Vulnerabilities > Vmware > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-05-25 | CVE-2014-0225 | XXE vulnerability in multiple products When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. | 8.8 |
2017-05-25 | CVE-2014-0097 | Improper Authentication vulnerability in VMWare Spring Security The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. | 7.3 |
2017-05-22 | CVE-2017-4915 | Incorrect Authorization vulnerability in VMWare Workstation Player and Workstation PRO VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. | 7.8 |
2017-05-10 | CVE-2017-4895 | Unspecified vulnerability in VMWare Airwatch Agent and Airwatch Inbox Airwatch Agent for Android contains a vulnerability that may allow a device to bypass root detection. | 8.8 |
2017-01-06 | CVE-2016-9879 | Channel and Path Errors vulnerability in multiple products An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. | 7.5 |
2016-12-29 | CVE-2016-9878 | Path Traversal vulnerability in multiple products An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. | 7.5 |
2016-12-29 | CVE-2016-7462 | Exposed Dangerous Method or Function vulnerability in VMWare Vrealize Operations The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files or rename files via a crafted DiskFileItem in a relay-request payload that is mishandled during deserialization. | 8.5 |
2016-12-29 | CVE-2016-7461 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in VMWare products The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion and Fusion Pro 8.x before 8.5.2 allows guest OS users to execute arbitrary code on the host OS or cause a denial of service (out-of-bounds memory access on the host OS) via unspecified vectors. | 8.8 |
2016-12-29 | CVE-2016-7459 | XXE vulnerability in VMWare Vcenter Server 5.0/5.5/6.0 VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distributed Switch setup, or (3) Content Library XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | 7.7 |
2016-12-29 | CVE-2016-7086 | Permissions, Privileges, and Access Controls vulnerability in VMWare Workstation Player and Workstation PRO The installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows allows local users to gain privileges via a Trojan horse setup64.exe file in the installation directory. | 7.8 |