CVE-2015-2339
published 2015-06-13CVE-2015-2339: TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client…
PriorityP423medium6.1CVSS 2.0
AVAACLAuNCNINAC
EPSS
0.66%
47.4th percentile
TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to cause a host OS denial of service via unspecified vectors, a different vulnerability than CVE-2015-2338.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | horizon_client | — | — |
| vmware | horizon_client | — | — |
| vmware | horizon_client | — | — |
| vmware | horizon_view_client | — | — |
| vmware | horizon_view_client | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_horizon | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Workstation, Fusion and Horizon View Client updates address critical security issues
vendor_vmware·2015-06-09·CVSS 6.8
CVE-2012-0897 [MEDIUM] VMware Workstation, Fusion and Horizon View Client updates address critical security issues
VMSA-2015-0004: VMware Workstation, Fusion and Horizon View Client updates address critical security issues
a. VMware Workstation and Horizon Client memory manipulation issues VMware Workstation and Horizon Client TPView.dll and TPInt.dll incorrectly handle memory allocation. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon Client. VMware would like to thank Kostya Kortchinsky of the Google Security Team for reporting these issues to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifiers CVE-2012-0897 and CVE-2015-2336 (TP
GHSA
GHSA-33mf-x5r5-qqmj: TPview
ghsa_unreviewed·2022-05-17·CVSS 6.1
CVE-2015-2338 [MEDIUM] GHSA-33mf-x5r5-qqmj: TPview
TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to cause a host OS denial of service via unspecified vectors, a different vulnerability than CVE-2015-2339.
GHSA
GHSA-g9ff-c72j-2fjq: TPview
ghsa_unreviewed·2022-05-17·CVSS 6.1
CVE-2015-2339 [MEDIUM] GHSA-g9ff-c72j-2fjq: TPview
TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to cause a host OS denial of service via unspecified vectors, a different vulnerability than CVE-2015-2338.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/75092http://www.securitytracker.com/id/1032529http://www.securitytracker.com/id/1032530http://www.vmware.com/security/advisories/VMSA-2015-0004.htmlhttp://www.securityfocus.com/bid/75092http://www.securitytracker.com/id/1032529http://www.securitytracker.com/id/1032530http://www.vmware.com/security/advisories/VMSA-2015-0004.html
2015-06-13
Published