cbcvebase.

Vmware Fusion vulnerabilities

137 known vulnerabilities affecting vmware/fusion.

Total CVEs
137
CISA KEV
2
actively exploited
Public exploits
11
Exploited in wild
6
Severity breakdown
CRITICAL10HIGH64MEDIUM58LOW5

Vulnerabilities

Page 4 of 7
CVE-2020-3982P3HIGHCVSS 7.7≥ 11.0, < 11.5.62020-10-20
CVE-2020-3982 [HIGH] CWE-367 CVE-2020-3982: VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650 VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds write vulnerability due to a time-of-check time-of-use issue in ACPI device. A malicious actor with administrative access to a virtual machine may be able to exploit
nvd
CVE-2020-3962P3HIGHCVSS 8.2≥ 11.0.0, < 11.5.5v11.x before 11.5.52020-06-24
CVE-2020-3962 [HIGH] CWE-416 CVE-2020-3962: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESX VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain a use-after-free vulnerability in the SVGA device. A malicious actor with local access to a virtual machine with 3D graphics enabled may be able to exploit this
nvd
CVE-2020-3968P3HIGHCVSS 8.2≥ 11.0.0, < 11.5.5v11.x before 11.5.52020-06-25
CVE-2020-3968 [HIGH] CWE-787 CVE-2020-3968: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESX VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds write vulnerability in the USB 3.0 controller (xHCI). A malicious actor with local administrative privileges on a virtual machine may be able to
nvd
CVE-2020-4004P3HIGHCVSS 8.2≥ 11.0, < 11.5.72020-11-20
CVE-2020-4004 [HIGH] CWE-416 CVE-2020-4004: VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-2020 VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x before 15.5.7), Fusion (11.x before 11.5.7) contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code
nvd
CVE-2019-5516P3MEDIUMCVSS 6.8≥ 10.0.0, < 10.1.6≥ 11.0.0, < 11.0.3+2 more2019-04-15
CVE-2019-5516 [MEDIUM] CWE-125 CVE-2019-5516: VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x be VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before 10.1.6) updates address an out-of-bounds vulnerability with the vertex shader functionality. Exploitation of this issue requires an attacker to have access to a virtual mach
nvd
CVE-2010-1142P3HIGHCVSS 8.5v2.0v2.0.1+5 more2010-04-12
CVE-2010-1142 [HIGH] CWE-264 CVE-2010-1142: VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 203138; VMware Fusion 2.x before 2.0.6 build 246742; VMware ESXi 3.5 and 4.0; and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0 does not properly load VMware programs,
nvd
CVE-2019-5542P3HIGHCVSS 7.7≥ 11.0.0, < 11.5.12019-11-20
CVE-2019-5542 [HIGH] CVE-2019-5542: VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain a denial-of-service VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain a denial-of-service vulnerability in the RPC handler. Successful exploitation of this issue may allow attackers with normal user privileges to create a denial-of-service condition on their own VM.
nvd
CVE-2020-3967P3HIGHCVSS 7.5≥ 11.0.0, < 11.5.5v11.x before 11.5.52020-06-25
CVE-2020-3967 [HIGH] CWE-787 CVE-2020-3967: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESX VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain a heap-overflow vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local access to a virtual machine may be able to exploit this vulnerabilit
nvd
CVE-2020-3966P3HIGHCVSS 7.5≥ 11.0.0, < 11.5.2v11.x before 11.5.22020-06-25
CVE-2020-3966 [HIGH] CWE-362 CVE-2020-3966: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESX VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a heap-overflow due to a race condition issue in the USB 2.0 controller (EHCI). A malicious actor with local access to a virtual machine may be able to exploit t
nvd
CVE-2018-6962P3HIGHCVSS 7.8≥ 10.0, < 10.1.2v10.x before 10.1.22018-05-22
CVE-2018-6962 [HIGH] CVE-2018-6962: VMware Fusion (10.x before 10.1.2) contains a signature bypass vulnerability which may lead to a loc VMware Fusion (10.x before 10.1.2) contains a signature bypass vulnerability which may lead to a local privilege escalation.
nvd
CVE-2026-41702P3HIGHCVSS 7.0fixed in 26h1≥ 2025H2, < 2026H12026-05-15
