Vulnerabilities > Vmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-01-04 CVE-2017-5753 Information Exposure Through Discrepancy vulnerability in multiple products
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
5.6
2017-12-20 CVE-2017-4940 Cross-site Scripting vulnerability in VMWare Esxi 6.0/6.5
The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESXi550-201709102-SG) contains a vulnerability that may allow for stored cross-site scripting (XSS).
network
low complexity
vmware CWE-79
6.1
2017-12-13 CVE-2017-4942 Unspecified vulnerability in VMWare Airwatch Console
VMware AirWatch Console (AWC) contains a Broken Access Control vulnerability.
network
low complexity
vmware
4.9
2017-12-05 CVE-2017-4920 Resource Exhaustion vulnerability in VMWare Nsx-V Edge
The implementation of the OSPF protocol in VMware NSX-V Edge 6.2.x prior to 6.2.8 and NSX-V Edge 6.3.x prior to 6.3.3 doesn't correctly handle the link-state advertisement (LSA).
network
high complexity
vmware CWE-400
5.9
2017-11-27 CVE-2017-8044 Cross-site Scripting vulnerability in VMWare Single Sign-On for Pivotal Cloud Foundry
In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3), certain pages allow code to be injected into the DOM environment through query parameters, leading to XSS attacks.
network
low complexity
vmware CWE-79
6.1
2017-11-17 CVE-2017-4938 NULL Pointer Dereference vulnerability in VMWare Fusion and Workstation
VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL pointer dereference vulnerability.
local
low complexity
vmware CWE-476
6.5
2017-11-17 CVE-2017-4929 Cross-site Scripting vulnerability in VMWare NSX Edge
VMware NSX Edge (6.2.x before 6.2.9 and 6.3.x before 6.3.5) contains a moderate Cross-Site Scripting (XSS) issue which may lead to information disclosure.
network
low complexity
vmware CWE-79
6.1
2017-11-16 CVE-2017-4930 Cross-site Scripting vulnerability in VMWare Airwatch
VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add a malicious URL to an enrolled device's 'Links' page.
network
low complexity
vmware CWE-79
5.4
2017-09-15 CVE-2017-4926 Cross-site Scripting vulnerability in VMWare Vcenter Server 6.5
VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS).
network
low complexity
vmware CWE-79
5.4
2017-09-15 CVE-2017-4925 NULL Pointer Dereference vulnerability in VMWare products
VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Workstation (12.x before 12.5.3), Fusion (8.x before 8.5.4) contain a NULL pointer dereference vulnerability.
local
low complexity
vmware CWE-476
5.5