cbcvebase.

Vmware Workstation vulnerabilities

225 known vulnerabilities affecting vmware/workstation.

Total CVEs
225
CISA KEV
2
actively exploited
Public exploits
18
Exploited in wild
7
Severity breakdown
CRITICAL32HIGH90MEDIUM88LOW15

Vulnerabilities

Page 11 of 12
CVE-2007-5023P4MEDIUMCVSS 6.9≥ 5, ≤ 5.5.5≥ 6.0, ≤ 6.0.12007-09-21
CVE-2007-5023 [MEDIUM] CWE-264 CVE-2007-5023: Unquoted Windows search path vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6. Unquoted Windows search path vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075, and Server before 1.0.4 Build 56528 allows local users to gain privileges via unspecified vectors, possibly involving a mali
nvd
CVE-2024-22251P4MEDIUMCVSS 4.4≥ 17.0, < 17.5.12024-02-29
CVE-2024-22251 [MEDIUM] CWE-125 CVE-2024-22251: VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on a virtual machine may trigger an out-of-bounds read leading to information disclosure.
nvd
CVE-2007-4497P4MEDIUMCVSS 5.5≥ 5, ≤ 5.5.5≥ 6.0, ≤ 6.0.12007-09-21
CVE-2007-4497 [MEDIUM] CWE-264 CVE-2007-4497: Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Bu Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows users with login access to a guest operating system to cause a
nvd
CVE-2009-1146P4MEDIUMCVSS 4.9≤ 6.5.1v1.0.1+31 more2009-04-06
CVE-2009-1146 [MEDIUM] CVE-2009-1146: Unspecified vulnerability in an ioctl in hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware P Unspecified vulnerability in an ioctl in hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 1.0.x before 1.0.9 build 156507 and 2.0.x before 2.0.1 build 156745 allows local users to cause a denial of service via unknown vectors, a different vulnerability than CVE-2008-3761.
nvd
CVE-2014-2384P4MEDIUMCVSS 4.9v10.0.1_build_13797762014-04-15
CVE-2014-2384 [MEDIUM] CWE-399 CVE-2014-2384: vmx86.sys in VMware Workstation 10.0.1 build 1379776 and VMware Player 6.0.1 build 1379776 on Window vmx86.sys in VMware Workstation 10.0.1 build 1379776 and VMware Player 6.0.1 build 1379776 on Windows might allow local users to cause a denial of service (read access violation and system crash) via a crafted buffer in an IOCTL call. NOTE: the researcher reports "Vendor rated issue as non-exploitable."
nvd
CVE-2005-0444P4MEDIUMCVSS 4.6≤ 4.5.2_build_88482005-02-14
CVE-2005-0444 [MEDIUM] CVE-2005-0444: VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the rrdharan world-writable temporary directory, which allows local users to execute arbitrary code.
nvd
CVE-2007-4593P4MEDIUMCVSS 6.9v6.02007-08-29
CVE-2007-4593 [MEDIUM] CVE-2007-4593: Unspecified vulnerability in vstor2-ws60.sys in VMWare Workstation 6.0 allows local users to cause a Unspecified vulnerability in vstor2-ws60.sys in VMWare Workstation 6.0 allows local users to cause a denial of service (host operating system crash) via unspecified vectors, as demonstrated by the DC2 test suite, possibly a related issue to CVE-2007-4591. NOTE: the provenance of this information is unknown; the details are obtained solely from third party inf
nvd
CVE-2020-3970P4LOWCVSS 3.8≥ 15.0.0, < 15.5.5v15.x before 15.5.52020-06-25
CVE-2020-3970 [LOW] CWE-125 CVE-2020-3970: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESX VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in the Shader functionality. A malicious actor with non-administrative local access to a virtual machine with 3D graphics enab
nvd
CVE-2020-3951P4LOWCVSS 3.8≥ 15.0.0, < 15.5.22020-03-17
CVE-2020-3951 [LOW] CWE-787 CVE-2020-3951: VMware Workstation (15.x before 15.5.2) and Horizon Client for Windows (5.x and prior before 5.4.0) VMware Workstation (15.x before 15.5.2) and Horizon Client for Windows (5.x and prior before 5.4.0) contain a denial-of-service vulnerability due to a heap-overflow issue in Cortado Thinprint. Attackers with non-administrative access to a guest VM with virtual printing enabled may exploit this issue to create a denial-of-service condition of the Thinprint
nvd
CVE-2015-1044P4LOWCVSS 3.3v10.0v10.0.1+3 more2015-01-29
