Vmware Vcenter Server vulnerabilities
81 known vulnerabilities affecting vmware/vcenter_server.
Total CVEs
81
CISA KEV
11
actively exploited
Public exploits
10
Exploited in wild
11
Severity breakdown
CRITICAL20HIGH29MEDIUM31LOW1
Vulnerabilities
Page 4 of 5
CVE-2017-4923CRITICALCVSS 9.8v6.52017-08-01
CVE-2017-4923 [CRITICAL] CWE-200 CVE-2017-4923: VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This i
VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtained when using the vCenter Server Appliance file-based backup feature.
nvd
CVE-2017-4921HIGHCVSS 8.8v6.52017-08-01
CVE-2017-4921 [HIGH] CVE-2017-4921: VMware vCenter Server (6.5 prior to 6.5 U1) contains an insecure library loading issue that occurs d
VMware vCenter Server (6.5 prior to 6.5 U1) contains an insecure library loading issue that occurs due to the use of LD_LIBRARY_PATH variable in an unsafe manner. Successful exploitation of this issue may allow unprivileged host users to load a shared library that may lead to privilege escalation.
nvd
CVE-2017-4922MEDIUMCVSS 6.5v6.52017-08-01
CVE-2017-4922 [MEDIUM] CWE-200 CVE-2017-4922: VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the serv
VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script using world writable directories as temporary storage for critical information. Successful exploitation of this issue may allow unprivileged host users to access certain critical information when the service gets restarted.
nvd
CVE-2017-4919CRITICALCVSS 9.0v5.5v6.0+1 more2017-07-28
CVE-2017-4919 [CRITICAL] CWE-306 CVE-2017-4919: VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to
VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating Systems without the need to authenticate.
nvd
CVE-2016-7459HIGHCVSS 7.7v5.0v5.5+1 more2016-12-29
CVE-2016-7459 [HIGH] CWE-611 CVE-2016-7459: VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read ar
VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distributed Switch setup, or (3) Content Library XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2016-5331MEDIUMCVSS 6.1≤ 6.02016-08-08
CVE-2016-5331 [MEDIUM] CWE-93 CVE-2016-5331: CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attac
CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
nvd
CVE-2015-6931MEDIUMCVSS 6.1v5.0v5.1+1 more2016-07-03
CVE-2015-6931 [MEDIUM] CWE-79 CVE-2015-6931: Cross-site scripting (XSS) vulnerability in the vSphere Web Client in VMware vCenter Server 5.0 befo
Cross-site scripting (XSS) vulnerability in the vSphere Web Client in VMware vCenter Server 5.0 before U3g, 5.1 before U3d, and 5.5 before U2d allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2016-2078MEDIUMCVSS 6.1v5.1v5.5+2 more2016-06-08
CVE-2016-2078 [MEDIUM] CWE-79 CVE-2016-2078: Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5.1 before updat
Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5.1 before update 3d, 5.5 before update 3d, and 6.0 before update 2 on Windows allows remote attackers to inject arbitrary web script or HTML via the flashvars parameter.
nvd
CVE-2016-2076HIGHCVSS 7.6≤ 6.0v5.52016-04-15
CVE-2016-2076 [HIGH] CWE-287 CVE-2016-2076: Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vC
Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which allows remote attackers to hijack sessions via a crafted web site.
nvd
CVE-2015-2342CRITICALCVSS 10.0PoCv5.0v5.1+2 more2015-10-12
CVE-2015-2342 [CRITICAL] CVE-2015-2342: The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0
The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol.
nvd
CVE-2015-1047MEDIUMCVSS 5.0v5.0v5.1+1 more2015-10-12
CVE-2015-1047 [MEDIUM] CWE-20 CVE-2015-1047: vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attacke
vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartbeat message.
nvd
CVE-2015-6932MEDIUMCVSS 5.8v5.5v6.02015-09-18
CVE-2015-6932 [MEDIUM] CWE-310 CVE-2015-6932: VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LD
VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
nvd
CVE-2014-4241MEDIUMCVSS 4.3v5.0v5.1+1 more2014-07-17
CVE-2014-4241 [MEDIUM] CVE-2014-4241: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect integrity via vectors related to WLS - Web Services.
nvd
CVE-2013-5971MEDIUMCVSS 6.8≤ 5.0v4.0.0.10021+6 more2013-10-21
CVE-2013-5971 [MEDIUM] CWE-264 CVE-2013-5971: Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before
Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web sessions and gain privileges via unspecified vectors.
nvd
CVE-2013-1659HIGHCVSS 7.6v4.0v5.02013-02-22
CVE-2013-1659 [HIGH] CVE-2013-1659: VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi
VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 do not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption) by modifying the client-server data
nvd
CVE-2012-6326HIGHCVSS 7.8v4.1v5.02013-02-22
CVE-2012-6326 [HIGH] CWE-119 CVE-2012-6326: VMware vCenter Server 4.1 before Update 3 and 5.0 before Update 2, and vCSA 5.0 before Update 2, all
VMware vCenter Server 4.1 before Update 3 and 5.0 before Update 2, and vCSA 5.0 before Update 2, allows remote attackers to cause a denial of service (disk consumption) via vectors that trigger large log entries.
nvd
CVE-2013-1405CRITICALCVSS 10.0v4.0v4.12013-02-15
CVE-2013-1405 [CRITICAL] CWE-287 CVE-2013-1405: VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMwar
VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update 3a, VMware VI-Client 2.5, VMware ESXi 3.5 through 4.1, and VMware ESX 3.5 through 4.1 do not properly implement the management authentication protocol, which allow remote servers to execute a
nvd
CVE-2010-2928LOWCVSS 2.1v4.12011-02-16
CVE-2010-2928 [LOW] CWE-255 CVE-2010-2928: The vCenter Tomcat Management Application in VMware vCenter Server 4.1 before Update 1 stores log-on
The vCenter Tomcat Management Application in VMware vCenter Server 4.1 before Update 1 stores log-on credentials in a configuration file, which allows local users to gain privileges by reading this file.
nvd
CVE-2009-2698HIGHCVSS 7.8PoCv4.02009-08-27
CVE-2009-2698 [HIGH] CWE-476 CVE-2009-2698: The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in t
The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving the MSG_MORE flag and a UDP socket.
nvd
CVE-2009-2416MEDIUMCVSS 6.5v4.02009-08-11
CVE-2009-2416 [MEDIUM] CWE-416 CVE-2009-2416: Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and l
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
nvd