Vmware Workstation Pro vulnerabilities
27 known vulnerabilities affecting vmware/workstation_pro.
Total CVEs
27
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
HIGH15MEDIUM11LOW1
Vulnerabilities
Page 2 of 2
CVE-2020-3986P4MEDIUMCVSS 6.1≥ 15.0.0, < 16.0.02020-09-16
CVE-2020-3986 [MEDIUM] CWE-125 CVE-2020-3986: VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds
VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMF Parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to leak memory from TPView process running
nvd
CVE-2020-3987P4MEDIUMCVSS 6.1≥ 15.0.0, < 16.0.02020-09-16
CVE-2020-3987 [MEDIUM] CWE-125 CVE-2020-3987: VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds
VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMR STRETCHDIBITS parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to leak memory from TPView pr
nvd
CVE-2018-6957P4MEDIUMCVSS 5.3≥ 14.0, < 14.1.1v12.0+11 more2018-03-15
CVE-2018-6957 [MEDIUM] CWE-772 CVE-2018-6957: VMware Workstation (14.x before 14.1.1, 12.x) and Fusion (10.x before 10.1.1 and 8.x) contain a deni
VMware Workstation (14.x before 14.1.1, 12.x) and Fusion (10.x before 10.1.1 and 8.x) contain a denial-of-service vulnerability which can be triggered by opening a large number of VNC sessions. Note: In order for exploitation to be possible on Workstation and Fusion, VNC must be manually enabled.
nvd
CVE-2017-4925P4MEDIUMCVSS 5.5≥ 12.0.0, < 12.5.32017-09-15
CVE-2017-4925 [MEDIUM] CWE-476 CVE-2017-4925: VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESX
VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Workstation (12.x before 12.5.3), Fusion (8.x before 8.5.4) contain a NULL pointer dereference vulnerability. This issue occurs when handling guest RPC requests. Successful exploitation of this issue may allow a
nvd
CVE-2017-4900P4MEDIUMCVSS 5.5v12.0.0v12.0.1+4 more2017-06-07
CVE-2017-4900 [MEDIUM] CWE-476 CVE-2017-4900: VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability t
VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SVGA driver. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.
nvd
CVE-2017-4899P4MEDIUMCVSS 4.7v12.0.0v12.0.1+3 more2017-06-07
CVE-2017-4899 [MEDIUM] CWE-125 CVE-2017-4899: VMware Workstation Pro/Player 12.x before 12.5.3 contains a security vulnerability that exists in th
VMware Workstation Pro/Player 12.x before 12.5.3 contains a security vulnerability that exists in the SVGA driver. An attacker may exploit this issue to crash the VM or trigger an out-of-bound read. Note: This issue can be triggered only when the host has no graphics card or no graphics drivers are installed.
nvd
CVE-2020-3989P4LOWCVSS 3.3≥ 15.0.0, < 16.0.02020-09-16
CVE-2020-3989 [LOW] CWE-787 CVE-2020-3989: VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain a denial of serv
VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain a denial of service vulnerability due to an out-of-bounds write issue in Cortado ThinPrint component. A malicious actor with normal access to a virtual machine may be able to exploit this issue to create a partial denial-of-service condition on the system where Workstatio
nvd
← Previous2 / 2