cbcvebase.

Vmware Ace vulnerabilities

45 known vulnerabilities affecting vmware/ace.

Total CVEs
45
CISA KEV
0
Public exploits
5
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH9MEDIUM17LOW1

Vulnerabilities

Page 1 of 3
CVE-2009-2267P2MEDIUMCVSS 6.9ExploitedPoCv2.5.0v2.5.1+1 more2009-11-02
CVE-2009-2267 [MEDIUM] CVE-2009-2267: VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, V VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138, VMware Fusion 2.x before 2.0.6 build 196839, VMware ESXi 3.5 and 4.0, and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0, when Virtual-8086 mode is
nvd
CVE-2009-3732P2CRITICALCVSS 10.0PoC≥ 2.5.0, < 2.5.4v2.62010-04-12
CVE-2009-3732 [CRITICAL] CWE-134 CVE-2009-3732: Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allo Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2008-3892P3CRITICALCVSS 10.0PoC≥ 1.0, < 1.0.7≥ 2.0, < 2.0.52008-09-03
CVE-2008-3892 [CRITICAL] CVE-2008-3892: Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server
nvd
CVE-2007-0063P3CRITICALCVSS 10.0≥ 1.0, < 1.0.3≥ 2.0, < 2.0.12007-09-21
CVE-2007-0063 [CRITICAL] CWE-191 CVE-2007-0063: Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x befo Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a m
nvd
CVE-2007-0061P3CRITICALCVSS 10.0≥ 1.0, < 1.0.3≥ 2.0, < 2.0.12007-09-21
CVE-2007-0061 [CRITICAL] CWE-119 CVE-2007-0061: The DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, The DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed packet that
nvd
CVE-2007-0062P3CRITICALCVSS 10.0v1.0.3v2.02007-09-21
CVE-2007-0062 [CRITICAL] CWE-119 CVE-2007-0062: Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 5652
nvd
CVE-2009-3707P4MEDIUMCVSS 5.0PoCv2.5.0v2.5.1+5 more2009-10-16
CVE-2009-3707 [MEDIUM] CWE-134 CVE-2009-3707: VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware W VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, and VMware Serve
nvd
CVE-2005-4459P3CRITICALCVSS 10.0v1.0.12005-12-21
CVE-2005-4459 [CRITICAL] CWE-119 CVE-2005-4459: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Works Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT and (2) PORT FTP commands.
nvd
CVE-2009-2628P3CRITICALCVSS 9.3v2.5.0v2.5.1+1 more2009-09-08
CVE-2009-2628 [CRITICAL] CWE-94 CVE-2009-2628: The VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstati The VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows does not properly handle certain small heights in video content, which might allow remote attackers to execute
nvd
CVE-2009-0177P4MEDIUMCVSS 5.0PoC≤ 2.5.1v2.5.02009-01-20
CVE-2009-0177 [MEDIUM] CWE-399 CVE-2009-0177: vmwarebase.dll, as used in the vmware-authd service (aka vmware-authd.exe), in VMware Workstation 6. vmwarebase.dll, as used in the vmware-authd service (aka vmware-authd.exe), in VMware Workstation 6.5.1 build 126130, 6.5.1 and earlier; VMware Player 2.5.1 build 126130, 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 2.0.x before 2.0.1 build 156745; and VMware Fusion before 2.0.2 build 147997 allows remote attackers to cause a denial
nvd
CVE-2010-1141P3HIGHCVSS 8.5v2.5.0v2.5.1+2 more2010-04-12
CVE-2010-1141 [HIGH] CWE-264 CVE-2010-1141: VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 203138; VMware Fusion 2.x before 2.0.6 build 246742; VMware ESXi 3.5 and 4.0; and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0 does not properly access libraries, whi
nvd
CVE-2009-0909P3CRITICALCVSS 9.3v2.5.12009-04-06
CVE-2009-0909 [CRITICAL] CWE-119 CVE-2009-0909: Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware Server 2.0.x before 2.0.1 build 156745 allows remote attackers to execute arbitrary code via a crafted web page or video file, aka ZDI-CAN-435.
nvd
CVE-2009-0199P3CRITICALCVSS 9.3v2.5.0v2.5.1+1 more2009-09-08
CVE-2009-0199 [CRITICAL] CWE-119 CVE-2009-0199: Heap-based buffer overflow in the VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 Heap-based buffer overflow in the VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows might allow remote attackers to execute arbitrary code via a video file with craf
nvd
CVE-2014-6311P3CRITICALCVSS 9.8≥ 0, < 6.2.7+dfsg-22019-11-22
CVE-2014-6311 [CRITICAL] CVE-2014-6311: generate_doygen generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated privileges.
osv
CVE-2008-3691P3CRITICALCVSS 10.0≥ 1.0, < 1.0.7≥ 2.0, < 2.0.52008-09-03
CVE-2008-3691 [CRITICAL] CVE-2008-3691: Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 buil Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server befor
nvd
CVE-2008-3696P3CRITICALCVSS 10.0≥ 1.0, < 1.0.7≥ 2.0, < 2.0.52008-09-03
CVE-2008-3696 [CRITICAL] CVE-2008-3696: Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 buil Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server befor
nvd
CVE-2008-3694P3CRITICALCVSS 10.0≥ 1.0, < 1.0.7≥ 2.0, < 2.0.52008-09-03
CVE-2008-3694 [CRITICAL] CVE-2008-3694: Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 buil Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server befor
nvd
CVE-2008-3692P3CRITICALCVSS 10.0≥ 1.0, < 1.0.7≥ 2.0, < 2.0.52008-09-03
CVE-2008-3692 [CRITICAL] CVE-2008-3692: Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 buil Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server befor
nvd
CVE-2008-3693P3CRITICALCVSS 10.0≥ 1.0, < 1.0.7≥ 2.0, < 2.0.52008-09-03
CVE-2008-3693 [CRITICAL] CVE-2008-3693: Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 buil Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server befor
nvd
CVE-2008-3695P3CRITICALCVSS 10.0≥ 1.0, < 1.0.7≥ 2.0, < 2.0.52008-09-03
CVE-2008-3695 [CRITICAL] CVE-2008-3695: Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 buil Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server befor
nvd
Vmware Ace vulnerabilities | cvebase