cbcvebase.

Vmware Fusion vulnerabilities

137 known vulnerabilities affecting vmware/fusion.

Total CVEs
137
CISA KEV
2
actively exploited
Public exploits
11
Exploited in wild
6
Severity breakdown
CRITICAL10HIGH64MEDIUM58LOW5

Vulnerabilities

Page 2 of 7
CVE-2019-5514P3HIGHCVSS 8.8≥ 11.0.0, < 11.0.32019-04-01
CVE-2019-5514 [HIGH] CWE-306 CVE-2019-5514: VMware VMware Fusion (11.x before 11.0.3) contains a security vulnerability due to certain unauthent VMware VMware Fusion (11.x before 11.0.3) contains a security vulnerability due to certain unauthenticated APIs accessible through a web socket. An attacker may exploit this issue by tricking the host user to execute a JavaScript to perform unauthorized functions on the guest machine where VMware Tools is installed. This may further be exploited to exec
nvd
CVE-2011-3868P3CRITICALCVSS 9.3v3.1v3.1.1+1 more2011-10-07
CVE-2011-3868 [CRITICAL] CWE-119 CVE-2011-3868: Buffer overflow in VMware Workstation 7.x before 7.1.5, VMware Player 3.x before 3.1.5, VMware Fusio Buffer overflow in VMware Workstation 7.x before 7.1.5, VMware Player 3.x before 3.1.5, VMware Fusion 3.1.x before 3.1.3, and VMware AMS allows remote attackers to execute arbitrary code via a crafted UDF filesystem in an ISO image.
nvd
CVE-2017-4905P4MEDIUMCVSS 5.5PoC≥ 8.0.0, < 8.5.62017-06-07
CVE-2017-4905 [MEDIUM] CWE-908 CVE-2017-4905: VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have uninitialized memory usage. This issu
nvd
CVE-2009-0177P4MEDIUMCVSS 5.0PoC≤ 2.0.12009-01-20
CVE-2009-0177 [MEDIUM] CWE-399 CVE-2009-0177: vmwarebase.dll, as used in the vmware-authd service (aka vmware-authd.exe), in VMware Workstation 6. vmwarebase.dll, as used in the vmware-authd service (aka vmware-authd.exe), in VMware Workstation 6.5.1 build 126130, 6.5.1 and earlier; VMware Player 2.5.1 build 126130, 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 2.0.x before 2.0.1 build 156745; and VMware Fusion before 2.0.2 build 147997 allows remote attackers to cause a denial
nvd
CVE-2021-22045P3HIGHCVSS 7.8≥ 12.0.0, < 12.2.02022-01-04
CVE-2021-22045 [HIGH] CWE-787 CVE-2021-22045: VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Works VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A malicious actor with access to a virtual machine with CD-ROM device emulation may be able to exploit this vulnerability in conjunction with o
nvd
CVE-2010-1141P3HIGHCVSS 8.5v2.0v2.0.1+5 more2010-04-12
CVE-2010-1141 [HIGH] CWE-264 CVE-2010-1141: VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 203138; VMware Fusion 2.x before 2.0.6 build 246742; VMware ESXi 3.5 and 4.0; and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0 does not properly access libraries, whi
nvd
CVE-2021-22043P3HIGHCVSS 7.5fixed in 4.42022-02-16
CVE-2021-22043 [HIGH] CWE-367 CVE-2021-22043: VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way tempo VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled. A malicious actor with access to settingsd, may exploit this issue to escalate their privileges by writing arbitrary files.
nvd
CVE-2018-6981P3HIGHCVSS 8.8≥ 10.0.0, < 10.1.4v11.0.02018-12-04
CVE-2018-6981 [HIGH] CWE-908 CVE-2018-6981: VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMwar VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMware ESXi 6.0 without ESXi600-201811401-BG, VMware Workstation 15, VMware Workstation 14.1.3 or below, VMware Fusion 11, VMware Fusion 10.1.3 or below contain uninitialized stack memory usage in the vmxnet3 virtual network adapter which may allow a guest to
nvd
CVE-2012-1666P4MEDIUMCVSS 6.9PoC≤ 4.1.1v4.0+3 more2012-09-08
CVE-2012-1666 [MEDIUM] CVE-2012-1666: Untrusted search path vulnerability in VMware Tools in VMware Workstation before 8.0.4, VMware Playe Untrusted search path vulnerability in VMware Tools in VMware Workstation before 8.0.4, VMware Player before 4.0.4, VMware Fusion before 4.1.2, VMware View before 5.1, and VMware ESX 4.1 before U3 and 5.0 before P03 allows local users to gain privileges via a Trojan horse tpfc.dll file in the current working directory.
