Vmware Esx vulnerabilities
86 known vulnerabilities affecting vmware/esx.
Total CVEs
86
CISA KEV
2
actively exploited
Public exploits
13
Exploited in wild
6
Severity breakdown
CRITICAL13HIGH32MEDIUM36LOW5
Vulnerabilities
Page 4 of 5
CVE-2009-2416P4MEDIUMCVSS 6.5v3.0.3v3.5+1 more2009-08-11
CVE-2009-2416 [MEDIUM] CWE-416 CVE-2009-2416: Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and l
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
nvd
CVE-2012-5703P4MEDIUMCVSS 5.0v4.12012-11-20
CVE-2012-5703 [MEDIUM] CWE-20 CVE-2012-5703: The vSphere API in VMware ESXi 4.1 and ESX 4.1 allows remote attackers to cause a denial of service
The vSphere API in VMware ESXi 4.1 and ESX 4.1 allows remote attackers to cause a denial of service (host daemon crash) via an invalid value in a (1) RetrieveProp or (2) RetrievePropEx SOAP request.
nvd
CVE-2010-2942P4MEDIUMCVSS 5.5v4.0v4.12010-09-21
CVE-2010-2942 [MEDIUM] CWE-401 CVE-2010-2942: The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-r
The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the tcf_gact_dump function in net/sched/act_gac
nvd
CVE-2010-3078P4MEDIUMCVSS 5.5v4.0v4.12010-09-21
CVE-2010-3078 [MEDIUM] CWE-200 CVE-2010-3078: The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc
The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc4 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an ioctl call.
nvd
CVE-2010-4655P4MEDIUMCVSS 5.5v4.0v4.12011-07-18
CVE-2010-4655 [MEDIUM] CWE-665 CVE-2010-4655: net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize certain data structures, wh
net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability for an ethtool ioctl call.
nvd
CVE-2005-3619P4MEDIUMCVSS 6.8v2.0v2.0.1+4 more2005-12-31
CVE-2005-3619 [MEDIUM] CVE-2005-3619: Cross-site scripting (XSS) vulnerability in the management interface for VMware ESX 2.5.x before 2.5
Cross-site scripting (XSS) vulnerability in the management interface for VMware ESX 2.5.x before 2.5.2 upgrade patch 2, 2.1.x before 2.1.2 upgrade patch 6, and 2.0.x before 2.0.1 upgrade patch 6 allows remote attackers to inject arbitrary web script or HTML via messages that are not sanitized when viewing syslog log files.
nvd
CVE-2008-4279P4MEDIUMCVSS 6.8≥ 2.5.4, ≤ 3.52008-10-06
CVE-2008-4279 [MEDIUM] CWE-264 CVE-2008-4279: The CPU hardware emulation for 64-bit guest operating systems in VMware Workstation 6.0.x before 6.0
The CPU hardware emulation for 64-bit guest operating systems in VMware Workstation 6.0.x before 6.0.5 build 109488 and 5.x before 5.5.8 build 108000; Player 2.0.x before 2.0.5 build 109488 and 1.x before 1.0.8; Server 1.x before 1.0.7 build 108231; and ESX 2.5.4 through 3.5 allows authenticated guest OS users to gain additional guest OS privileges by
nvd
CVE-2007-5671P4MEDIUMCVSS 4.4v2.5.4v3.0.0+2 more2008-06-05
CVE-2007-5671 [MEDIUM] CWE-20 CVE-2007-5671: HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Play
HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Player before 1.0.6 build 80404, VMware ACE before 1.0.5 build 79846, VMware Server before 1.0.5 build 80187, and VMware ESX 2.5.4 through 3.0.2 does not properly validate arguments in user-mode METHOD_NEITHER IOCTLs to the \\.\hgfs device, which allows gues
nvd
CVE-2005-4583P4MEDIUMCVSS 4.3v2.0v2.0.1+4 more2005-12-29
CVE-2005-4583 [MEDIUM] CWE-79 CVE-2005-4583: Unspecified vulnerability in the Management Interface in VMware ESX Server 2.x up to 2.5.x before 24
Unspecified vulnerability in the Management Interface in VMware ESX Server 2.x up to 2.5.x before 24 December 2005 allows "remote code execution in the Web browser" via unspecified attack vectors, probably related to cross-site scripting (XSS).
nvd
CVE-2010-2066P4MEDIUMCVSS 5.5v4.0v4.12010-09-08
CVE-2010-2066 [MEDIUM] CVE-2010-2066: The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows
The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a MOVE_EXT ioctl call that specifies this file as a donor.
