Vmware Fusion vulnerabilities
137 known vulnerabilities affecting vmware/fusion.
Total CVEs
137
CISA KEV
2
actively exploited
Public exploits
11
Exploited in wild
6
Severity breakdown
CRITICAL10HIGH64MEDIUM58LOW5
Vulnerabilities
Page 6 of 7
CVE-2024-22268P4MEDIUMCVSS 6.5≥ 13.0.0, < 13.5.22024-05-14
CVE-2024-22268 [MEDIUM] CWE-787 CVE-2024-22268: VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionali
VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to create a denial of service condition.
nvd
CVE-2011-1787P4MEDIUMCVSS 6.9v3.1v3.1.1+1 more2011-06-06
CVE-2011-1787 [MEDIUM] CWE-362 CVE-2011-1787: Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1
Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.1.x before 3.1.3, VMware ESXi 3.5 through 4.1, and VMware ESX 3.0.3 through 4.1 allows guest OS users to gain privileges on the guest OS by mounting a filesystem on top of an arbitrary d
nvd
CVE-2024-22270P4MEDIUMCVSS 6.0≥ 13.0.0, < 13.5.22024-05-14
CVE-2024-22270 [MEDIUM] CWE-200 CVE-2024-22270: VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File
VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.
nvd
CVE-2018-6957P4MEDIUMCVSS 5.3v8.0v8.0.1+15 more2018-03-15
CVE-2018-6957 [MEDIUM] CWE-772 CVE-2018-6957: VMware Workstation (14.x before 14.1.1, 12.x) and Fusion (10.x before 10.1.1 and 8.x) contain a deni
VMware Workstation (14.x before 14.1.1, 12.x) and Fusion (10.x before 10.1.1 and 8.x) contain a denial-of-service vulnerability which can be triggered by opening a large number of VNC sessions. Note: In order for exploitation to be possible on Workstation and Fusion, VNC must be manually enabled.
nvd
CVE-2020-3995P4MEDIUMCVSS 5.3≥ 11.0.0, < 11.1.02020-10-20
CVE-2020-3995 [MEDIUM] CWE-401 CVE-2020-3995: In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x
In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x before 15.1.0), Fusion (11.x before 11.1.0), the VMCI host drivers used by VMware hypervisors contain a memory leak vulnerability. A malicious actor with access to a virtual machine may be able to trigger a memory leak issue resulting in memory resourc
nvd
CVE-2020-3965P4MEDIUMCVSS 5.5≥ 11.0.0, < 11.5.2v11.x before 11.5.22020-06-25
CVE-2020-3965 [MEDIUM] CWE-125 CVE-2020-3965: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESX
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain an information leak in the XHCI USB controller. A malicious actor with local access to a virtual machine may be able to read privileged information contained i
nvd
CVE-2020-3963P4MEDIUMCVSS 5.5≥ 11.0.0, < 11.5.2v11.x before 11.5.22020-06-25
CVE-2020-3963 [MEDIUM] CWE-416 CVE-2020-3963: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESX
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a use-after-free vulnerability in PVNVRAM. A malicious actor with local access to a virtual machine may be able to read privileged information contained in phy
nvd
CVE-2020-3971P4MEDIUMCVSS 5.5≥ 11.0.0, < 11.0.2v11.x before 11.0.22020-06-25
CVE-2020-3971 [MEDIUM] CWE-787 CVE-2020-3971: VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201907101-SG), Workstation (15.x
VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201907101-SG), Workstation (15.x before 15.0.2), and Fusion (11.x before 11.0.2) contain a heap overflow vulnerability in the vmxnet3 virtual network adapter. A malicious actor with local access to a virtual machine with a vmxnet3 network adapter present may be able to read privileged
nvd
CVE-2018-6982P4MEDIUMCVSS 6.5≥ 10.0.0, < 10.1.4v11.0.02018-12-04
CVE-2018-6982 [MEDIUM] CWE-908 CVE-2018-6982: VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contai
VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contain uninitialized stack memory usage in the vmxnet3 virtual network adapter which may lead to an information leak from host to guest.
