Vmware Workstation vulnerabilities

225 known vulnerabilities affecting vmware/workstation.

Total CVEs
225
CISA KEV
2
actively exploited
Public exploits
18
Exploited in wild
0
Severity breakdown
CRITICAL32HIGH90MEDIUM88LOW15

Vulnerabilities

Page 10 of 12
CVE-2008-3695CRITICALCVSS 10.0≥ 5.5, < 5.5.8≥ 6.0, < 6.0.52008-09-03
CVE-2008-3695 [CRITICAL] CVE-2008-3695: Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 buil Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server befor
nvd
CVE-2008-3698HIGHCVSS 7.2≥ 5.5, < 5.5.8≥ 6.0, < 6.0.52008-09-03
CVE-2008-3698 [HIGH] CWE-264 CVE-2008-3698: Unspecified vulnerability in the OpenProcess function in VMware Workstation 5.5.x before 5.5.8 build Unspecified vulnerability in the OpenProcess function in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server be
nvd
CVE-2008-2100HIGHCVSS 7.2≥ 5.5, ≤ 5.5.6≥ 6.0, ≤ 6.0.32008-06-05
CVE-2008-2100 [HIGH] CWE-119 CVE-2008-2100: Multiple buffer overflows in VIX API 1.1.x before 1.1.4 build 93057 on VMware Workstation 5.x and 6. Multiple buffer overflows in VIX API 1.1.x before 1.1.4 build 93057 on VMware Workstation 5.x and 6.x, VMware Player 1.x and 2.x, VMware ACE 2.x, VMware Server 1.x, VMware Fusion 1.x, VMware ESXi 3.5, and VMware ESX 3.0.1 through 3.5 allow guest OS users to execute arbitrary code on the host OS via unspecified vectors.
nvd
CVE-2008-0967MEDIUMCVSS 6.9v5.5.1v5.5.3+2 more2008-06-05
CVE-2008-0967 [MEDIUM] CVE-2008-0967: Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 917 Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware Player 1.x before 1.0.7 build 91707 and 2.x before 2.0.4 build 93057, and VMware Server before 1.0.6 build 91891 on Linux, and VMware ESXi 3.5 and VMware ESX 2.5.4 through 3.5, allows local users to gain privileges vi
nvd
CVE-2007-5671MEDIUMCVSS 4.4v5.5.1v5.5.3+1 more2008-06-05
CVE-2007-5671 [MEDIUM] CWE-20 CVE-2007-5671: HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Play HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Player before 1.0.6 build 80404, VMware ACE before 1.0.5 build 79846, VMware Server before 1.0.5 build 80187, and VMware ESX 2.5.4 through 3.0.2 does not properly validate arguments in user-mode METHOD_NEITHER IOCTLs to the \\.\hgfs device, which allows gues
nvd
CVE-2008-2098MEDIUMCVSS 6.9v6.02008-06-02
CVE-2008-2098 [MEDIUM] CWE-119 CVE-2008-2098: Heap-based buffer overflow in the VMware Host Guest File System (HGFS) in VMware Workstation 6 befor Heap-based buffer overflow in the VMware Host Guest File System (HGFS) in VMware Workstation 6 before 6.0.4 build 93057, VMware Player 2 before 2.0.4 build 93057, VMware ACE 2 before 2.0.2 build 93057, and VMware Fusion before 1.1.2 build 87978, when folder sharing is used, allows guest OS users to execute arbitrary code on the host OS via unspecified
nvd
CVE-2008-2099MEDIUMCVSS 6.9v6.02008-06-02
CVE-2008-2099 [MEDIUM] CWE-119 CVE-2008-2099: Unspecified vulnerability in VMCI in VMware Workstation 6 before 6.0.4 build 93057, VMware Player 2 Unspecified vulnerability in VMCI in VMware Workstation 6 before 6.0.4 build 93057, VMware Player 2 before 2.0.4 build 93057, and VMware ACE 2 before 2.0.2 build 93057 on Windows allows guest OS users to execute arbitrary code on the host OS via unspecified vectors.
nvd
CVE-2008-1362HIGHCVSS 7.2v5.5v5.5.3_build_34685+4 more2008-03-20
CVE-2008-1362 [HIGH] CVE-2008-1362: VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1 VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges or cause a denial of service by impersonating the authd process through an unspecified use of an "insecur
nvd
CVE-2008-1363HIGHCVSS 7.2≥ 5.5, < 5.5.6≥ 6.0, < 6.0.32008-03-20
CVE-2008-1363 [HIGH] CWE-264 CVE-2008-1363: VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1 VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges via an unspecified manipulation of a config.ini file located in an Application Data folder, which
