Skip to main content

Vendor/product archive

vmware / esx CVEs

Beta · best-effort

84 CVEs tagged to vmware / esx11 Critical, 32 High, 36 Medium, 5 Low, 0 Unrated.

CVE-2014-1207

Published Jan 17, 2014

VMware ESXi 4.0 through 5.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (NULL pointer dereference) by intercepting and modifying Network File Copy (NFC…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5973

Published Dec 23, 2013

VMware ESXi 4.0 through 5.5 and ESX 4.0 and 4.1 allow local users to read or modify arbitrary files by leveraging the Virtual Machine Power User or Resource Pool Administrator rol…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5970

Published Oct 21, 2013

hostd-vmdb in VMware ESXi 4.0 through 5.0 and ESX 4.0 through 4.1 allows remote attackers to cause a denial of service (hostd-vmdb service outage) by modifying management traffic.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3658

Published Sep 10, 2013

Directory traversal vulnerability in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to delete arbitrary host OS files via unspecified vectors.

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-3657

Published Sep 10, 2013

Buffer overflow in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-1661

Published Sep 4, 2013

VMware ESXi 4.0 through 5.1, and ESX 4.0 and 4.1, does not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to cause a denial of s…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5703

Published Nov 20, 2012

The vSphere API in VMware ESXi 4.1 and ESX 4.1 allows remote attackers to cause a denial of service (host daemon crash) via an invalid value in a (1) RetrieveProp or (2) RetrieveP…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-2448

Published May 4, 2012

VMware ESXi 3.5 through 5.0 and ESX 3.5 through 4.1 allow remote attackers to execute arbitrary code or cause a denial of service (memory overwrite) via NFS traffic.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1517

Published May 4, 2012

The VMX process in VMware ESXi 4.1 and ESX 4.1 does not properly handle RPC commands, which allows guest OS users to cause a denial of service (memory overwrite and process crash)…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1516

Published May 4, 2012

The VMX process in VMware ESXi 3.5 through 4.1 and ESX 3.5 through 4.1 does not properly handle RPC commands, which allows guest OS users to cause a denial of service (memory over…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1515

Published Apr 2, 2012

VMware ESXi 3.5, 4.0, and 4.1 and ESX 3.5, 4.0, and 4.1 do not properly implement port-based I/O operations, which allows guest OS users to gain guest OS privileges by overwriting…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1510

Published Mar 16, 2012

Buffer overflow in the WDDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1508

Published Mar 16, 2012

The XPDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges or cause a denial…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 84 CVEsPage 1 of 4