Vmware Player vulnerabilities
87 known vulnerabilities affecting vmware/player.
Total CVEs
87
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL27HIGH22MEDIUM33LOW5
Vulnerabilities
Page 1 of 5
CVE-2009-2267P2MEDIUMCVSS 6.9ExploitedPoCv2.5v2.5.1+1 more2009-11-02
CVE-2009-2267 [MEDIUM] CVE-2009-2267: VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, V
VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138, VMware Fusion 2.x before 2.0.6 build 196839, VMware ESXi 3.5 and 4.0, and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0, when Virtual-8086 mode is
nvd
CVE-2010-1205P2CRITICALCVSS 9.8PoC≥ 2.5, < 2.5.5≥ 3.1, < 3.1.22010-06-30
CVE-2010-1205 [CRITICAL] CWE-120 CVE-2010-1205: Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.
nvd
CVE-2012-3569P2CRITICALCVSS 9.3PoCv4.0v4.0.0.18997+4 more2012-11-14
CVE-2012-3569 [CRITICAL] CWE-134 CVE-2012-3569: Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x bef
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.5, and other products, allows user-assisted remote attackers to execute arbitrary code via a crafted OVF file.
nvd
CVE-2009-3732P2CRITICALCVSS 10.0PoC≥ 2.5.0, < 2.5.4v3.02010-04-12
CVE-2009-3732 [CRITICAL] CWE-134 CVE-2009-3732: Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allo
Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2008-3892P3CRITICALCVSS 10.0PoC≥ 1.0.0, < 1.0.8≥ 2.0, < 2.0.52008-09-03
CVE-2008-3892 [CRITICAL] CVE-2008-3892: Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8
Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server
nvd
CVE-2007-0063P3CRITICALCVSS 10.0≥ 1.0, < 1.0.5≥ 2.0, < 2.0.12007-09-21
CVE-2007-0063 [CRITICAL] CWE-191 CVE-2007-0063: Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x befo
Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a m
nvd
CVE-2010-4297P3HIGHCVSS 7.2PoCv2.5v2.5.1+7 more2010-12-06
CVE-2010-4297 [HIGH] CWE-20 CVE-2010-4297: The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x
The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548; VMware Player 2.5.x before 2.5.5 build 328052 and 3.1.x before 3.1.2 build 301548; VMware Server 2.0.2; VMware Fusion 2.x before 2.0.8 build 328035 and 3.1.x before 3.1.2 build 332101; VMware ESXi 3.5, 4.0, and 4.1; and VMware ESX
nvd
CVE-2013-1662P4MEDIUMCVSS 6.9PoCv4.0v4.0.0.18997+9 more2013-08-24
CVE-2013-1662 [MEDIUM] CWE-264 CVE-2013-1662: vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on De
vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host OS privileges via a crafted lsb_release binary in a directory in the PATH, related to use of the popen library function.
nvd
CVE-2009-1565P3CRITICALCVSS 9.3v2.5v2.5.1+2 more2010-04-12
CVE-2009-1565 [CRITICAL] CWE-119 CVE-2009-1565: vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and t
vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute arbitrary code via an AVI file with crafted HexTile-encoded vid
nvd
CVE-2007-0061P3CRITICALCVSS 10.0≥ 1.0, < 1.0.5≥ 2.0, < 2.0.12007-09-21
CVE-2007-0061 [CRITICAL] CWE-119 CVE-2007-0061: The DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017,
The DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed packet that
nvd
CVE-2007-0062P3CRITICALCVSS 10.0v1.0.4v2.02007-09-21
CVE-2007-0062 [CRITICAL] CWE-119 CVE-2007-0062: Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in
Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 5652
nvd
CVE-2016-2077P3CRITICALCVSS 9.8v7.0v7.1+2 more2016-05-18
CVE-2016-2077 [CRITICAL] CWE-264 CVE-2016-2077: VMware Workstation 11.x before 11.1.3 and VMware Player 7.x before 7.1.3 on Windows incorrectly acce
VMware Workstation 11.x before 11.1.3 and VMware Player 7.x before 7.1.3 on Windows incorrectly access an executable file, which allows host OS users to gain host OS privileges via unspecified vectors.
nvd
CVE-2009-1564P3CRITICALCVSS 9.3v2.5v2.5.1+2 more2010-04-12
CVE-2009-1564 [CRITICAL] CWE-119 CVE-2009-1564: Heap-based buffer overflow in vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4
Heap-based buffer overflow in vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute arbitrary code via an AVI file wit
nvd
CVE-2011-3868P3CRITICALCVSS 9.3v3.0v3.0.1+5 more2011-10-07
CVE-2011-3868 [CRITICAL] CWE-119 CVE-2011-3868: Buffer overflow in VMware Workstation 7.x before 7.1.5, VMware Player 3.x before 3.1.5, VMware Fusio
Buffer overflow in VMware Workstation 7.x before 7.1.5, VMware Player 3.x before 3.1.5, VMware Fusion 3.1.x before 3.1.3, and VMware AMS allows remote attackers to execute arbitrary code via a crafted UDF filesystem in an ISO image.
nvd
CVE-2009-3707P4MEDIUMCVSS 5.0PoCv2.5v2.5.1+5 more2009-10-16
CVE-2009-3707 [MEDIUM] CWE-134 CVE-2009-3707: VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware W
VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, and VMware Serve
nvd
CVE-2005-4459P3CRITICALCVSS 10.0v1.0.02005-12-21
CVE-2005-4459 [CRITICAL] CWE-119 CVE-2005-4459: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Works
Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT and (2) PORT FTP commands.
nvd
CVE-2010-4294P3CRITICALCVSS 9.3v2.5v2.5.1+9 more2010-12-06
CVE-2010-4294 [CRITICAL] CWE-94 CVE-2010-4294: The frame decompression functionality in the VMnc media codec in VMware Movie Decoder before 6.5.5 b
The frame decompression functionality in the VMnc media codec in VMware Movie Decoder before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548, VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548 on Windows, VMware Player 2.5.x before 2.5.5 build 246459 and 3.x before 3.1.2 build 301548 on Windows, and VMware Serve
nvd
CVE-2009-2628P3CRITICALCVSS 9.3v2.5v2.5.1+1 more2009-09-08
CVE-2009-2628 [CRITICAL] CWE-94 CVE-2009-2628: The VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstati
The VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows does not properly handle certain small heights in video content, which might allow remote attackers to execute
nvd
CVE-2010-1141P3HIGHCVSS 8.5v2.5v2.5.1+2 more2010-04-12
CVE-2010-1141 [HIGH] CWE-264 CVE-2010-1141: VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4
VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 203138; VMware Fusion 2.x before 2.0.6 build 246742; VMware ESXi 3.5 and 4.0; and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0 does not properly access libraries, whi
nvd
CVE-2012-1666P4MEDIUMCVSS 6.9PoC≤ 4.0.3v4.0+3 more2012-09-08
CVE-2012-1666 [MEDIUM] CVE-2012-1666: Untrusted search path vulnerability in VMware Tools in VMware Workstation before 8.0.4, VMware Playe
Untrusted search path vulnerability in VMware Tools in VMware Workstation before 8.0.4, VMware Player before 4.0.4, VMware Fusion before 4.1.2, VMware View before 5.1, and VMware ESX 4.1 before U3 and 5.0 before P03 allows local users to gain privileges via a Trojan horse tpfc.dll file in the current working directory.
nvd
1 / 5Next →