cbcvebase.

Vmware Workstation vulnerabilities

225 known vulnerabilities affecting vmware/workstation.

Total CVEs
225
CISA KEV
2
actively exploited
Public exploits
18
Exploited in wild
7
Severity breakdown
CRITICAL32HIGH90MEDIUM88LOW15

Vulnerabilities

Page 3 of 12
CVE-2018-6981P3HIGHCVSS 8.8≥ 14.0.0, < 14.1.4v15.0.02018-12-04
CVE-2018-6981 [HIGH] CWE-908 CVE-2018-6981: VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMwar VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMware ESXi 6.0 without ESXi600-201811401-BG, VMware Workstation 15, VMware Workstation 14.1.3 or below, VMware Fusion 11, VMware Fusion 10.1.3 or below contain uninitialized stack memory usage in the vmxnet3 virtual network adapter which may allow a guest to
nvd
CVE-2012-1666P4MEDIUMCVSS 6.9PoC≤ 8.0.3v8.0+4 more2012-09-08
CVE-2012-1666 [MEDIUM] CVE-2012-1666: Untrusted search path vulnerability in VMware Tools in VMware Workstation before 8.0.4, VMware Playe Untrusted search path vulnerability in VMware Tools in VMware Workstation before 8.0.4, VMware Player before 4.0.4, VMware Fusion before 4.1.2, VMware View before 5.1, and VMware ESX 4.1 before U3 and 5.0 before P03 allows local users to gain privileges via a Trojan horse tpfc.dll file in the current working directory.
nvd
CVE-2017-4924P3HIGHCVSS 8.8v12.x before 12.5.72017-09-15
CVE-2017-4924 [HIGH] CWE-787 CVE-2017-4924: VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusi VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusion (8.x before 8.5.8) contain an out-of-bounds write vulnerability in SVGA device. This issue may allow a guest to execute code on the host.
nvd
CVE-2023-20869P3HIGHCVSS 8.2≥ 17.0.0, < 17.0.22023-04-25
CVE-2023-20869 [HIGH] CWE-787 CVE-2023-20869: VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerabili VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.
nvd
CVE-2018-6983P3HIGHCVSS 8.8≥ 14.0.0, < 14.1.5≥ 15.0.0, < 15.0.22018-11-27
CVE-2018-6983 [HIGH] CWE-190 CVE-2018-6983: VMware Workstation (15.x before 15.0.2 and 14.x before 14.1.5) and Fusion (11.x before 11.0.2 and 10 VMware Workstation (15.x before 15.0.2 and 14.x before 14.1.5) and Fusion (11.x before 11.0.2 and 10.x before 10.1.5) contain an integer overflow vulnerability in the virtual network devices. This issue may allow a guest to execute code on the host.
nvd
CVE-2009-0909P3CRITICALCVSS 9.3v6.5.12009-04-06
CVE-2009-0909 [CRITICAL] CWE-119 CVE-2009-0909: Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware Server 2.0.x before 2.0.1 build 156745 allows remote attackers to execute arbitrary code via a crafted web page or video file, aka ZDI-CAN-435.
nvd
CVE-2019-5541P3CRITICALCVSS 9.1≥ 15.0.0, < 15.5.12019-11-20
CVE-2019-5541 [CRITICAL] CWE-787 CVE-2019-5541: VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds wri VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in the e1000e virtual network adapter. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to create a denial-of-service condition on their own VM.
nvd
CVE-2018-6965P3HIGHCVSS 8.1≥ 14.0, < 14.1.22018-07-09
CVE-2018-6965 [HIGH] CWE-125 CVE-2018-6965: VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x be VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash their VMs, a different vulnerability th
nvd
CVE-2009-0199P3CRITICALCVSS 9.3v6.5v6.5.0+2 more2009-09-08
CVE-2009-0199 [CRITICAL] CWE-119 CVE-2009-0199: Heap-based buffer overflow in the VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 Heap-based buffer overflow in the VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows might allow remote attackers to execute arbitrary code via a video file with craf
nvd
CVE-2012-3288P3CRITICALCVSS 9.3v7.0v7.0.1+11 more2012-06-14
CVE-2012-3288 [CRITICAL] CWE-20 CVE-2012-3288: VMware Workstation 7.x before 7.1.6 and 8.x before 8.0.4, VMware Player 3.x before 3.1.6 and 4.x bef VMware Workstation 7.x before 7.1.6 and 8.x before 8.0.4, VMware Player 3.x before 3.1.6 and 4.x before 4.0.4, VMware Fusion 4.x before 4.1.3, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 allow user-assisted remote attackers to execute arbitrary code on the host OS or cause a denial of service (memory corruption) on the host OS via a c
