Vulnerabilities > CVE-2007-1270 - Numeric Errors vulnerability in VMWare ESX and ESX Server

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
vmware
CWE-189

Summary

Double free vulnerability in VMware ESX Server 3.0.0 and 3.0.1 allows attackers to cause a denial of service (crash), obtain sensitive information, or possibly execute arbitrary code via unspecified vectors.

Vulnerable Configurations

Part Description Count
Application
Vmware
1
OS
Vmware
2

Common Weakness Enumeration (CWE)

Oval

accepted2010-08-16T04:10:48.244-04:00
classvulnerability
contributors
  • nameYuzheng Zhou
    organizationHewlett-Packard
  • namePai Peng
    organizationHewlett-Packard
  • nameMichael Wood
    organizationHewlett-Packard
  • nameJonathan Baker
    organizationThe MITRE Corporation
definition_extensions
  • commentVMWare ESX Server 3.0.1 is installed
    ovaloval:org.mitre.oval:def:5367
  • commentVMWare ESX Server 3.0.0 is installed
    ovaloval:org.mitre.oval:def:5501
descriptionDouble free vulnerability in VMware ESX Server 3.0.0 and 3.0.1 allows attackers to cause a denial of service (crash), obtain sensitive information, or possibly execute arbitrary code via unspecified vectors.
familyunix
idoval:org.mitre.oval:def:5463
statusaccepted
submitted2008-04-10T15:10:44.000-05:00
titleVMware ESX server double free vulnerability may let remote users execute arbitrary code
version9