cbcvebase.

Vmware Fusion vulnerabilities

137 known vulnerabilities affecting vmware/fusion.

Total CVEs
137
CISA KEV
2
actively exploited
Public exploits
11
Exploited in wild
6
Severity breakdown
CRITICAL10HIGH64MEDIUM58LOW5

Vulnerabilities

Page 7 of 7
CVE-2023-20870P4MEDIUMCVSS 6.0≥ 13.0.0, < 13.0.22023-04-25
CVE-2023-20870 [MEDIUM] CWE-125 CVE-2023-20870: VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functio VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.
nvd
CVE-2017-4945P4MEDIUMCVSS 5.5v8.0v8.0.1+20 more2018-01-05
CVE-2017-4945 [MEDIUM] CVE-2017-4945: VMware Workstation (14.x and 12.x) and Fusion (10.x and 8.x) contain a guest access control vulnerab VMware Workstation (14.x and 12.x) and Fusion (10.x and 8.x) contain a guest access control vulnerability. This issue may allow program execution via Unity on locked Windows VMs. VMware Tools must be updated to 10.2.0 for each VM to resolve CVE-2017-4945. VMware Tools 10.2.0 is consumed by Workstation 14.1.0 and Fusion 10.1.0 by default.
nvd
CVE-2015-2340P4MEDIUMCVSS 6.1v6.0v6.0.1+6 more2015-06-13
CVE-2015-2340 [MEDIUM] CWE-399 CVE-2015-2340: TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to cause a host OS denial of service via unspecified vectors.
nvd
CVE-2020-3958P4MEDIUMCVSS 5.5≥ 11.0.0, < 11.5.22020-05-29
CVE-2020-3958 [MEDIUM] CWE-617 CVE-2020-3958: VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstatio VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.5.2) and VMware Fusion (11.x before 11.5.2) contain a denial-of-service vulnerability in the shader functionality. Successful exploitation of this issue may allow attackers with non-administrative access to a virtual machine to crash t
nvd
CVE-2016-5329P4MEDIUMCVSS 5.5v8.0.0v8.0.1+3 more2016-12-29
CVE-2016-5329 [MEDIUM] CWE-200 CVE-2016-5329: VMware Fusion 8.x before 8.5 on OS X, when System Integrity Protection (SIP) is enabled, allows loca VMware Fusion 8.x before 8.5 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and bypass the kASLR protection mechanism via unspecified vectors.
nvd
CVE-2025-41227P4MEDIUMCVSS 5.5≥ 13.x, < 13.6.32025-05-20
CVE-2025-41227 [MEDIUM] CWE-400 CVE-2025-41227: VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest options. A malicious actor with non-administrative privileges within a guest operating system may be able to exploit this issue by exhausting memory of the host process leading to a denial-of-service condition.
nvd
CVE-2017-4925P4MEDIUMCVSS 5.5≥ 8.0.0, < 8.5.4v8.x before 8.5.42017-09-15
CVE-2017-4925 [MEDIUM] CWE-476 CVE-2017-4925: VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESX VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Workstation (12.x before 12.5.3), Fusion (8.x before 8.5.4) contain a NULL pointer dereference vulnerability. This issue occurs when handling guest RPC requests. Successful exploitation of this issue may allow a
nvd
CVE-2020-3964P4MEDIUMCVSS 4.7≥ 11.0.0, < 11.5.2v11.x before 11.5.22020-06-25
CVE-2020-3964 [MEDIUM] CWE-908 CVE-2020-3964: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESX VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain an information leak in the EHCI USB controller. A malicious actor with local access to a virtual machine may be able to read privileged information contained i
nvd
CVE-2018-6963P4MEDIUMCVSS 5.5≥ 10.0, < 10.1.2v10.x before 10.1.22018-05-22