nvd
CVE-2014-1207P4MEDIUMCVSS 4.3v4.0v4.12014-01-17
CVE-2014-1207 [MEDIUM] CVE-2014-1207: VMware ESXi 4.0 through 5.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service
VMware ESXi 4.0 through 5.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (NULL pointer dereference) by intercepting and modifying Network File Copy (NFC) traffic.
nvd
CVE-2008-0967P4MEDIUMCVSS 6.9v3.0.0v3.0.1+1 more2008-06-05
CVE-2008-0967 [MEDIUM] CVE-2008-0967: Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 917
Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware Player 1.x before 1.0.7 build 91707 and 2.x before 2.0.4 build 93057, and VMware Server before 1.0.6 build 91891 on Linux, and VMware ESXi 3.5 and VMware ESX 2.5.4 through 3.5, allows local users to gain privileges vi
nvd
CVE-2013-5973P4MEDIUMCVSS 4.4v4.0v4.12013-12-23
CVE-2013-5973 [MEDIUM] CWE-264 CVE-2013-5973: VMware ESXi 4.0 through 5.5 and ESX 4.0 and 4.1 allow local users to read or modify arbitrary files
VMware ESXi 4.0 through 5.5 and ESX 4.0 and 4.1 allow local users to read or modify arbitrary files by leveraging the Virtual Machine Power User or Resource Pool Administrator role for a vCenter Server Add Existing Disk action with a (1) -flat, (2) -rdm, or (3) -rdmp filename.
nvd
CVE-2010-4343P4MEDIUMCVSS 5.5v4.0v4.12010-12-29
CVE-2010-4343 [MEDIUM] CWE-665 CVE-2010-4343: drivers/scsi/bfa/bfa_core.c in the Linux kernel before 2.6.35 does not initialize a certain port dat
drivers/scsi/bfa/bfa_core.c in the Linux kernel before 2.6.35 does not initialize a certain port data structure, which allows local users to cause a denial of service (system crash) via read operations on an fc_host statistics file.
nvd
CVE-2007-1271P4MEDIUMCVSS 6.6v3.0.0v3.0.12007-04-06
CVE-2007-1271 [MEDIUM] CVE-2007-1271: Buffer overflow in VMware ESX Server 3.0.0 and 3.0.1 might allow attackers to gain privileges or cau
Buffer overflow in VMware ESX Server 3.0.0 and 3.0.1 might allow attackers to gain privileges or cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2009-1072P4MEDIUMCVSS 4.9v3.0.3v3.5+1 more2009-03-25
CVE-2009-1072 [MEDIUM] CWE-16 CVE-2009-1072: nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a us
nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.
nvd
CVE-2009-1630P4MEDIUMCVSS 4.4v2.5.5v3.0.3+2 more2009-05-14
CVE-2009-1630 [MEDIUM] CWE-264 CVE-2009-1630: The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6
The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions and execute files, as demonstrated by files on an NFSv4 fileserver.
nvd
CVE-2013-1661P4MEDIUMCVSS 4.3v4.0v4.12013-09-04
CVE-2013-1661 [MEDIUM] CWE-20 CVE-2013-1661: VMware ESXi 4.0 through 5.1, and ESX 4.0 and 4.1, does not properly implement the Network File Copy
VMware ESXi 4.0 through 5.1, and ESX 4.0 and 4.1, does not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to cause a denial of service (unhandled exception and application crash) by modifying the client-server data stream.
nvd
CVE-2009-1805P4MEDIUMCVSS 4.0v3.0.2v3.0.3+1 more2009-06-01
CVE-2009-1805 [MEDIUM] CVE-2009-1805: Unspecified vulnerability in the VMware Descheduled Time Accounting driver in VMware Workstation 6.5
Unspecified vulnerability in the VMware Descheduled Time Accounting driver in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, VMware Server 1.x before 1.0.9 build 156507 and 2.x before 2.0.1 build 156745, VMware Fusion 2.x before 2.0.2 build 147997, VMware ESXi 3.5, and VMware ESX 3.0.2, 3.0.3, and 3.5, whe
nvd
CVE-2005-4773P4MEDIUMCVSS 4.9≤ 2.5.2v1.5.2+5 more2005-12-31
CVE-2005-4773 [MEDIUM] CVE-2005-4773: The configuration of VMware ESX Server 2.x, 2.0.x, 2.1.x, and 2.5.x allows local users to cause a de
The configuration of VMware ESX Server 2.x, 2.0.x, 2.1.x, and 2.5.x allows local users to cause a denial of service (shutdown) via the (1) halt, (2) poweroff, and (3) reboot scripts executed at the service console.
nvd