nvd
CVE-2008-1364HIGHCVSS 7.8v5.5v5.5.3_build_34685+4 more2008-03-20
CVE-2008-1364 [HIGH] CWE-399 CVE-2008-1364: Unspecified vulnerability in the DHCP service in VMware Workstation 5.5.x before 5.5.6, VMware Playe Unspecified vulnerability in the DHCP service in VMware Workstation 5.5.x before 5.5.6, VMware Player 1.0.x before 1.0.6, VMware ACE 1.0.x before 1.0.5, VMware Server 1.0.x before 1.0.5, and VMware Fusion 1.1.x before 1.1.1 allows attackers to cause a denial of service.
nvd
CVE-2008-1340HIGHCVSS 7.1v5.5v5.5.3_build_34685+4 more2008-03-20
CVE-2008-1340 [HIGH] CWE-399 CVE-2008-1340: Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.0.x before 6.0.3, VMware Play Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.0.x before 6.0.3, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 allows attackers to cause a denial of service (host OS crash) via crafted VMCI calls that trigger "memory exhaustion and memory corruption."
nvd
CVE-2008-1361MEDIUMCVSS 6.8v5.5v5.5.3_build_34685+4 more2008-03-20
CVE-2008-1361 [MEDIUM] CWE-264 CVE-2008-1361: VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1 VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges via an unspecified manipulation that causes the authd process to connect to an arbitrary named
nvd
CVE-2008-0923MEDIUMCVSS 6.9v4.5.2v5.5.3_build_34685+2 more2008-02-26
CVE-2008-0923 [MEDIUM] CWE-22 CVE-2008-0923: Directory traversal vulnerability in the Shared Folders feature for VMWare ACE 1.0.2 and 2.0.2, Play Directory traversal vulnerability in the Shared Folders feature for VMWare ACE 1.0.2 and 2.0.2, Player 1.0.4 and 2.0.2, and Workstation 5.5.4 and 6.0.2 allows guest OS users to read and write arbitrary files on the host OS via a multibyte string that produces a wide character string containing .. (dot dot) sequences, which bypasses the protection mecha
nvd
CVE-2007-5617CRITICALCVSS 10.0≥ 5.5, < 5.5.5≥ 6.0, < 6.0.12007-10-21
CVE-2007-5617 [CRITICAL] CVE-2007-5617: Unspecified vulnerability in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, and Workstation Unspecified vulnerability in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1, prevents it from launching, which has unspecified impact, related to untrusted virtual machine images.
nvd
CVE-2007-5618HIGHCVSS 7.2≥ 5.5, < 5.5.5≥ 6.0, < 6.0.12007-10-21
CVE-2007-5618 [HIGH] CVE-2007-5618: Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, VMware Server before 1.0.4, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1 might allow local users to gain privileges via malicious programs.
nvd
CVE-2007-0063CRITICALCVSS 10.0≥ 5.5, < 5.5.5≥ 6.0, < 6.0.12007-09-21
CVE-2007-0063 [CRITICAL] CWE-191 CVE-2007-0063: Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x befo Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a m
nvd
CVE-2007-0061CRITICALCVSS 10.0≥ 5.5, < 5.5.5≥ 6.0, < 6.0.12007-09-21
CVE-2007-0061 [CRITICAL] CWE-119 CVE-2007-0061: The DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, The DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed packet that
nvd
CVE-2007-0062CRITICALCVSS 10.0v3.4v4.0+11 more2007-09-21
CVE-2007-0062 [CRITICAL] CWE-119 CVE-2007-0062: Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 5652
nvd
CVE-2007-4497MEDIUMCVSS 5.5≥ 5, ≤ 5.5.5≥ 6.0, ≤ 6.0.12007-09-21
CVE-2007-4497 [MEDIUM] CWE-264 CVE-2007-4497: Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Bu Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows users with login access to a guest operating system to cause a
nvd
CVE-2007-5023MEDIUMCVSS 6.9≥ 5, ≤ 5.5.5≥ 6.0, ≤ 6.0.12007-09-21
CVE-2007-5023 [MEDIUM] CWE-264 CVE-2007-5023: Unquoted Windows search path vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6. Unquoted Windows search path vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075, and Server before 1.0.4 Build 56528 allows local users to gain privileges via unspecified vectors, possibly involving a mali
nvd