CVE-2018-6963 [MEDIUM] CWE-476 CVE-2018-6963: VMware Workstation (14.x before 14.1.2) and Fusion (10.x before 10.1.2) contain multiple denial-of-s VMware Workstation (14.x before 14.1.2) and Fusion (10.x before 10.1.2) contain multiple denial-of-service vulnerabilities that occur due to NULL pointer dereference issues in the RPC handler. Successful exploitation of these issues may allow an attacker with limited privileges on the guest machine trigger a denial-of-Service of their guest machine.
nvd
CVE-2019-5535P4MEDIUMCVSS 4.7≥ 11.0.0, < 11.5.02019-10-10
CVE-2019-5535 [MEDIUM] CVE-2019-5535: VMware Workstation and Fusion contain a network denial-of-service vulnerability due to improper hand VMware Workstation and Fusion contain a network denial-of-service vulnerability due to improper handling of certain IPv6 packets. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.7.
nvd
CVE-2024-22251P4MEDIUMCVSS 4.4≥ 13.0.0, < 13.5.12024-02-29
CVE-2024-22251 [MEDIUM] CWE-125 CVE-2024-22251: VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on a virtual machine may trigger an out-of-bounds read leading to information disclosure.
nvd
CVE-2020-3970P4LOWCVSS 3.8≥ 11.0.0, < 11.5.5v11.x before 11.5.52020-06-25
CVE-2020-3970 [LOW] CWE-125 CVE-2020-3970: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESX VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in the Shader functionality. A malicious actor with non-administrative local access to a virtual machine with 3D graphics enab
nvd
CVE-2015-1043P4LOWCVSS 3.3v6.0v6.0.1+4 more2015-01-29
CVE-2015-1043 [LOW] CWE-20 CVE-2015-1043: The Host Guest File System (HGFS) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before The Host Guest File System (HGFS) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, and VMware Fusion 6.x before 6.0.5 and 7.x before 7.0.1 allows guest OS users to cause a guest OS denial of service via unspecified vectors.
nvd
CVE-2009-1805P4MEDIUMCVSS 4.0≤ 2.0.1v2.02009-06-01
CVE-2009-1805 [MEDIUM] CVE-2009-1805: Unspecified vulnerability in the VMware Descheduled Time Accounting driver in VMware Workstation 6.5 Unspecified vulnerability in the VMware Descheduled Time Accounting driver in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, VMware Server 1.x before 1.0.9 build 156507 and 2.x before 2.0.1 build 156745, VMware Fusion 2.x before 2.0.2 build 147997, VMware ESXi 3.5, and VMware ESX 3.0.2, 3.0.3, and 3.5, whe
nvd
CVE-2014-1208P4LOWCVSS 3.3v5.02014-01-17
CVE-2014-1208 [LOW] CVE-2014-1208: VMware Workstation 9.x before 9.0.1, VMware Player 5.x before 5.0.1, VMware Fusion 5.x before 5.0.1, VMware Workstation 9.x before 9.0.1, VMware Player 5.x before 5.0.1, VMware Fusion 5.x before 5.0.1, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1 allow guest OS users to cause a denial of service (VMX process disruption) by using an invalid port.
nvd
CVE-2020-3959P4LOWCVSS 3.3≥ 11.0.0, < 11.1.02020-05-29
CVE-2020-3959 [LOW] CWE-401 CVE-2020-3959: VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstatio VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.1.0) and VMware Fusion (11.x before 11.1.0) contain a memory leak vulnerability in the VMCI module. A malicious actor with local non-administrative access to a virtual machine may be able to crash the virtual machine's vmx process leading
nvd
CVE-2011-2146P4LOWCVSS 2.1v3.1v3.1.1+1 more2011-06-06
CVE-2011-2146 [LOW] CWE-200 CVE-2011-2146: mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, V mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.1.x before 3.1.3, VMware ESXi 3.5 through 4.1, and VMware ESX 3.0.3 through 4.1 allows guest OS users to determine the existence of host OS files and directories via unspecified vectors.
nvd