CVE-2026-41702 [HIGH] CWE-367 CVE-2026-41702: VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an oper VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed.
nvd
CVE-2012-1518P4HIGHCVSS 8.3v4.0v4.0.1+3 more2012-04-17
CVE-2012-1518 [HIGH] CWE-264 CVE-2012-1518: VMware Workstation 8.x before 8.0.2, VMware Player 4.x before 4.0.2, VMware Fusion 4.x before 4.1.2, VMware Workstation 8.x before 8.0.2, VMware Player 4.x before 4.0.2, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 use an incorrect ACL for the VMware Tools folder, which allows guest OS users to gain guest OS privileges via unspecified vectors.
nvd
CVE-2015-2341P4HIGHCVSS 7.8v6.0v6.0.1+8 more2015-06-13
CVE-2015-2341 [HIGH] CWE-20 CVE-2015-2341: VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.6, and VMware Fusion 6.x before VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.6, and VMware Fusion 6.x before 6.0.6 and 7.x before 7.0.1 allow attackers to cause a denial of service against a 32-bit guest OS or 64-bit host OS via a crafted RPC command.
nvd
CVE-2014-8370P4MEDIUMCVSS 6.4v6.0v6.0.1+3 more2015-01-29
CVE-2014-8370 [MEDIUM] CWE-264 CVE-2014-8370: VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, VMware Fusion 6.x before 6.0. VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, VMware Fusion 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allow host OS users to gain host OS privileges or cause a denial of service (arbitrary write to a file) by modifying a configuration file.
nvd
CVE-2019-5536P4MEDIUMCVSS 6.5≥ 11.0.0, < 11.5.02019-10-28
CVE-2019-5536 [MEDIUM] CVE-2019-5536: VMware ESXi (6.7 before ESXi670-201908101-SG and 6.5 before ESXi650-201910401-SG), Workstation (15.x VMware ESXi (6.7 before ESXi670-201908101-SG and 6.5 before ESXi650-201910401-SG), Workstation (15.x before 15.5.0) and Fusion (11.x before 11.5.0) contain a denial-of-service vulnerability in the shader functionality. Successful exploitation of this issue may allow attackers with normal user privileges to create a denial-of-service condition on their own VM.
nvd
CVE-2019-5517P4MEDIUMCVSS 6.8≥ 10.0.0, < 10.1.6≥ 11.0.0, < 11.0.3+2 more2019-04-15
CVE-2019-5517 [MEDIUM] CWE-125 CVE-2019-5517: VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x be VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before 10.1.6) contain multiple out-of-bounds read vulnerabilities in the shader translator. Exploitation of these issues requires an attacker to have access to a virtual machine w
nvd
CVE-2025-41239P3HIGHCVSS 7.1≥ 13.x, < 13.6.42025-07-15
CVE-2025-41239 [HIGH] CWE-908 CVE-2025-41239: VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to leak memory from processes communicating with vSockets.
nvd
CVE-2015-6933P3MEDIUMCVSS 6.3v7.0v7.1+1 more2016-01-09
CVE-2015-6933 [MEDIUM] CWE-284 CVE-2015-6933: The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2, VMware Fusion 7.x before 7.1.2, and VMware ESXi 5.0 through 6.0 allows Windows guest OS users to gain guest OS privileges or cause a denial of service (guest OS kernel memory corruption) via unspecified vectors.
nvd
CVE-2018-6972P4MEDIUMCVSS 6.5≥ 10.0, < 10.1.2v10.x before 10.1.22018-07-25
CVE-2018-6972 [MEDIUM] CWE-476 CVE-2018-6972: VMware ESXi (6.7 before ESXi670-201806401-BG, 6.5 before ESXi650-201806401-BG, 6.0 before ESXi600-20 VMware ESXi (6.7 before ESXi670-201806401-BG, 6.5 before ESXi650-201806401-BG, 6.0 before ESXi600-201806401-BG and 5.5 before ESXi550-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain a denial-of-service vulnerability due to NULL pointer dereference issue in RPC handler. Successful exploitation of this issue may
nvd
CVE-2008-2100P4HIGHCVSS 7.2≤ 1.1.12008-06-05
CVE-2008-2100 [HIGH] CWE-119 CVE-2008-2100: Multiple buffer overflows in VIX API 1.1.x before 1.1.4 build 93057 on VMware Workstation 5.x and 6. Multiple buffer overflows in VIX API 1.1.x before 1.1.4 build 93057 on VMware Workstation 5.x and 6.x, VMware Player 1.x and 2.x, VMware ACE 2.x, VMware Server 1.x, VMware Fusion 1.x, VMware ESXi 3.5, and VMware ESX 3.0.1 through 3.5 allow guest OS users to execute arbitrary code on the host OS via unspecified vectors.
nvd
Vmware Fusion vulnerabilities | cvebase