Skip to main content

Vendor/product archive

vmware / esxi CVEs

Beta · best-effort

136 CVEs tagged to vmware / esxi19 Critical, 57 High, 54 Medium, 6 Low, 0 Unrated.

CVE-2024-37086

Published Jun 25, 2024

VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an ou…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37085

Published Jun 25, 2024

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was prev…

CVSS 6.8 · Medium
evidence mentions
17
Buzz score
69.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2024-22254

Published Mar 5, 2024

VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the…

CVSS 7.9 · High
evidence mentions
4
Buzz score
24.1
Vendor/product tagsBeta · best-effort

CVE-2022-31699

Published Dec 13, 2022

VMware ESXi contains a heap-overflow vulnerability. A malicious local actor with restricted privileges within a sandbox process may exploit this issue to achieve a partial informa…

CVSS 3.3 · Low
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2022-31696

Published Dec 13, 2022

VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to co…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-31681

Published Oct 7, 2022

VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process only, may create a denial of service condition on the host.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-22050

Published Feb 16, 2022

ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to create a denial-of-service co…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22043

Published Feb 16, 2022

VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled. A malicious actor with access to settingsd, may exploit…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-22042

Published Feb 16, 2022

VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privileges within the VMX process onl…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-21995

Published Jul 13, 2021

OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-bounds read issue. A malicious actor with network access to port 427 on ESXi may be able to trigger…

CVSS 7.5 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort
Showing 1-25 of 136 CVEsPage 1 of 6