CVE-2012-1512
published 2012-03-16CVE-2012-1512: Cross-site scripting (XSS) vulnerability in the internal browser in vSphere Client in VMware vSphere 4.1 before Update 2 and 5.0 before Update 1 allows remote…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.95%
77.9th percentile
Cross-site scripting (XSS) vulnerability in the internal browser in vSphere Client in VMware vSphere 4.1 before Update 2 and 5.0 before Update 1 allows remote attackers to inject arbitrary web script or HTML via a crafted log-file entry.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
| vmware | vsphere | <= 4.1 | — |
| vmware | vsphere | <= 5.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fx5m-6p6r-8x4h: Cross-site scripting (XSS) vulnerability in the internal browser in vSphere Client in VMware vSphere 4
ghsa_unreviewed·2022-05-14
CVE-2012-1512 [MEDIUM] CWE-79 GHSA-fx5m-6p6r-8x4h: Cross-site scripting (XSS) vulnerability in the internal browser in vSphere Client in VMware vSphere 4
Cross-site scripting (XSS) vulnerability in the internal browser in vSphere Client in VMware vSphere 4.1 before Update 2 and 5.0 before Update 1 allows remote attackers to inject arbitrary web script or HTML via a crafted log-file entry.
VMware
VMware vCenter Server, Orchestrator, Update Manager, vShield, vSphere Client, Workstation, Player, ESXi and ESX address several security issues
vendor_vmware·2012-03-15·CVSS 7.2
CVE-2010-0405 [HIGH] VMware vCenter Server, Orchestrator, Update Manager, vShield, vSphere Client, Workstation, Player, ESXi and ESX address several security issues
VMSA-2012-0005: VMware vCenter Server, Orchestrator, Update Manager, vShield, vSphere Client, Workstation, Player, ESXi and ESX address several security issues
a. VMware Tools Display Driver Privilege Escalation The VMware XPDM and WDDM display drivers contain buffer overflow vulnerabilities and the XPDM display driver does not properly check for NULL pointers. Exploitation of these issues may lead to local privilege escalation on Windows-based Guest Operating Systems. VMware would like to thank Tarjei Mandt for reporting theses issues to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2012-1509 (XPDM buffer overrun), CVE-2012-1510 (WDDM buffer overrun) and CVE-2012-1508 (XPDM null pointer dereference) to these issues. Note: CVE-2012-1509 do
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/80119http://secunia.com/advisories/48387http://www.securityfocus.com/bid/52525http://www.securitytracker.com/id?1026817http://www.vmware.com/security/advisories/VMSA-2012-0005.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/74093http://osvdb.org/80119http://secunia.com/advisories/48387http://www.securityfocus.com/bid/52525http://www.securitytracker.com/id?1026817http://www.vmware.com/security/advisories/VMSA-2012-0005.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/74093
2012-03-16
Published