CVE-2008-3697
published 2008-09-03CVE-2008-3697: An unspecified ISAPI extension in VMware Server before 1.0.7 build 108231 allows remote attackers to cause a denial of service (IIS crash) via a malformed…
PriorityP420medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.04%
86.0th percentile
An unspecified ISAPI extension in VMware Server before 1.0.7 build 108231 allows remote attackers to cause a denial of service (IIS crash) via a malformed request.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | server | — | — |
| vmware | server | — | — |
| vmware | server | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_server | <= 1.0.6 | — |
| vmware | vmware_server | — | — |
| vmware | vmware_server | — | — |
| vmware | vmware_server | — | — |
| vmware | vmware_server | — | — |
| vmware | vmware_server | — | — |
| vmware | vmware_server | — | — |
| vmware | vmware_workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w7x3-rwmf-hc38: An unspecified ISAPI extension in VMware Server before 1
ghsa_unreviewed·2022-05-02
CVE-2008-3697 [MEDIUM] CWE-20 GHSA-w7x3-rwmf-hc38: An unspecified ISAPI extension in VMware Server before 1
An unspecified ISAPI extension in VMware Server before 1.0.7 build 108231 allows remote attackers to cause a denial of service (IIS crash) via a malformed request.
VMware
Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX, VMware VCB address information disclosure, privilege escalation and other security issues.
vendor_vmware·2008-08-29·CVSS 1.9
CVE-2007-5269 [LOW] Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX, VMware VCB address information disclosure, privilege escalation and other security issues.
VMSA-2008-0014: Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX, VMware VCB address information disclosure, privilege escalation and other security issues.
I Security Issues a. Setting ActiveX killbit Starting from this release, VMware has set the killbit on its ActiveX controls. Setting the killbit ensures that ActiveX controls cannot run in Internet Explorer (IE), and avoids Microsoft KB article 240797 and the related references on this topic. Security vulnerabilities have been reported for ActiveX controls provided by VMware when run in IE. Under specific circumstances, exploitation of these ActiveX controls might result in denial-of- service or can allow running of arbitrary code when the user browses a malicious Web site or opens a malicious file i
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064118.htmlhttp://secunia.com/advisories/31708http://securityreason.com/securityalert/4202http://www.securityfocus.com/archive/1/495869/100/0/threadedhttp://www.securityfocus.com/bid/30935http://www.securitytracker.com/id?1020789http://www.vmware.com/security/advisories/VMSA-2008-0014.htmlhttp://www.vmware.com/support/server/doc/releasenotes_server.htmlhttp://www.vupen.com/english/advisories/2008/2466https://exchange.xforce.ibmcloud.com/vulnerabilities/44796http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064118.htmlhttp://secunia.com/advisories/31708http://securityreason.com/securityalert/4202http://www.securityfocus.com/archive/1/495869/100/0/threadedhttp://www.securityfocus.com/bid/30935http://www.securitytracker.com/id?1020789http://www.vmware.com/security/advisories/VMSA-2008-0014.htmlhttp://www.vmware.com/support/server/doc/releasenotes_server.htmlhttp://www.vupen.com/english/advisories/2008/2466https://exchange.xforce.ibmcloud.com/vulnerabilities/44796
2008-09-03
Published