Vmware Workstation Pro Player vulnerabilities
12 known vulnerabilities affecting vmware/workstation_pro_player.
Total CVEs
12
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH7MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2017-4950HIGHCVSS 7.0v14.x before 14.1.1v12.x before 12.5.92018-01-11
CVE-2017-4950 [HIGH] CWE-190 CVE-2017-4950: VMware Workstation and Fusion contain an integer overflow vulnerability in VMware NAT service when I
VMware Workstation and Fusion contain an integer overflow vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may lead to an out-of-bound read which can then be used to execute code on the host in conjunction with other issues. Note: IPv6 mode for VMNAT is not enabled by default.
cvelistv5nvd
CVE-2017-4949HIGHCVSS 7.0v14.x before 14.1.1v12.x before 12.5.92018-01-11
CVE-2017-4949 [HIGH] CWE-416 CVE-2017-4949: VMware Workstation and Fusion contain a use-after-free vulnerability in VMware NAT service when IPv6
VMware Workstation and Fusion contain a use-after-free vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may allow a guest to execute code on the host. Note: IPv6 mode for VMNAT is not enabled by default.
cvelistv5nvd
CVE-2017-4901CRITICALCVSS 9.9PoCv12.x prior to 12.5.42017-06-08
CVE-2017-4901 [CRITICAL] CWE-119 CVE-2017-4901: The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x bef
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.
cvelistv5nvd
CVE-2017-4902HIGHCVSS 8.8v12.x prior to 12.5.52017-06-07
CVE-2017-4902 [HIGH] CWE-119 CVE-2017-4902: VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550-201703401-SG; Works
VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have a Heap Buffer Overflow in SVGA. This issue may allow a guest to execute code on the host.
cvelistv5nvd
CVE-2017-4903HIGHCVSS 8.8v12.x prior to 12.5.52017-06-07
CVE-2017-4903 [HIGH] CWE-119 CVE-2017-4903: VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U
VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have an uninitialized stack memory usage
cvelistv5nvd
CVE-2017-4904HIGHCVSS 8.8v12.x prior to 12.5.52017-06-07
CVE-2017-4904 [HIGH] CWE-119 CVE-2017-4904: The XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi
The XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 has uninitialized
cvelistv5nvd
CVE-2017-4898HIGHCVSS 8.8v12.x prior to version 12.5.32017-06-07
CVE-2017-4898 [HIGH] CVE-2017-4898: VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs du
VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a path defined in the local environment-variable. Successful exploitation of this issue may allow normal users to escalate privileges to System in the host machine where VMware Workstation is installed.
cvelistv5nvd
CVE-2017-4905MEDIUMCVSS 5.5PoCv12.x prior to 12.5.52017-06-07
CVE-2017-4905 [MEDIUM] CWE-908 CVE-2017-4905: VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U
VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have uninitialized memory usage. This issu
cvelistv5nvd
CVE-2017-4899MEDIUMCVSS 4.7v12.x prior to version 12.5.32017-06-07
CVE-2017-4899 [MEDIUM] CWE-125 CVE-2017-4899: VMware Workstation Pro/Player 12.x before 12.5.3 contains a security vulnerability that exists in th
VMware Workstation Pro/Player 12.x before 12.5.3 contains a security vulnerability that exists in the SVGA driver. An attacker may exploit this issue to crash the VM or trigger an out-of-bound read. Note: This issue can be triggered only when the host has no graphics card or no graphics drivers are installed.
cvelistv5nvd
CVE-2017-4900MEDIUMCVSS 5.5v12.x prior to version 12.5.32017-06-07
CVE-2017-4900 [MEDIUM] CWE-476 CVE-2017-4900: VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability t
VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SVGA driver. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.
cvelistv5nvd
CVE-2017-4915HIGHCVSS 7.8PoCvAll 12.x versions prior to version 12.5.62017-05-22
CVE-2017-4915 [HIGH] CWE-863 CVE-2017-4915: VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driv
VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation of this issue may allow unprivileged host users to escalate their privileges to root in a Linux host machine.
cvelistv5nvd
CVE-2017-4916MEDIUMCVSS 6.5PoCvAll 12.x versions prior to version 12.5.62017-05-22
CVE-2017-4916 [MEDIUM] CWE-476 CVE-2017-4916: VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the v
VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Successful exploitation of this issue may allow host users with normal user privileges to trigger a denial-of-service in a Windows host machine.
cvelistv5nvd