Vmware Workstation vulnerabilities

225 known vulnerabilities affecting vmware/workstation.

Total CVEs
225
CISA KEV
2
actively exploited
Public exploits
18
Exploited in wild
0
Severity breakdown
CRITICAL32HIGH90MEDIUM88LOW15

Vulnerabilities

Page 11 of 12
CVE-2007-4496MEDIUMCVSS 6.5≥ 5, ≤ 5.5.5≥ 6.0, ≤ 6.0.12007-09-21
CVE-2007-4496 [MEDIUM] CWE-399 CVE-2007-4496: Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Bu Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows authenticated users with administrative privileges on a guest o
nvd
CVE-2007-4591MEDIUMCVSS 6.9v6.02007-08-29
CVE-2007-4591 [MEDIUM] CVE-2007-4591: vstor-ws60.sys in VMWare Workstation 6.0 allows local users to cause a denial of service (host opera vstor-ws60.sys in VMWare Workstation 6.0 allows local users to cause a denial of service (host operating system crash) and possibly gain privileges by sending a small file buffer size value to the FsSetVolumeInformation IOCTL handler with an FsSetFileInformation subcode.
nvd
CVE-2007-4593MEDIUMCVSS 6.9v6.02007-08-29
CVE-2007-4593 [MEDIUM] CVE-2007-4593: Unspecified vulnerability in vstor2-ws60.sys in VMWare Workstation 6.0 allows local users to cause a Unspecified vulnerability in vstor2-ws60.sys in VMWare Workstation 6.0 allows local users to cause a denial of service (host operating system crash) via unspecified vectors, as demonstrated by the DC2 test suite, possibly a related issue to CVE-2007-4591. NOTE: the provenance of this information is unknown; the details are obtained solely from third party inf
nvd
CVE-2007-4059MEDIUMCVSS 5.8PoCv5.5.32007-07-30
CVE-2007-4059 [MEDIUM] CVE-2007-4059: Absolute path traversal vulnerability in a certain ActiveX control in IntraProcessLogging.dll 5.5.3. Absolute path traversal vulnerability in a certain ActiveX control in IntraProcessLogging.dll 5.5.3.42958 in EMC VMware allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SetLogFileName method.
nvd
CVE-2007-2491HIGHCVSS 7.2v5.5.3_build_346852007-05-04
CVE-2007-2491 [HIGH] CVE-2007-2491: The PIIX4 power management subsystem in EMC VMware Workstation 5.5.3.34685 and VMware Server 1.0.1.2 The PIIX4 power management subsystem in EMC VMware Workstation 5.5.3.34685 and VMware Server 1.0.1.29996 allows local users to write to arbitrary memory locations via a crafted poke to I/O port 0x1004, triggering a denial of service (virtual machine crash) or other unspecified impact, a related issue to CVE-2007-1337.
nvd
CVE-2007-1876HIGHCVSS 7.2≤ 5.5.32007-05-02
CVE-2007-1876 [HIGH] CVE-2007-1876: VMware Workstation before 5.5.4, when running a 64-bit Windows guest on a 64-bit host, allows local VMware Workstation before 5.5.4, when running a 64-bit Windows guest on a 64-bit host, allows local users to "corrupt the virtual machine's register context" by debugging a local program and stepping into a "syscall instruction."
nvd
CVE-2007-1337HIGHCVSS 7.8≤ 5.5.32007-05-02
CVE-2007-1337 [HIGH] CVE-2007-1337: The virtual machine process (VMX) in VMware Workstation before 5.5.4 does not properly read state in The virtual machine process (VMX) in VMware Workstation before 5.5.4 does not properly read state information when moving from the ACPI sleep state to the run state, which allows attackers to cause a denial of service (virtual machine reboot) via unknown vectors.
nvd
CVE-2007-1877HIGHCVSS 7.8≤ 5.5.32007-05-02
CVE-2007-1877 [HIGH] CVE-2007-1877: VMware Workstation before 5.5.4 allows attackers to cause a denial of service against the guest OS b VMware Workstation before 5.5.4 allows attackers to cause a denial of service against the guest OS by causing the virtual machine process (VMX) to store malformed configuration information.
nvd
CVE-2007-1069HIGHCVSS 7.8≤ 5.5.32007-05-02
CVE-2007-1069 [HIGH] CVE-2007-1069: The memory management in VMware Workstation before 5.5.4 allows attackers to cause a denial of servi The memory management in VMware Workstation before 5.5.4 allows attackers to cause a denial of service (Windows virtual machine crash) by triggering certain general protection faults (GPF).
nvd
CVE-2007-1744MEDIUMCVSS 6.3≤ 5.5.32007-05-02
