Vulnerabilities > Vmware > High

DATE CVE VULNERABILITY TITLE RISK
2018-05-22 CVE-2018-6962 Unspecified vulnerability in VMWare Fusion
VMware Fusion (10.x before 10.1.2) contains a signature bypass vulnerability which may lead to a local privilege escalation.
local
low complexity
vmware
7.8
2018-05-11 CVE-2018-1258 Incorrect Authorization vulnerability in multiple products
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security.
8.8
2018-05-07 CVE-2018-1256 Unspecified vulnerability in VMWare Spring Cloud SSO Connector 2.1.2
Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers that are not bound to the SSO service.
network
high complexity
vmware
8.1
2018-05-02 CVE-2017-4952 Incorrect Permission Assignment for Critical Resource vulnerability in VMWare Xenon
VMware Xenon 1.x, prior to 1.5.4-CR7_1, 1.5.7_7, 1.5.4-CR6_2, 1.3.7-CR1_2, 1.1.0-CR0-3, 1.1.0-CR3_1,1.4.2-CR4_1, and 1.5.4_8, contains an authentication bypass vulnerability due to insufficient access controls for utility endpoints.
network
low complexity
vmware CWE-732
7.5
2018-04-20 CVE-2018-6960 Improper Authentication vulnerability in VMWare Horizon Daas 7.0.0
VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow an attacker to bypass two-factor authentication.
network
low complexity
vmware CWE-287
8.8
2018-04-13 CVE-2018-5511 Unsafe Reflection vulnerability in multiple products
On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.
network
low complexity
f5 vmware CWE-470
7.2
2018-04-06 CVE-2018-1272 Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests.
network
high complexity
vmware oracle
7.5
2018-01-29 CVE-2017-4951 Cross-Site Request Forgery (CSRF) vulnerability in VMWare Airwatch
VMware AirWatch Console (9.2.x before 9.2.2 and 9.1.x before 9.1.5) contains a Cross Site Request Forgery vulnerability when accessing the App Catalog.
network
low complexity
vmware CWE-352
8.8
2018-01-11 CVE-2017-4950 Integer Overflow or Wraparound vulnerability in VMWare Fusion and Workstation
VMware Workstation and Fusion contain an integer overflow vulnerability in VMware NAT service when IPv6 mode is enabled.
local
high complexity
vmware CWE-190
7.0
2018-01-11 CVE-2017-4949 Use After Free vulnerability in VMWare Fusion and Workstation
VMware Workstation and Fusion contain a use-after-free vulnerability in VMware NAT service when IPv6 mode is enabled.
local
high complexity
vmware CWE-416
7.0