cbcvebase.

Vmware Workstation vulnerabilities

225 known vulnerabilities affecting vmware/workstation.

Total CVEs
225
CISA KEV
2
actively exploited
Public exploits
18
Exploited in wild
7
Severity breakdown
CRITICAL32HIGH90MEDIUM88LOW15

Vulnerabilities

Page 5 of 12
CVE-2006-6410P4MEDIUMCVSS 4.6PoCv5.5.12006-12-10
CVE-2006-6410 [MEDIUM] CVE-2006-6410: Buffer overflow in an ActiveX control in VMWare 5.5.1 allows local users to execute arbitrary code v Buffer overflow in an ActiveX control in VMWare 5.5.1 allows local users to execute arbitrary code via a long VmdbDb parameter to the Initialize function.
nvd
CVE-2020-3962P3HIGHCVSS 8.2≥ 15.0.0, < 15.5.5v15.x before 15.5.52020-06-24
CVE-2020-3962 [HIGH] CWE-416 CVE-2020-3962: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESX VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain a use-after-free vulnerability in the SVGA device. A malicious actor with local access to a virtual machine with 3D graphics enabled may be able to exploit this
nvd
CVE-2020-3968P3HIGHCVSS 8.2≥ 15.0.0, < 15.5.5v15.x before 15.5.52020-06-25
CVE-2020-3968 [HIGH] CWE-787 CVE-2020-3968: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESX VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds write vulnerability in the USB 3.0 controller (xHCI). A malicious actor with local administrative privileges on a virtual machine may be able to
nvd
CVE-2020-4004P3HIGHCVSS 8.2≥ 15.0.0, < 15.5.72020-11-20
CVE-2020-4004 [HIGH] CWE-416 CVE-2020-4004: VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-2020 VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x before 15.5.7), Fusion (11.x before 11.5.7) contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code
nvd
CVE-2017-4935P3HIGHCVSS 7.8v12.0.0v12.0.1+11 more2017-11-17
CVE-2017-4935 [HIGH] CWE-787 CVE-2017-4935: VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) conta VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds write vulnerability in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may all
nvd
CVE-2017-4909P3HIGHCVSS 7.8v12.0v12.0.1+6 more2017-06-08
CVE-2017-4909 [HIGH] CWE-119 CVE-2017-4909: VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain a hea VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain a heap buffer-overflow vulnerability in TrueType Font (TTF) parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may
nvd
CVE-2017-4911P3HIGHCVSS 7.8v12.0v12.0.1+6 more2017-06-08
CVE-2017-4911 [HIGH] CWE-787 CVE-2017-4911: VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multi VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds write vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may all
nvd
CVE-2017-4908P3HIGHCVSS 7.8v12.0v12.0.1+6 more2017-06-08
CVE-2017-4908 [HIGH] CWE-119 CVE-2017-4908: VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multi VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple heap buffer-overflow vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may al
nvd
CVE-2019-5516P3MEDIUMCVSS 6.8≥ 14.0.0, < 14.1.6≥ 15.0.0, < 15.0.3+2 more2019-04-15
CVE-2019-5516 [MEDIUM] CWE-125 CVE-2019-5516: VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x be VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before 10.1.6) updates address an out-of-bounds vulnerability with the vertex shader functionality. Exploitation of this issue requires an attacker to have access to a virtual mach
nvd
CVE-2010-1142P3HIGHCVSS 8.5v6.5.0v6.5.1+2 more2010-04-12
CVE-2010-1142 [HIGH] CWE-264 CVE-2010-1142: VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 203138; VMware Fusion 2.x before 2.0.6 build 246742; VMware ESXi 3.5 and 4.0; and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0 does not properly load VMware programs,
nvd
CVE-2017-4939P3HIGHCVSS 7.8v12.0.0v12.0.1+10 more2017-11-17
CVE-2017-4939 [HIGH] CWE-426 CVE-2017-4939: VMware Workstation (12.x before 12.5.8) installer contains a DLL hijacking issue that exists due to VMware Workstation (12.x before 12.5.8) installer contains a DLL hijacking issue that exists due to some DLL files loaded by the application improperly. This issue may allow an attacker to load a DLL file of the attacker's choosing that could execute arbitrary code.
nvd
CVE-2019-5542P3HIGHCVSS 7.7≥ 15.0.0, < 15.5.12019-11-20
CVE-2019-5542 [HIGH] CVE-2019-5542: VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain a denial-of-service VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain a denial-of-service vulnerability in the RPC handler. Successful exploitation of this issue may allow attackers with normal user privileges to create a denial-of-service condition on their own VM.
nvd
CVE-2017-4936P3HIGHCVSS 7.8v12.0.0v12.0.1+11 more2017-11-17
CVE-2017-4936 [HIGH] CWE-125 CVE-2017-4936: VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) conta VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulnerability in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allo
nvd
CVE-2017-4937P3HIGHCVSS 7.8v12.0.0v12.0.1+11 more2017-11-17
CVE-2017-4937 [HIGH] CWE-125 CVE-2017-4937: VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) conta VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulnerability in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allo
nvd
CVE-2017-4913P3HIGHCVSS 7.8v12.0v12.0.1+6 more2017-06-08
CVE-2017-4913 [HIGH] CWE-190 CVE-2017-4913: VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain an in VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain an integer-overflow vulnerability in the True Type Font parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allo
nvd
CVE-2017-4910P3HIGHCVSS 7.8v12.0v12.0.1+6 more2017-06-08
CVE-2017-4910 [HIGH] CWE-125 CVE-2017-4910: VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multi VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allo
nvd
CVE-2017-4912P3HIGHCVSS 7.8v12.0v12.0.1+6 more2017-06-08
CVE-2017-4912 [HIGH] CWE-125 CVE-2017-4912: VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multi VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in TrueType Font (TTF) parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, th
nvd
CVE-2020-3967P3HIGHCVSS 7.5≥ 15.0.0, < 15.5.5v15.x before 15.5.52020-06-25
CVE-2020-3967 [HIGH] CWE-787 CVE-2020-3967: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESX VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain a heap-overflow vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local access to a virtual machine may be able to exploit this vulnerabilit
nvd
CVE-2020-3966P3HIGHCVSS 7.5≥ 15.0.0, < 15.5.2v15.x before 15.5.22020-06-25
CVE-2020-3966 [HIGH] CWE-362 CVE-2020-3966: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESX VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a heap-overflow due to a race condition issue in the USB 2.0 controller (EHCI). A malicious actor with local access to a virtual machine may be able to exploit t
nvd
CVE-2019-5539P3HIGHCVSS 7.8≥ 15.0.0, < 15.5.12019-12-23
CVE-2019-5539 [HIGH] CWE-427 CVE-2019-5539: VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x p VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to insecure loading of a DLL by Cortado Thinprint. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a Windows ma
nvd
Vmware Workstation vulnerabilities | cvebase