Vmware Server vulnerabilities
58 known vulnerabilities affecting vmware/server.
Total CVEs
58
CISA KEV
0
Public exploits
6
Exploited in wild
2
Severity breakdown
CRITICAL15HIGH17MEDIUM25LOW1
Vulnerabilities
Page 3 of 3
CVE-2008-1340P4HIGHCVSS 7.1v1.0.32008-03-20
CVE-2008-1340 [HIGH] CWE-399 CVE-2008-1340: Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.0.x before 6.0.3, VMware Play
Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.0.x before 6.0.3, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 allows attackers to cause a denial of service (host OS crash) via crafted VMCI calls that trigger "memory exhaustion and memory corruption."
nvd
CVE-2007-5619P4HIGHCVSS 7.2≤ 1.0.32007-10-21
CVE-2007-5619 [HIGH] CVE-2007-5619: Unspecified vulnerability in VMware Server before 1.0.4 causes user passwords to be recorded in clea
Unspecified vulnerability in VMware Server before 1.0.4 causes user passwords to be recorded in cleartext in server logs, which might allow local users to gain privileges.
nvd
CVE-2010-4295P4MEDIUMCVSS 6.9v2.0.22010-12-06
CVE-2010-4295 [MEDIUM] CWE-362 CVE-2010-4295: Race condition in the mounting process in vmware-mount in VMware Workstation 7.x before 7.1.2 build
Race condition in the mounting process in vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2 build 332101 allows host OS users to gain privileges via vectors involving temporary files.
nvd
CVE-2009-4811P4MEDIUMCVSS 5.0v2.0.0v2.0.1+1 more2010-04-27
CVE-2009-4811 [MEDIUM] CVE-2009-4811: VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware W
VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, and VMware Server 2.x al
nvd
CVE-2008-3697P4MEDIUMCVSS 5.0v1.0.1_build_29996v1.0.3+1 more2008-09-03
CVE-2008-3697 [MEDIUM] CWE-20 CVE-2008-3697: An unspecified ISAPI extension in VMware Server before 1.0.7 build 108231 allows remote attackers to
An unspecified ISAPI extension in VMware Server before 1.0.7 build 108231 allows remote attackers to cause a denial of service (IIS crash) via a malformed request.
nvd
CVE-2009-3731P4MEDIUMCVSS 4.3v2.0.22009-12-16
CVE-2009-3731 [MEDIUM] CWE-79 CVE-2009-3731: Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCent
Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware Stage Manager 1.x before 4.0.1; WebWorks Publisher 6.x through 8.x; WebWorks Publisher 2003; and
nvd
CVE-2008-4279P4MEDIUMCVSS 6.8≥ 1.0, < 1.0.82008-10-06
CVE-2008-4279 [MEDIUM] CWE-264 CVE-2008-4279: The CPU hardware emulation for 64-bit guest operating systems in VMware Workstation 6.0.x before 6.0
The CPU hardware emulation for 64-bit guest operating systems in VMware Workstation 6.0.x before 6.0.5 build 109488 and 5.x before 5.5.8 build 108000; Player 2.0.x before 2.0.5 build 109488 and 1.x before 1.0.8; Server 1.x before 1.0.7 build 108231; and ESX 2.5.4 through 3.5 allows authenticated guest OS users to gain additional guest OS privileges by
nvd
CVE-2007-5671P4MEDIUMCVSS 4.4v1.0.32008-06-05
CVE-2007-5671 [MEDIUM] CWE-20 CVE-2007-5671: HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Play
HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Player before 1.0.6 build 80404, VMware ACE before 1.0.5 build 79846, VMware Server before 1.0.5 build 80187, and VMware ESX 2.5.4 through 3.0.2 does not properly validate arguments in user-mode METHOD_NEITHER IOCTLs to the \\.\hgfs device, which allows gues
nvd
CVE-2010-1137P4MEDIUMCVSS 4.3v1.02010-04-01
CVE-2010-1137 [MEDIUM] CWE-79 CVE-2010-1137: Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMwa
Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5, and the Server Console in VMware Server 1.0, allows remote attackers to inject arbitrary web script or HTML via the name of a virtual machine.
nvd
CVE-2008-0967P4MEDIUMCVSS 6.9v1.0.32008-06-05
CVE-2008-0967 [MEDIUM] CVE-2008-0967: Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 917
Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware Player 1.x before 1.0.7 build 91707 and 2.x before 2.0.4 build 93057, and VMware Server before 1.0.6 build 91891 on Linux, and VMware ESXi 3.5 and VMware ESX 2.5.4 through 3.5, allows local users to gain privileges vi
nvd
CVE-2010-1193P4MEDIUMCVSS 4.3v2.0.02010-04-01
CVE-2010-1193 [MEDIUM] CWE-79 CVE-2010-1193: Cross-site scripting (XSS) vulnerability in WebAccess in VMware Server 2.0 allows remote attackers t
Cross-site scripting (XSS) vulnerability in WebAccess in VMware Server 2.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to JSON error messages.
nvd
CVE-2007-5023P4MEDIUMCVSS 6.9≥ 1.0, ≤ 1.0.42007-09-21
CVE-2007-5023 [MEDIUM] CWE-264 CVE-2007-5023: Unquoted Windows search path vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.
Unquoted Windows search path vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075, and Server before 1.0.4 Build 56528 allows local users to gain privileges via unspecified vectors, possibly involving a mali
nvd
CVE-2007-4497P4MEDIUMCVSS 5.5≥ 1.0, ≤ 1.0.42007-09-21
CVE-2007-4497 [MEDIUM] CWE-264 CVE-2007-4497: Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Bu
Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows users with login access to a guest operating system to cause a
nvd
CVE-2009-1072P4MEDIUMCVSS 4.9v2.0.02009-03-25
CVE-2009-1072 [MEDIUM] CWE-16 CVE-2009-1072: nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a us
nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.
nvd
CVE-2006-2662P4MEDIUMCVSS 4.6v1.0.1_build_299962006-06-02
CVE-2006-2662 [MEDIUM] CVE-2006-2662: VMware Server before RC1 does not clear user credentials from memory after a console connection is m
VMware Server before RC1 does not clear user credentials from memory after a console connection is made, which might allow local attackers to gain privileges.
nvd
CVE-2009-1146P4MEDIUMCVSS 4.9v1.0v1.0.1+8 more2009-04-06
CVE-2009-1146 [MEDIUM] CVE-2009-1146: Unspecified vulnerability in an ioctl in hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware P
Unspecified vulnerability in an ioctl in hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 1.0.x before 1.0.9 build 156507 and 2.0.x before 2.0.1 build 156745 allows local users to cause a denial of service via unknown vectors, a different vulnerability than CVE-2008-3761.
nvd
CVE-2009-1805P4MEDIUMCVSS 4.0≤ 1.0.8v1.0+10 more2009-06-01
CVE-2009-1805 [MEDIUM] CVE-2009-1805: Unspecified vulnerability in the VMware Descheduled Time Accounting driver in VMware Workstation 6.5
Unspecified vulnerability in the VMware Descheduled Time Accounting driver in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, VMware Server 1.x before 1.0.9 build 156507 and 2.x before 2.0.1 build 156745, VMware Fusion 2.x before 2.0.2 build 147997, VMware ESXi 3.5, and VMware ESX 3.0.2, 3.0.3, and 3.5, whe
nvd
CVE-2006-3589P4LOWCVSS 3.6v1.0.1_build_299962006-07-21
CVE-2006-3589 [LOW] CVE-2006-3589: vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return
vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the SSL key.
nvd
← Previous3 / 3