on its ActiveX controls. Setting the killbit ensures that ActiveX controls cannot run in Internet Explorer (IE), and avoids Microsoft KB article 240797 and the related references on this topic. Security vulnerabilities have been reported for ActiveX controls provided by VMware when run in IE. Under specific circumstances, exploitation of these ActiveX controls might result in denial-of- service or can allow running of arbitrary code when the user browses a malicious Web site or opens a malicious file i
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064118.htmlhttp://secunia.com/advisories/31707http://secunia.com/advisories/31708http://secunia.com/advisories/31709http://secunia.com/advisories/31710http://securityreason.com/securityalert/4202http://www.securityfocus.com/archive/1/495869/100/0/threadedhttp://www.securityfocus.com/bid/30934http://www.securitytracker.com/id?1020791http://www.vmware.com/security/advisories/VMSA-2008-0014.htmlhttp://www.vmware.com/support/ace/doc/releasenotes_ace.htmlhttp://www.vmware.com/support/ace2/doc/releasenotes_ace2.htmlhttp://www.vmware.com/support/player/doc/releasenotes_player.htmlhttp://www.vmware.com/support/player2/doc/releasenotes_player2.htmlhttp://www.vmware.com/support/server/doc/releasenotes_server.htmlhttp://www.vmware.com/support/ws55/doc/releasenotes_ws55.htmlhttp://www.vmware.com/support/ws6/doc/releasenotes_ws6.htmlhttp://www.vupen.com/english/advisories/2008/2466http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064118.htmlhttp://secunia.com/advisories/31707http://secunia.com/advisories/31708http://secunia.com/advisories/31709http://secunia.com/advisories/31710http://securityreason.com/securityalert/4202http://www.securityfocus.com/archive/1/495869/100/0/threadedhttp://www.securityfocus.com/bid/30934http://www.securitytracker.com/id?1020791http://www.vmware.com/security/advisories/VMSA-2008-0014.htmlhttp://www.vmware.com/support/ace/doc/releasenotes_ace.htmlhttp://www.vmware.com/support/ace2/doc/releasenotes_ace2.htmlhttp://www.vmware.com/support/player/doc/releasenotes_player.htmlhttp://www.vmware.com/support/player2/doc/releasenotes_player2.htmlhttp://www.vmware.com/support/server/doc/releasenotes_server.htmlhttp://www.vmware.com/support/ws55/doc/releasenotes_ws55.htmlhttp://www.vmware.com/support/ws6/doc/releasenotes_ws6.htmlhttp://www.vupen.com/english/advisories/2008/2466
2008-09-03
Published