CVE-2009-0910
published 2009-04-06CVE-2009-0910: Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE…
PriorityP333medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.81%
85.0th percentile
Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware Server 2.0.x before 2.0.1 build 156745 allows remote attackers to execute arbitrary code via a crafted web page or video file, aka ZDI-CAN-436.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | ace | — | — |
| vmware | player | — | — |
| vmware | server | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7f62-x26q-v865: Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6
ghsa_unreviewed·2022-05-02
CVE-2009-0910 [MEDIUM] CWE-119 GHSA-7f62-x26q-v865: Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6
Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware Server 2.0.x before 2.0.1 build 156745 allows remote attackers to execute arbitrary code via a crafted web page or video file, aka ZDI-CAN-436.
VMware
VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues
vendor_vmware·2009-04-03·CVSS 4.6
CVE-2008-3761 [MEDIUM] VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues
VMSA-2009-0005: VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues
a. Denial of service guest to host vulnerability in a virtual device A vulnerability in a guest virtual device driver, could allow a guest operating system to crash the host and consequently any virtual machines on that host. VMware would like to thank Andrew Honig of the Department of Defense for reporting this issue. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2008-4916 to this issue. The following table lists what action remediates the vulnerability (column 4) if a solution is available. VMware Product ============= Product Version ======= Running on ======= Replace with/ Apply Patch ================= VMware Product =============
No detection rules found.
No writeups or analysis indexed.
http://lists.vmware.com/pipermail/security-announce/2009/000054.htmlhttp://seclists.org/fulldisclosure/2009/Apr/0036.htmlhttp://security.gentoo.org/glsa/glsa-201209-25.xmlhttp://www.securityfocus.com/bid/34373http://www.securitytracker.com/id?1021974http://www.vmware.com/security/advisories/VMSA-2009-0005.htmlhttp://www.vupen.com/english/advisories/2009/0944https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5786http://lists.vmware.com/pipermail/security-announce/2009/000054.htmlhttp://seclists.org/fulldisclosure/2009/Apr/0036.htmlhttp://security.gentoo.org/glsa/glsa-201209-25.xmlhttp://www.securityfocus.com/bid/34373http://www.securitytracker.com/id?1021974http://www.vmware.com/security/advisories/VMSA-2009-0005.htmlhttp://www.vupen.com/english/advisories/2009/0944https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5786
2009-04-06
Published