nvd
CVE-2019-5098P3HIGHCVSS 8.6v15.0.02019-12-05
CVE-2019-5098 [HIGH] CWE-125 CVE-2019-5098: An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.130 An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.29010. A specially crafted pixel shader can cause out-of-bounds memory read. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.
nvd
CVE-2020-3947P3HIGHCVSS 8.8≥ 15.0.0, < 15.5.2v15.x before 15.5.22020-03-16
CVE-2020-3947 [HIGH] CWE-416 CVE-2020-3947: VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerab VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerability in vmnetdhcp. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to create a denial-of-service condition of the vmnetdhcp service running on the host machine.
nvd
CVE-2018-6967P3HIGHCVSS 8.1≥ 14.0, < 14.1.22018-07-09
CVE-2018-6967 [HIGH] CVE-2018-6967: VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x be VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash their VMs, a different vulnerability than CVE-2
nvd
CVE-2018-6966P3HIGHCVSS 8.1≥ 14.0, < 14.1.22018-07-09
CVE-2018-6966 [HIGH] CVE-2018-6966: VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x be VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash their VMs, a different vulnerability than CVE-2
nvd
CVE-2018-6973P3HIGHCVSS 8.8≥ 14.0.0, < 14.1.3v14.x before 14.1.32018-08-15
CVE-2018-6973 [HIGH] CWE-787 CVE-2018-6973: VMware Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds wri VMware Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds write vulnerability in the e1000 device. This issue may allow a guest to execute code on the host.
nvd
CVE-2018-6974P3HIGHCVSS 8.8≥ 14.0, < 14.1.3v14.x before 14.1.32018-10-16
CVE-2018-6974 [HIGH] CWE-125 CVE-2018-6974: VMware ESXi (6.7 before ESXi670-201810101-SG, 6.5 before ESXi650-201808401-BG, and 6.0 before ESXi60 VMware ESXi (6.7 before ESXi670-201810101-SG, 6.5 before ESXi650-201808401-BG, and 6.0 before ESXi600-201808401-BG), Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds read vulnerability in SVGA device. This issue may allow a guest to execute code on the host.
nvd
CVE-2012-2449P3CRITICALCVSS 9.0v8.0v8.0.1+1 more2012-05-04
CVE-2012-2449 [CRITICAL] CWE-119 CVE-2012-2449: VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x through 4.1.2 VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x through 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 do not properly configure the virtual floppy device, which allows guest OS users to cause a denial of service (out-of-bounds write operation and VMX process crash) or possibly execute arbit
nvd
CVE-2012-2450P3CRITICALCVSS 9.0v8.0v8.0.1+1 more2012-05-04
CVE-2012-2450 [CRITICAL] CVE-2012-2450: VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x before 4.1.2, VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 do not properly register SCSI devices, which allows guest OS users to cause a denial of service (invalid write operation and VMX process crash) or possibly execute arbitrary code on the host OS by l
nvd
CVE-2023-20872P3HIGHCVSS 8.8v17.0.02023-04-25
CVE-2023-20872 [HIGH] CWE-787 CVE-2023-20872: VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD devic VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation.
nvd
CVE-2019-5525P3HIGHCVSS 8.8≥ 15.0.0, < 15.1.02019-06-06
CVE-2019-5525 [HIGH] CWE-416 CVE-2019-5525: VMware Workstation (15.x before 15.1.0) contains a use-after-free vulnerability in the Advanced Linu VMware Workstation (15.x before 15.1.0) contains a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) backend. A malicious user with normal user privileges on the guest machine may exploit this issue in conjunction with other issues to execute code on the Linux host where Workstation is installed.
nvd
Vmware Workstation vulnerabilities | cvebase