Vulnerabilities > Vmware

DATE CVE VULNERABILITY TITLE RISK
2022-11-23 CVE-2009-1143 Link Following vulnerability in VMWare Open-Vm-Tools 2009.03.18154848
An issue was discovered in open-vm-tools 2009.03.18-154848.
local
high complexity
vmware CWE-59
7.0
2022-11-12 CVE-2022-38650 Deserialization of Untrusted Data vulnerability in VMWare Hyperic Server 5.8.6
A remote unauthenticated insecure deserialization vulnerability exists in VMware Hyperic Server 5.8.6.
network
low complexity
vmware CWE-502
critical
10.0
2022-11-12 CVE-2022-38651 Unspecified vulnerability in VMWare Hyperic Server 5.8.6
A security filter misconfiguration exists in VMware Hyperic Server 5.8.6.
network
low complexity
vmware
critical
9.8
2022-11-12 CVE-2022-38652 Deserialization of Untrusted Data vulnerability in VMWare Hyperic Agent 5.8.6
A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6.
network
low complexity
vmware CWE-502
critical
9.9
2022-11-09 CVE-2022-31685 Unspecified vulnerability in VMWare Workspace ONE Assist
VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability.
network
low complexity
vmware
critical
9.8
2022-11-09 CVE-2022-31686 Unspecified vulnerability in VMWare Workspace ONE Assist
VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability.
network
low complexity
vmware
critical
9.8
2022-11-09 CVE-2022-31687 Unspecified vulnerability in VMWare Workspace ONE Assist
VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability.
network
low complexity
vmware
critical
9.8
2022-11-09 CVE-2022-31688 Cross-site Scripting vulnerability in VMWare Workspace ONE Assist
VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability.
network
low complexity
vmware CWE-79
6.1
2022-11-09 CVE-2022-31689 Session Fixation vulnerability in VMWare Workspace ONE Assist
VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability.
network
low complexity
vmware CWE-384
critical
9.8
2022-11-04 CVE-2022-31691 Unspecified vulnerability in VMWare products
Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39.0 and below all use Snakeyaml library for YAML editing support.
network
low complexity
vmware
critical
9.8