cbcvebase.

Vmware Esx vulnerabilities

86 known vulnerabilities affecting vmware/esx.

Total CVEs
86
CISA KEV
2
actively exploited
Public exploits
13
Exploited in wild
6
Severity breakdown
CRITICAL13HIGH32MEDIUM36LOW5

Vulnerabilities

Page 2 of 5
CVE-2008-2097P3CRITICALCVSS 9.0v3.52008-06-05
CVE-2008-2097 [CRITICAL] CWE-119 CVE-2008-2097: Buffer overflow in the openwsman management service in VMware ESXi 3.5 and ESX 3.5 allows remote aut Buffer overflow in the openwsman management service in VMware ESXi 3.5 and ESX 3.5 allows remote authenticated users to gain privileges via an "invalid Content-Length."
nvd
CVE-2012-2449P3CRITICALCVSS 9.0v3.5v4.0+1 more2012-05-04
CVE-2012-2449 [CRITICAL] CWE-119 CVE-2012-2449: VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x through 4.1.2 VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x through 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 do not properly configure the virtual floppy device, which allows guest OS users to cause a denial of service (out-of-bounds write operation and VMX process crash) or possibly execute arbit
nvd
CVE-2012-2450P3CRITICALCVSS 9.0v3.5v4.0+1 more2012-05-04
CVE-2012-2450 [CRITICAL] CVE-2012-2450: VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x before 4.1.2, VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 do not properly register SCSI devices, which allows guest OS users to cause a denial of service (invalid write operation and VMX process crash) or possibly execute arbitrary code on the host OS by l
nvd
CVE-2012-1517P3CRITICALCVSS 9.0v4.12012-05-04
CVE-2012-1517 [CRITICAL] CWE-119 CVE-2012-1517: The VMX process in VMware ESXi 4.1 and ESX 4.1 does not properly handle RPC commands, which allows g The VMX process in VMware ESXi 4.1 and ESX 4.1 does not properly handle RPC commands, which allows guest OS users to cause a denial of service (memory overwrite and process crash) or possibly execute arbitrary code on the host OS via vectors involving function pointers.
nvd
CVE-2013-3657P3HIGHCVSS 7.5v4.0v4.12013-09-10
CVE-2013-3657 [HIGH] CWE-119 CVE-2013-3657: Buffer overflow in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to exec Buffer overflow in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors.
nvd
CVE-2009-3621P4MEDIUMCVSS 5.5PoCv4.02009-10-22
CVE-2009-3621 [MEDIUM] CWE-400 CVE-2009-3621: net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing a series of connect operations to this socket.
nvd
CVE-2012-2448P3HIGHCVSS 7.5v3.5v4.0+1 more2012-05-04
CVE-2012-2448 [HIGH] CWE-119 CVE-2012-2448: VMware ESXi 3.5 through 5.0 and ESX 3.5 through 4.1 allow remote attackers to execute arbitrary code VMware ESXi 3.5 through 5.0 and ESX 3.5 through 4.1 allow remote attackers to execute arbitrary code or cause a denial of service (memory overwrite) via NFS traffic.
nvd
CVE-2011-0355P3HIGHCVSS 7.8v4.0v4.12011-02-17
CVE-2011-0355 [HIGH] CWE-399 CVE-2011-0355: Cisco Nexus 1000V Virtual Ethernet Module (VEM) 4.0(4) SV1(1) through SV1(3b), as used in VMware ESX Cisco Nexus 1000V Virtual Ethernet Module (VEM) 4.0(4) SV1(1) through SV1(3b), as used in VMware ESX 4.0 and 4.1 and ESXi 4.0 and 4.1, does not properly handle dropped packets, which allows guest OS users to cause a denial of service (ESX or ESXi host OS crash) by sending an 802.1Q tagged packet over an access vEthernet port, aka Cisco Bug ID CSCtj17451
nvd
CVE-2010-1142P3HIGHCVSS 8.5v2.5.5v3.0.3+2 more2010-04-12
CVE-2010-1142 [HIGH] CWE-264 CVE-2010-1142: VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 203138; VMware Fusion 2.x before 2.0.6 build 246742; VMware ESXi 3.5 and 4.0; and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0 does not properly load VMware programs,
nvd
CVE-2008-4281P3CRITICALCVSS 9.3≤ 3.52008-11-10
CVE-2008-4281 [CRITICAL] CWE-22 CVE-2008-4281: Directory traversal vulnerability in VMWare ESXi 3.5 before ESXe350-200810401-O-UG and ESX 3.5 befor Directory traversal vulnerability in VMWare ESXi 3.5 before ESXe350-200810401-O-UG and ESX 3.5 before ESX350-200810201-UG allows administrators with the Datastore.FileManagement privilege to gain privileges via unknown vectors.
nvd