nvd
CVE-2018-6977P4MEDIUMCVSS 6.5≥ 10.0.0, ≤ 10.1.5≥ 11.0.0, ≤ 11.0.2+1 more2018-10-09
CVE-2018-6977 [MEDIUM] CWE-835 CVE-2018-6977: VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial
VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a 3D-rendering shader. Successfully exploiting this issue may allow an attacker with normal user privileges in the guest to make the VM unresponsive, and in some cases, possibly result other VMs on th
nvd
CVE-2020-3999P4MEDIUMCVSS 6.5≥ 11.5.0, < 11.5.72020-12-21
CVE-2020-3999 [MEDIUM] CWE-20 CVE-2020-3999: VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior
VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12.x prior to 12.0 and 11.x prior to 11.5.7) and VMware Cloud Foundation contain a denial of service vulnerability due to improper input validation in GuestInfo. A malicious actor with normal user privilege access to a virtual
nvd
CVE-2024-22269P4MEDIUMCVSS 6.0≥ 13.0.0, < 13.5.22024-05-14
CVE-2024-22269 [MEDIUM] CWE-200 CVE-2024-22269: VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth devi
VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.
nvd
CVE-2023-34044P4MEDIUMCVSS 6.0≥ 13.0.0, < 13.5≥ 13.x, < 13.52023-10-20
CVE-2023-34044 [MEDIUM] CWE-125 CVE-2023-34044: VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds rea
VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds
read vulnerability that exists in the functionality for sharing host
Bluetooth devices with the virtual machine. A malicious actor with local administrative privileges on a virtual
machine may be able to read privileged information contained in
hypervisor
nvd
CVE-2017-4938P4MEDIUMCVSS 6.5v8.0.0v8.0.1+13 more2017-11-17
CVE-2017-4938 [MEDIUM] CWE-476 CVE-2017-4938: VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL point
VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL pointer dereference vulnerability. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.
nvd
CVE-2011-2145P4MEDIUMCVSS 6.3v3.1v3.1.1+1 more2011-06-06
CVE-2011-2145 [MEDIUM] CWE-264 CVE-2011-2145: mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, V
mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.1.x before 3.1.3, VMware ESXi 3.5 through 4.1, and VMware ESX 3.0.3 through 4.1, when a Solaris or FreeBSD guest OS is used, allows guest OS users to modify arbitrary guest OS files via unspecified vector
nvd
CVE-2015-2339P4MEDIUMCVSS 6.1v6.0v6.0.1+6 more2015-06-13
CVE-2015-2339 [MEDIUM] CVE-2015-2339: TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before
TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to cause a host OS denial of service via unspecified vectors, a different
nvd
CVE-2015-2338P4MEDIUMCVSS 6.1v6.0v6.0.1+6 more2015-06-13
CVE-2015-2338 [MEDIUM] CWE-399 CVE-2015-2338: TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before
TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to cause a host OS denial of service via unspecified vectors, a d
nvd
CVE-2010-1138P4MEDIUMCVSS 5.0v2.0v2.0.1+6 more2010-04-12
CVE-2010-1138 [MEDIUM] CWE-200 CVE-2010-1138: The virtual networking stack in VMware Workstation 7.0 before 7.0.1 build 227600, VMware Workstation
The virtual networking stack in VMware Workstation 7.0 before 7.0.1 build 227600, VMware Workstation 6.5.x before 6.5.4 build 246459 on Windows, VMware Player 3.0 before 3.0.1 build 227600, VMware Player 2.5.x before 2.5.4 build 246459 on Windows, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware Server 2.x, and VMwa
nvd
CVE-2010-4295P4MEDIUMCVSS 6.9v3.1v3.1.1+1 more2010-12-06
CVE-2010-4295 [MEDIUM] CWE-362 CVE-2010-4295: Race condition in the mounting process in vmware-mount in VMware Workstation 7.x before 7.1.2 build
Race condition in the mounting process in vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2 build 332101 allows host OS users to gain privileges via vectors involving temporary files.
nvd
CVE-2014-3793P4MEDIUMCVSS 5.8v6.0v6.0.1+1 more2014-05-31
CVE-2014-3793 [MEDIUM] CVE-2014-3793: VMware Tools in VMware Workstation 10.x before 10.0.2, VMware Player 6.x before 6.0.2, VMware Fusion
VMware Tools in VMware Workstation 10.x before 10.0.2, VMware Player 6.x before 6.0.2, VMware Fusion 6.x before 6.0.3, and VMware ESXi 5.0 through 5.5, when a Windows 8.1 guest OS is used, allows guest OS users to gain guest OS privileges or cause a denial of service (kernel NULL pointer dereference and guest OS crash) via unspecified vectors.
nvd