Vmware Player vulnerabilities
87 known vulnerabilities affecting vmware/player.
Total CVEs
87
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL27HIGH22MEDIUM33LOW5
Vulnerabilities
Page 3 of 5
CVE-2012-5458P4HIGHCVSS 8.3v4.0v4.0.0.18997+4 more2012-11-14
CVE-2012-5458 [HIGH] CWE-264 CVE-2012-5458: VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows use weak permissio
VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows use weak permissions for unspecified process threads, which allows host OS users to gain host OS privileges via a crafted application.
nvd
CVE-2008-4917P4HIGHCVSS 7.2≥ 1.0.0, ≤ 1.0.8≥ 2.0, ≤ 2.0.52008-12-09
CVE-2008-4917 [HIGH] CWE-399 CVE-2008-4917: Unspecified vulnerability in VMware Workstation 5.5.8 and earlier, and 6.0.5 and earlier 6.x version
Unspecified vulnerability in VMware Workstation 5.5.8 and earlier, and 6.0.5 and earlier 6.x versions; VMware Player 1.0.8 and earlier, and 2.0.5 and earlier 2.x versions; VMware Server 1.0.9 and earlier; VMware ESXi 3.5; and VMware ESX 3.0.2 through 3.5 allows guest OS users to have an unknown impact by sending the virtual hardware a request that trigg
nvd
CVE-2007-5617P4CRITICALCVSS 10.0≥ 1.0.0, < 1.0.5≥ 2.0, < 2.0.12007-10-21
CVE-2007-5617 [CRITICAL] CVE-2007-5617: Unspecified vulnerability in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, and Workstation
Unspecified vulnerability in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1, prevents it from launching, which has unspecified impact, related to untrusted virtual machine images.
nvd
CVE-2013-3519P4HIGHCVSS 7.9v5.0v5.0.1+1 more2013-12-04
CVE-2013-3519 [HIGH] CWE-264 CVE-2013-3519: lgtosync.sys in VMware Workstation 9.x before 9.0.3, VMware Player 5.x before 5.0.3, VMware Fusion 5
lgtosync.sys in VMware Workstation 9.x before 9.0.3, VMware Player 5.x before 5.0.3, VMware Fusion 5.x before 5.0.4, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1, when a 32-bit Windows guest OS is used, allows guest OS users to gain guest OS privileges via an application that performs a crafted memory allocation.
nvd
CVE-2009-1244P4MEDIUMCVSS 6.8≤ 2.5.1v1.0.0+15 more2009-04-13
CVE-2009-1244 [MEDIUM] CVE-2009-1244: Unspecified vulnerability in the virtual machine display function in VMware Workstation 6.5.1 and ea
Unspecified vulnerability in the virtual machine display function in VMware Workstation 6.5.1 and earlier; VMware Player 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 1.x before 1.0.9 build 156507 and 2.x before 2.0.1 build 156745; VMware Fusion before 2.0.4 build 159196; VMware ESXi 3.5; and VMware ESX 3.0.2, 3.0.3, and 3.5 allows guest OS u
nvd
CVE-2012-5459P4HIGHCVSS 7.9v4.0v4.0.0.18997+4 more2012-11-14
CVE-2012-5459 [HIGH] CVE-2012-5459: Untrusted search path vulnerability in VMware Workstation 8.x before 8.0.5 and VMware Player 4.x bef
Untrusted search path vulnerability in VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows allows host OS users to gain host OS privileges via a Trojan horse DLL in a "system folder."
nvd
CVE-2015-3650P4HIGHCVSS 7.2v5.0v5.0.1+12 more2015-07-10
CVE-2015-3650 [HIGH] CWE-284 CVE-2015-3650: vmware-vmx.exe in VMware Workstation 7.x through 10.x before 10.0.7 and 11.x before 11.1.1, VMware P
vmware-vmx.exe in VMware Workstation 7.x through 10.x before 10.0.7 and 11.x before 11.1.1, VMware Player 5.x and 6.x before 6.0.7 and 7.x before 7.1.1, and VMware Horizon Client 5.x local-mode before 5.4.2 on Windows does not provide a valid DACL pointer during the setup of the vprintproxy.exe process, which allows host OS users to gain host OS privile
nvd
CVE-2015-2336P4MEDIUMCVSS 5.8v6.0v6.0.1+6 more2015-06-13
CVE-2015-2336 [MEDIUM] CVE-2015-2336: TPView.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before
TPView.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to execute arbitrary code on the host OS via unspecified vectors, a diffe
nvd
CVE-2015-2337P4MEDIUMCVSS 5.8v6.0v6.0.1+6 more2015-06-13
CVE-2015-2337 [MEDIUM] CWE-399 CVE-2015-2337: TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before
TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to execute arbitrary code on the host OS via unspecified vectors.