nvd
CVE-2017-4924P3HIGHCVSS 8.8≥ 8.0.0, < 8.5.8v8.x before 8.5.82017-09-15
CVE-2017-4924 [HIGH] CWE-787 CVE-2017-4924: VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusi VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusion (8.x before 8.5.8) contain an out-of-bounds write vulnerability in SVGA device. This issue may allow a guest to execute code on the host.
nvd
CVE-2023-20869P3HIGHCVSS 8.2≥ 13.0.0, < 13.0.22023-04-25
CVE-2023-20869 [HIGH] CWE-787 CVE-2023-20869: VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerabili VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.
nvd
CVE-2018-6983P3HIGHCVSS 8.8≥ 10.0.0, < 10.1.5≥ 11.0.0, < 11.0.22018-11-27
CVE-2018-6983 [HIGH] CWE-190 CVE-2018-6983: VMware Workstation (15.x before 15.0.2 and 14.x before 14.1.5) and Fusion (11.x before 11.0.2 and 10 VMware Workstation (15.x before 15.0.2 and 14.x before 14.1.5) and Fusion (11.x before 11.0.2 and 10.x before 10.1.5) contain an integer overflow vulnerability in the virtual network devices. This issue may allow a guest to execute code on the host.
nvd
CVE-2019-5541P3CRITICALCVSS 9.1≥ 11.0.0, < 11.5.12019-11-20
CVE-2019-5541 [CRITICAL] CWE-787 CVE-2019-5541: VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds wri VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in the e1000e virtual network adapter. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to create a denial-of-service condition on their own VM.
nvd
CVE-2018-6965P3HIGHCVSS 8.1≥ 10.0, < 10.1.22018-07-09
CVE-2018-6965 [HIGH] CWE-125 CVE-2018-6965: VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x be VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash their VMs, a different vulnerability th
nvd
CVE-2016-7461P3HIGHCVSS 8.8v8.0.0v8.0.1+5 more2016-12-29
CVE-2016-7461 [HIGH] CWE-119 CVE-2016-7461: The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Worksta The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion and Fusion Pro 8.x before 8.5.2 allows guest OS users to execute arbitrary code on the host OS or cause a denial of service (out-of-bounds memory access on the host OS) via unspecified vectors.
nvd
CVE-2012-3288P3CRITICALCVSS 9.3v4.0v4.0.1+4 more2012-06-14
CVE-2012-3288 [CRITICAL] CWE-20 CVE-2012-3288: VMware Workstation 7.x before 7.1.6 and 8.x before 8.0.4, VMware Player 3.x before 3.1.6 and 4.x bef VMware Workstation 7.x before 7.1.6 and 8.x before 8.0.4, VMware Player 3.x before 3.1.6 and 4.x before 4.0.4, VMware Fusion 4.x before 4.1.3, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 allow user-assisted remote attackers to execute arbitrary code on the host OS or cause a denial of service (memory corruption) on the host OS via a c
nvd
CVE-2020-3947P3HIGHCVSS 8.8fixed in 11.5.2v11.x before 11.5.22020-03-16
CVE-2020-3947 [HIGH] CWE-416 CVE-2020-3947: VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerab VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerability in vmnetdhcp. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to create a denial-of-service condition of the vmnetdhcp service running on the host machine.
nvd
CVE-2018-6967P3HIGHCVSS 8.1≥ 10.0, < 10.1.22018-07-09
CVE-2018-6967 [HIGH] CVE-2018-6967: VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x be VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash their VMs, a different vulnerability than CVE-2
nvd
CVE-2018-6966P3HIGHCVSS 8.1≥ 10.0, < 10.1.22018-07-09
CVE-2018-6966 [HIGH] CVE-2018-6966: VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x be VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash their VMs, a different vulnerability than CVE-2
nvd
CVE-2018-6973P3HIGHCVSS 8.8fixed in 10.1.3v10.x before 10.1.32018-08-15
CVE-2018-6973 [HIGH] CWE-787 CVE-2018-6973: VMware Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds wri VMware Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds write vulnerability in the e1000 device. This issue may allow a guest to execute code on the host.
nvd
Vmware Fusion vulnerabilities | cvebase