CVE-2010-4251P3HIGHCVSS 7.5v4.0v4.12011-05-26
CVE-2010-4251 [HIGH] CWE-400 CVE-2010-4251: The socket implementation in net/core/sock.c in the Linux kernel before 2.6.34 does not properly man The socket implementation in net/core/sock.c in the Linux kernel before 2.6.34 does not properly manage a backlog of received packets, which allows remote attackers to cause a denial of service (memory consumption) by sending a large amount of network traffic, as demonstrated by netperf UDP tests.
nvd
CVE-2012-1518P4HIGHCVSS 8.3v3.5v4.0+1 more2012-04-17
CVE-2012-1518 [HIGH] CWE-264 CVE-2012-1518: VMware Workstation 8.x before 8.0.2, VMware Player 4.x before 4.0.2, VMware Fusion 4.x before 4.1.2, VMware Workstation 8.x before 8.0.2, VMware Player 4.x before 4.0.2, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 use an incorrect ACL for the VMware Tools folder, which allows guest OS users to gain guest OS privileges via unspecified vectors.
nvd
CVE-2010-4263P4HIGHCVSS 7.9v3.0.0v3.0.1+5 more2011-01-18
CVE-2010-4263 [HIGH] CWE-476 CVE-2010-4263: The igb_receive_skb function in drivers/net/igb/igb_main.c in the Intel Gigabit Ethernet (aka igb) s The igb_receive_skb function in drivers/net/igb/igb_main.c in the Intel Gigabit Ethernet (aka igb) subsystem in the Linux kernel before 2.6.34, when Single Root I/O Virtualization (SR-IOV) and promiscuous mode are enabled but no VLANs are registered, allows remote attackers to cause a denial of service (NULL pointer dereference and panic) and possibly h
nvd
CVE-2010-2492P4HIGHCVSS 7.8v4.0v4.12010-09-08
CVE-2010-2492 [HIGH] CWE-120 CVE-2010-2492: Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash) via unspecified vectors.
nvd
CVE-2010-2524P4HIGHCVSS 7.8v4.0v4.12010-09-08
CVE-2010-2524 [HIGH] CVE-2010-2524: The DNS resolution functionality in the CIFS implementation in the Linux kernel before 2.6.35, when The DNS resolution functionality in the CIFS implementation in the Linux kernel before 2.6.35, when CONFIG_CIFS_DFS_UPCALL is enabled, relies on a user's keyring for the dns_resolver upcall in the cifs.upcall userspace helper, which allows local users to spoof the results of DNS queries and perform arbitrary CIFS mounts via vectors involving an add_key call, rel
nvd
CVE-2009-0034P4HIGHCVSS 7.8v4.02009-01-30
CVE-2009-0034 [HIGH] CWE-863 CVE-2009-0034: parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.
nvd
CVE-2012-1515P4HIGHCVSS 8.3v3.5v4.0+1 more2012-04-02
CVE-2012-1515 [HIGH] CWE-264 CVE-2012-1515: VMware ESXi 3.5, 4.0, and 4.1 and ESX 3.5, 4.0, and 4.1 do not properly implement port-based I/O ope VMware ESXi 3.5, 4.0, and 4.1 and ESX 3.5, 4.0, and 4.1 do not properly implement port-based I/O operations, which allows guest OS users to gain guest OS privileges by overwriting memory locations in a read-only memory block associated with the Virtual DOS Machine.
nvd
CVE-2012-3289P4HIGHCVSS 7.8v3.5v4.0+1 more2012-06-14
CVE-2012-3289 [HIGH] CWE-94 CVE-2012-3289: VMware Workstation 8.x before 8.0.4, VMware Player 4.x before 4.0.4, VMware ESXi 3.5 through 5.0, an VMware Workstation 8.x before 8.0.4, VMware Player 4.x before 4.0.4, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 allow remote attackers to cause a denial of service (guest OS crash) via crafted traffic from a remote virtual device.
nvd
CVE-2008-2100P4HIGHCVSS 7.2v2.5.4v2.5.5+4 more2008-06-05
CVE-2008-2100 [HIGH] CWE-119 CVE-2008-2100: Multiple buffer overflows in VIX API 1.1.x before 1.1.4 build 93057 on VMware Workstation 5.x and 6. Multiple buffer overflows in VIX API 1.1.x before 1.1.4 build 93057 on VMware Workstation 5.x and 6.x, VMware Player 1.x and 2.x, VMware ACE 2.x, VMware Server 1.x, VMware Fusion 1.x, VMware ESXi 3.5, and VMware ESX 3.0.1 through 3.5 allow guest OS users to execute arbitrary code on the host OS via unspecified vectors.
nvd
CVE-2011-1785P4HIGHCVSS 7.8v4.0v4.12011-05-03
CVE-2011-1785 [HIGH] CWE-399 CVE-2011-1785: VMware ESXi 4.0 and 4.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (soc VMware ESXi 4.0 and 4.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (socket exhaustion) via unspecified network traffic.
nvd
Vmware Esx vulnerabilities | cvebase