nvd
CVE-2013-5972P4HIGHCVSS 7.2v5.0v5.0.1+1 more2013-11-18
CVE-2013-5972 [HIGH] CWE-264 CVE-2013-5972: VMware Workstation 9.x before 9.0.3 and VMware Player 5.x before 5.0.3 on Linux do not properly hand
VMware Workstation 9.x before 9.0.3 and VMware Player 5.x before 5.0.3 on Linux do not properly handle shared libraries, which allows host OS users to gain host OS privileges via unspecified vectors.
nvd
CVE-2010-4296P4HIGHCVSS 7.2v3.1v3.1.1+1 more2010-12-06
CVE-2010-4296 [HIGH] CWE-863 CVE-2010-4296: vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x befor
vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2 build 332101 does not properly load libraries, which allows host OS users to gain privileges via vectors involving shared object files.
nvd
CVE-2010-1139P4HIGHCVSS 7.2v2.5v2.5.1+2 more2010-04-12
CVE-2010-1139 [HIGH] CWE-134 CVE-2010-1139: Format string vulnerability in vmrun in VMware VIX API 1.6.x, VMware Workstation 6.5.x before 6.5.4
Format string vulnerability in vmrun in VMware VIX API 1.6.x, VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Linux, and VMware Fusion 2.x before 2.0.7 build 246742, allows local users to gain privileges via format string specifiers in process metadata.
nvd
CVE-2008-1364P4HIGHCVSS 7.8v1.0.2v1.0.3+5 more2008-03-20
CVE-2008-1364 [HIGH] CWE-399 CVE-2008-1364: Unspecified vulnerability in the DHCP service in VMware Workstation 5.5.x before 5.5.6, VMware Playe
Unspecified vulnerability in the DHCP service in VMware Workstation 5.5.x before 5.5.6, VMware Player 1.0.x before 1.0.6, VMware ACE 1.0.x before 1.0.5, VMware Server 1.0.x before 1.0.5, and VMware Fusion 1.1.x before 1.1.1 allows attackers to cause a denial of service.
nvd
CVE-2008-3698P4HIGHCVSS 7.2≥ 1.0.0, < 1.0.8≥ 2.0, < 2.0.52008-09-03
CVE-2008-3698 [HIGH] CWE-264 CVE-2008-3698: Unspecified vulnerability in the OpenProcess function in VMware Workstation 5.5.x before 5.5.8 build
Unspecified vulnerability in the OpenProcess function in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server be
nvd
CVE-2007-4496P4MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.0.5≥ 2.0, ≤ 2.0.12007-09-21
CVE-2007-4496 [MEDIUM] CWE-399 CVE-2007-4496: Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Bu
Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows authenticated users with administrative privileges on a guest o
nvd
CVE-2011-1787P4MEDIUMCVSS 6.9v3.1v3.1.1+2 more2011-06-06
CVE-2011-1787 [MEDIUM] CWE-362 CVE-2011-1787: Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1
Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.1.x before 3.1.3, VMware ESXi 3.5 through 4.1, and VMware ESX 3.0.3 through 4.1 allows guest OS users to gain privileges on the guest OS by mounting a filesystem on top of an arbitrary d
nvd
CVE-2007-5618P4HIGHCVSS 7.2≥ 1.0.0, < 1.0.5≥ 2.0, < 2.0.12007-10-21
CVE-2007-5618 [HIGH] CVE-2007-5618: Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player
Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, VMware Server before 1.0.4, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1 might allow local users to gain privileges via malicious programs.
nvd
CVE-2008-1363P4HIGHCVSS 7.2≥ 1.0.0, < 1.0.6≥ 2.0, < 2.0.32008-03-20
CVE-2008-1363 [HIGH] CWE-264 CVE-2008-1363: VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1
VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges via an unspecified manipulation of a config.ini file located in an Application Data folder, which
nvd
CVE-2008-1362P4HIGHCVSS 7.2v1.0.2v1.0.3+5 more2008-03-20
CVE-2008-1362 [HIGH] CVE-2008-1362: VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1
VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges or cause a denial of service by impersonating the authd process through an unspecified use of an "insecur
nvd
CVE-2009-1147P4HIGHCVSS 7.2v1.0.0v1.0.1+15 more2009-04-06
CVE-2009-1147 [HIGH] CVE-2009-1147: Unspecified vulnerability in vmci.sys in the Virtual Machine Communication Interface (VMCI) in VMwar
Unspecified vulnerability in vmci.sys in the Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 2.0.x before 2.0.1 build 156745 allows local users to gain privileges via unknown vectors.
nvd