Skip to main content

Vendor/product archive

vmware / vcenter_server_appliance CVEs

Beta · best-effort

12 CVEs tagged to vmware / vcenter_server_appliance3 Critical, 2 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2014-8371

Published Dec 8, 2014

VMware vCenter Server Appliance (vCSA) 5.5 before Update 2, 5.1 before Update 3, and 5.0 before Update 3c does not properly validate certificates when connecting to a CIM Server o…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-3797

Published Dec 8, 2014

Cross-site scripting (XSS) vulnerability in VMware vCenter Server Appliance (vCSA) 5.1 before Update 3 allows remote attackers to inject arbitrary web script or HTML via unspecifi…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-3790

Published Jun 1, 2014

Ruby vSphere Console (RVC) in VMware vCenter Server Appliance allows remote authenticated users to execute arbitrary commands as root by escaping from a chroot jail.

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-3107

Published May 1, 2013

VMware vCenter Server 5.1 before Update 1, when anonymous LDAP binding for Active Directory is enabled, allows remote attackers to bypass authentication by providing a valid usern…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3080

Published May 1, 2013

VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to create or overwrite arbitrary files, and consequently execute arbitrary code or cau…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-3079

Published May 1, 2013

VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to execute arbitrary programs with root privileges by leveraging Virtual Appliance Man…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6325

Published Dec 21, 2012

VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 does not properly parse XML documents, which allows remote authenticated users to read arbitrary files via unspecified v…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6324

Published Dec 21, 2012

Directory traversal vulnerability in VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 and 5.1 before Patch 1 allows remote authenticated users to read arbitrary files vi…

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1