CVE-2008-4916
published 2009-04-06CVE-2008-4916: Unspecified vulnerability in a guest virtual device driver in VMware Workstation before 5.5.9 build 126128, and 6.5.1 and earlier 6.x versions; VMware Player…
PriorityP414medium4.6CVSS 2.0
AVLACLAuSCNINAC
EPSS
0.33%
25.4th percentile
Unspecified vulnerability in a guest virtual device driver in VMware Workstation before 5.5.9 build 126128, and 6.5.1 and earlier 6.x versions; VMware Player before 1.0.9 build 126128, and 2.5.1 and earlier 2.x versions; VMware ACE before 1.0.8 build 125922, and 2.5.1 and earlier 2.x versions; VMware Server 1.x before 1.0.8 build 126538 and 2.0.x before 2.0.1 build 156745; VMware Fusion before 2.0.1; VMware ESXi 3.5; and VMware ESX 3.0.2, 3.0.3, and 3.5 allows guest OS users to cause a denial of service (host OS crash) via unknown vectors.
Affected
166 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | ace | <= 2.5.1 | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esxi | — | — |
| vmware | fusion | <= 2.0.3 | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Hosted products and patches for ESX and ESXi resolve a critical security vulnerability
vendor_vmware·2009-04-10·CVSS 4.6
CVE-2008-4916 [MEDIUM] VMware Hosted products and patches for ESX and ESXi resolve a critical security vulnerability
VMSA-2009-0006: VMware Hosted products and patches for ESX and ESXi resolve a critical security vulnerability
a. Host code execution vulnerability from a guest operating system A critical vulnerability in the virtual machine display function might allow a guest operating system to run code on the host. This issue is different from the vulnerability in a guest virtual device driver reported in VMware security advisory VMSA-2009-0005 on 2009-04-03. That vulnerability can cause a potential denial of service and is identified by CVE-2008-4916. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2009-1244 to this issue. The following table lists what action remediates the vulnerability (column 4) if a solution is available. VMware Product ============= Pr
VMware
VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues
vendor_vmware·2009-04-03·CVSS 4.6
CVE-2008-3761 [MEDIUM] VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues
VMSA-2009-0005: VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues
a. Denial of service guest to host vulnerability in a virtual device A vulnerability in a guest virtual device driver, could allow a guest operating system to crash the host and consequently any virtual machines on that host. VMware would like to thank Andrew Honig of the Department of Defense for reporting this issue. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2008-4916 to this issue. The following table lists what action remediates the vulnerability (column 4) if a solution is available. VMware Product ============= Product Version ======= Running on ======= Replace with/ Apply Patch ================= VMware Product =============
GHSA
GHSA-m34f-92c4-4h99: Unspecified vulnerability in a guest virtual device driver in VMware Workstation before 5
ghsa_unreviewed·2022-05-17
CVE-2008-4916 [MEDIUM] GHSA-m34f-92c4-4h99: Unspecified vulnerability in a guest virtual device driver in VMware Workstation before 5
Unspecified vulnerability in a guest virtual device driver in VMware Workstation before 5.5.9 build 126128, and 6.5.1 and earlier 6.x versions; VMware Player before 1.0.9 build 126128, and 2.5.1 and earlier 2.x versions; VMware ACE before 1.0.8 build 125922, and 2.5.1 and earlier 2.x versions; VMware Server 1.x before 1.0.8 build 126538 and 2.0.x before 2.0.1 build 156745; VMware Fusion before 2.0.1; VMware ESXi 3.5; and VMware ESX 3.0.2, 3.0.3, and 3.5 allows guest OS users to cause a denial of service (host OS crash) via unknown vectors.
GHSA
GHSA-3pp9-5q74-pq79: Unspecified vulnerability in the virtual machine display function in VMware Workstation 6
ghsa_unreviewed·2022-05-02·CVSS 4.6
CVE-2009-1244 [MEDIUM] GHSA-3pp9-5q74-pq79: Unspecified vulnerability in the virtual machine display function in VMware Workstation 6
Unspecified vulnerability in the virtual machine display function in VMware Workstation 6.5.1 and earlier; VMware Player 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 1.x before 1.0.9 build 156507 and 2.x before 2.0.1 build 156745; VMware Fusion before 2.0.4 build 159196; VMware ESXi 3.5; and VMware ESX 3.0.2, 3.0.3, and 3.5 allows guest OS users to execute arbitrary code on the host OS via unknown vectors, a different vulnerability than CVE-2008-4916.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.vmware.com/pipermail/security-announce/2009/000054.htmlhttp://seclists.org/fulldisclosure/2009/Apr/0036.htmlhttp://security.gentoo.org/glsa/glsa-201209-25.xmlhttp://www.securityfocus.com/bid/34373http://www.securitytracker.com/id?1021973http://www.vmware.com/security/advisories/VMSA-2009-0005.htmlhttp://www.vupen.com/english/advisories/2009/0944https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6439http://lists.vmware.com/pipermail/security-announce/2009/000054.htmlhttp://seclists.org/fulldisclosure/2009/Apr/0036.htmlhttp://security.gentoo.org/glsa/glsa-201209-25.xmlhttp://www.securityfocus.com/bid/34373http://www.securitytracker.com/id?1021973http://www.vmware.com/security/advisories/VMSA-2009-0005.htmlhttp://www.vupen.com/english/advisories/2009/0944https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6439
2009-04-06
Published