cbcvebase.

Vmware Esx vulnerabilities

89 known vulnerabilities affecting vmware/esx.

Total CVEs
89
CISA KEV
2
actively exploited
Public exploits
13
Exploited in wild
6
Severity breakdown
CRITICAL14HIGH33MEDIUM36LOW6

Vulnerabilities

Page 5 of 5
CVE-2009-1805P4MEDIUMCVSS 4.0v3.0.2v3.0.3+1 more2009-06-01
CVE-2009-1805 [MEDIUM] CVE-2009-1805: Unspecified vulnerability in the VMware Descheduled Time Accounting driver in VMware Workstation 6.5 Unspecified vulnerability in the VMware Descheduled Time Accounting driver in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, VMware Server 1.x before 1.0.9 build 156507 and 2.x before 2.0.1 build 156745, VMware Fusion 2.x before 2.0.2 build 147997, VMware ESXi 3.5, and VMware ESX 3.0.2, 3.0.3, and 3.5, whe
nvd
CVE-2005-4773P4MEDIUMCVSS 4.9≤ 2.5.2v1.5.2+5 more2005-12-31
CVE-2005-4773 [MEDIUM] CVE-2005-4773: The configuration of VMware ESX Server 2.x, 2.0.x, 2.1.x, and 2.5.x allows local users to cause a de The configuration of VMware ESX Server 2.x, 2.0.x, 2.1.x, and 2.5.x allows local users to cause a denial of service (shutdown) via the (1) halt, (2) poweroff, and (3) reboot scripts executed at the service console.
nvd
CVE-2014-1208P4LOWCVSS 3.3v4.0v4.12014-01-17
CVE-2014-1208 [LOW] CVE-2014-1208: VMware Workstation 9.x before 9.0.1, VMware Player 5.x before 5.0.1, VMware Fusion 5.x before 5.0.1, VMware Workstation 9.x before 9.0.1, VMware Player 5.x before 5.0.1, VMware Fusion 5.x before 5.0.1, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1 allow guest OS users to cause a denial of service (VMX process disruption) by using an invalid port.
nvd
CVE-2026-41709P4LOWCVSS 2.7≥ 9.1.x.x, < ESXi-9.1.0.0-25370933≥ 9.0.x.x, < ESXi-9.0.2.0100-25595025+1 more2026-07-30
CVE-2026-41709 [LOW] CWE-778 CVE-2026-41709: VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit t VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.
nvd
CVE-2008-4914P4MEDIUMCVSS 4.7v3.52009-02-03
CVE-2008-4914 [MEDIUM] CVE-2008-4914: Unspecified vulnerability in VMware ESXi 3.5 before ESXe350-200901401-I-SG and ESX 3.5 before ESX350 Unspecified vulnerability in VMware ESXi 3.5 before ESXe350-200901401-I-SG and ESX 3.5 before ESX350-200901401-SG allows local administrators to cause a denial of service (host crash) via a snapshot with a malformed VMDK delta disk.
nvd
CVE-2005-3620P4LOWCVSS 2.1≥ 2.0.1, < 2.0.2≥ 2.1.1, < 2.1.3+1 more2005-12-31
CVE-2005-3620 [LOW] CVE-2005-3620: The management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch The management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch 1, and 2.x before 2.5.3 patch 2 records passwords in cleartext in URLs that are stored in world-readable web server log files, which allows local users to gain privileges.
nvd
CVE-2011-2146P4LOWCVSS 2.1v3.0.3v3.5+2 more2011-06-06
CVE-2011-2146 [LOW] CWE-200 CVE-2011-2146: mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, V mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.1.x before 3.1.3, VMware ESXi 3.5 through 4.1, and VMware ESX 3.0.3 through 4.1 allows guest OS users to determine the existence of host OS files and directories via unspecified vectors.
nvd
CVE-2006-3589P4LOWCVSS 3.6v2.0v2.0.1+5 more2006-07-21
CVE-2006-3589 [LOW] CVE-2006-3589: vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the SSL key.
nvd
CVE-2008-2101P4LOWCVSS 2.1v3.0.1v3.0.2+2 more2008-09-03
CVE-2008-2101 [LOW] CWE-200 CVE-2008-2101: The VMware Consolidated Backup (VCB) command-line utilities in VMware ESX 3.0.1 through 3.0.3 and ES The VMware Consolidated Backup (VCB) command-line utilities in VMware ESX 3.0.1 through 3.0.3 and ESX 3.5 place a password on the command line, which allows local users to obtain sensitive information by listing the process.
nvd
Vmware Esx vulnerabilities | cvebase