CVE-2015-1044 [LOW] CVE-2015-1044: vmware-authd (aka the Authorization process) in VMware Workstation 10.x before 10.0.5, VMware Player vmware-authd (aka the Authorization process) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allows attackers to cause a host OS denial of service via unspecified vectors.
nvd
CVE-2014-4200P4MEDIUMCVSS 4.7≤ 10.0.3v10.0+2 more2014-08-28
CVE-2014-4200 [MEDIUM] CWE-264 CVE-2014-4200: vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other pro vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, uses 0644 permissions for the vm-support archive, which allows local users to obtain sensitive information by extracting files from this archive.
nvd
CVE-2003-0739P4MEDIUMCVSS 4.6≤ 4.0.1_build_52892003-10-20
CVE-2003-0739 [MEDIUM] CVE-2003-0739: VMware Workstation 4.0.1 for Linux, build 5289 and earlier, allows local users to delete arbitrary f VMware Workstation 4.0.1 for Linux, build 5289 and earlier, allows local users to delete arbitrary files via a symlink attack.
nvd
CVE-2003-0480P4LOWCVSS 3.7v4.02003-08-07
CVE-2003-0480 [LOW] CVE-2003-0480: VMware Workstation 4.0 for Linux allows local users to overwrite arbitrary files and gain privileges VMware Workstation 4.0 for Linux allows local users to overwrite arbitrary files and gain privileges via "symlink manipulation."
nvd
CVE-2015-1043P4LOWCVSS 3.3v10.0v10.0.1+3 more2015-01-29
CVE-2015-1043 [LOW] CWE-20 CVE-2015-1043: The Host Guest File System (HGFS) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before The Host Guest File System (HGFS) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, and VMware Fusion 6.x before 6.0.5 and 7.x before 7.0.1 allows guest OS users to cause a guest OS denial of service via unspecified vectors.
nvd
CVE-2009-1805P4MEDIUMCVSS 4.0≤ 6.5.1v1.0.1+43 more2009-06-01
CVE-2009-1805 [MEDIUM] CVE-2009-1805: Unspecified vulnerability in the VMware Descheduled Time Accounting driver in VMware Workstation 6.5 Unspecified vulnerability in the VMware Descheduled Time Accounting driver in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, VMware Server 1.x before 1.0.9 build 156507 and 2.x before 2.0.1 build 156745, VMware Fusion 2.x before 2.0.2 build 147997, VMware ESXi 3.5, and VMware ESX 3.0.2, 3.0.3, and 3.5, whe
nvd
CVE-2014-1208P4LOWCVSS 3.3v9.02014-01-17
CVE-2014-1208 [LOW] CVE-2014-1208: VMware Workstation 9.x before 9.0.1, VMware Player 5.x before 5.0.1, VMware Fusion 5.x before 5.0.1, VMware Workstation 9.x before 9.0.1, VMware Player 5.x before 5.0.1, VMware Fusion 5.x before 5.0.1, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1 allow guest OS users to cause a denial of service (VMX process disruption) by using an invalid port.
nvd
CVE-2026-22717P4LOWCVSS 2.7≥ 25H2, < 25H1U12026-02-27
CVE-2026-22717 [LOW] CWE-125 CVE-2026-22717: Out-of-bound read vulnerability in VMware Workstation 25H1 and below on any platform allows an actor Out-of-bound read vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to obtain limited information disclosure from the machine where VMware Workstation is installed.
nvd
CVE-2020-3959P4LOWCVSS 3.3≥ 15.0.0, < 15.1.02020-05-29
CVE-2020-3959 [LOW] CWE-401 CVE-2020-3959: VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstatio VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.1.0) and VMware Fusion (11.x before 11.1.0) contain a memory leak vulnerability in the VMCI module. A malicious actor with local non-administrative access to a virtual machine may be able to crash the virtual machine's vmx process leading
nvd
CVE-2011-2146P4LOWCVSS 2.1v7.1.1v7.1.2+1 more2011-06-06
CVE-2011-2146 [LOW] CWE-200 CVE-2011-2146: mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, V mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.1.x before 3.1.3, VMware ESXi 3.5 through 4.1, and VMware ESX 3.0.3 through 4.1 allows guest OS users to determine the existence of host OS files and directories via unspecified vectors.
nvd
CVE-2006-3589P4LOWCVSS 3.6v5.5.32006-07-21
CVE-2006-3589 [LOW] CVE-2006-3589: vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the SSL key.
nvd