CVE-2007-1744 [MEDIUM] CVE-2007-1744: Directory traversal vulnerability in the Shared Folders feature for VMware Workstation before 5.5.4, Directory traversal vulnerability in the Shared Folders feature for VMware Workstation before 5.5.4, when a folder is shared, allows users on the guest system to write to arbitrary files on the host system via the "Backdoor I/O Port" interface.
nvd
CVE-2007-1056HIGHCVSS 7.2v5.5.3_build_346852007-02-21
CVE-2007-1056 [HIGH] CWE-264 CVE-2007-1056: VMware Workstation 5.5.3 build 34685 does not provide per-user restrictions on certain privileged ac VMware Workstation 5.5.3 build 34685 does not provide per-user restrictions on certain privileged actions, which allows local users to perform restricted operations such as changing system time, accessing hardware components, and stopping the "VMware tools service" service. NOTE: exploitation is simplified via (1) weak file permissions (Users = Read & E
nvd
CVE-2007-0832LOWCVSS 1.2v5.5.3_build_346852007-02-07
CVE-2007-0832 [LOW] CVE-2007-0832: VMware Workstation 5.5.3 34685 does not immediately change the availability of a shared clipboard wh VMware Workstation 5.5.3 34685 does not immediately change the availability of a shared clipboard when the "Enable copy and paste to and from this virtual machine" checkbox is changed, which allows local users to obtain sensitive information or conduct certain attacks that are facilitated by weaker isolation between the host and guest operating systems.
nvd
CVE-2007-0833LOWCVSS 1.2v5.5.3_build_346852007-02-07
CVE-2007-0833 [LOW] CVE-2007-0833: VMware Workstation 5.5.3 34685, when the "Enable copy and paste to and from this virtual machine" op VMware Workstation 5.5.3 34685, when the "Enable copy and paste to and from this virtual machine" option is enabled, preserves clipboard data on the guest operating system after it was deleted on the host operating system, which might allow local users to read clipboard contents by moving the focus back to the host operating system.
nvd
CVE-2006-6410MEDIUMCVSS 4.6PoCv5.5.12006-12-10
CVE-2006-6410 [MEDIUM] CVE-2006-6410: Buffer overflow in an ActiveX control in VMWare 5.5.1 allows local users to execute arbitrary code v Buffer overflow in an ActiveX control in VMWare 5.5.1 allows local users to execute arbitrary code via a long VmdbDb parameter to the Initialize function.
nvd
CVE-2006-3589LOWCVSS 3.6v5.5.32006-07-21
CVE-2006-3589 [LOW] CVE-2006-3589: vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the SSL key.
nvd
CVE-2005-4459CRITICALCVSS 10.0v3.2.1v3.4+7 more2005-12-21
CVE-2005-4459 [CRITICAL] CWE-119 CVE-2005-4459: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Works Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT and (2) PORT FTP commands.
nvd
CVE-2005-2939HIGHCVSS 7.2v5.0.0_build_131242005-11-18
CVE-2005-2939 [HIGH] CVE-2005-2939: Unquoted Windows search path vulnerability in VMWare Workstation 5.0.0 build-13124 might allow local Unquoted Windows search path vulnerability in VMWare Workstation 5.0.0 build-13124 might allow local users to gain privileges via a malicious "program.exe" file in the C: folder.
nvd
CVE-2005-0444MEDIUMCVSS 4.6≤ 4.5.2_build_88482005-02-14
CVE-2005-0444 [MEDIUM] CVE-2005-0444: VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the rrdharan world-writable temporary directory, which allows local users to execute arbitrary code.
nvd
CVE-2004-2515HIGHCVSS 7.2v4.5.2_build_88482004-12-31
CVE-2004-2515 [HIGH] CVE-2004-2515: Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privile Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privileges, might allow local users to execute arbitrary code via format string specifiers in command line arguments. NOTE: it is not clear if there are any default or typical circumstances under which VMware would be running with privileges beyond those already availab
nvd
CVE-2003-0739MEDIUMCVSS 4.6≤ 4.0.1_build_52892003-10-20
CVE-2003-0739 [MEDIUM] CVE-2003-0739: VMware Workstation 4.0.1 for Linux, build 5289 and earlier, allows local users to delete arbitrary f VMware Workstation 4.0.1 for Linux, build 5289 and earlier, allows local users to delete arbitrary files via a symlink attack.
nvd