CVE-2011-1785
published 2011-05-03CVE-2011-1785: VMware ESXi 4.0 and 4.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (socket exhaustion) via unspecified network traffic.
PriorityP431high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.41%
87.5th percentile
VMware ESXi 4.0 and 4.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (socket exhaustion) via unspecified network traffic.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter Server and vSphere Client security vulnerabilities
vendor_vmware·2011-05-05·CVSS 4.3
CVE-2011-0426 [MEDIUM] VMware vCenter Server and vSphere Client security vulnerabilities
VMSA-2011-0008: VMware vCenter Server and vSphere Client security vulnerabilities
a. vCenter Server Directory Traversal vulnerability A directory traversal vulnerability allows an attacker to remotely retrieve files from vCenter Server without authentication. In order to exploit this vulnerability, the attacker will need to have access to the network on which the vCenter Server host resides. In case vCenter Server is installed on Windows 2008 or Windows 2008 R2, the security vulnerability is not present. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2011-0426 to this issue. VMware Product ============= Product Version ======= Running on ======= Replace with/ Apply Patch ================= VMware Product ============= vCenter Product Version ====
VMware
VMware ESXi and ESX Denial of Service and third party updates for Likewise components and ESX Service Console
vendor_vmware·2011-04-28·CVSS 7.8
CVE-2010-1323 [HIGH] VMware ESXi and ESX Denial of Service and third party updates for Likewise components and ESX Service Console
VMSA-2011-0007: VMware ESXi and ESX Denial of Service and third party updates for Likewise components and ESX Service Console
a. ESX/ESXi Socket Exhaustion By sending malicious network traffic to an ESXi or ESX host an attacker could exhaust the available sockets which would prevent further connections to the host. In the event a host becomes inaccessible its virtual machines will continue to run and have network connectivity but a reboot of the ESXi or ESX host may be required in order to be able to connect to the host again. ESXi and ESX hosts may intermittently lose connectivity caused by applications that do not correctly close sockets. If this occurs an error message similar to the following may be written to the vpxa log: socket() returns -1 (Cannot allocate memory) An error message
GHSA
GHSA-4248-p64f-3j9w: VMware ESXi 4
ghsa_unreviewed·2022-05-14
CVE-2011-1785 [HIGH] GHSA-4248-p64f-3j9w: VMware ESXi 4
VMware ESXi 4.0 and 4.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (socket exhaustion) via unspecified network traffic.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://kb.vmware.com/kb/1035108http://lists.vmware.com/pipermail/security-announce/2011/000133.htmlhttp://osvdb.org/72118http://securityreason.com/securityalert/8240http://securitytracker.com/id?1025452http://www.securityfocus.com/archive/1/517739/100/0/threadedhttp://www.securityfocus.com/bid/47627http://www.vmware.com/security/advisories/VMSA-2011-0007.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/67195https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13242http://kb.vmware.com/kb/1035108http://lists.vmware.com/pipermail/security-announce/2011/000133.htmlhttp://osvdb.org/72118http://securityreason.com/securityalert/8240http://securitytracker.com/id?1025452http://www.securityfocus.com/archive/1/517739/100/0/threadedhttp://www.securityfocus.com/bid/47627http://www.vmware.com/security/advisories/VMSA-2011-0007.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/67195https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13242
2011-05-03
Published