Vulnerabilities > Vmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2014-07-17 CVE-2014-4241 Remote Security vulnerability in Oracle WebLogic Server
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect integrity via vectors related to WLS - Web Services.
network
vmware oracle
4.3
2014-05-31 CVE-2014-3793 Local Privilege Escalation vulnerability in Multiple VMware Products
VMware Tools in VMware Workstation 10.x before 10.0.2, VMware Player 6.x before 6.0.2, VMware Fusion 6.x before 6.0.3, and VMware ESXi 5.0 through 5.5, when a Windows 8.1 guest OS is used, allows guest OS users to gain guest OS privileges or cause a denial of service (kernel NULL pointer dereference and guest OS crash) via unspecified vectors.
low complexity
vmware
5.8
2014-04-17 CVE-2014-0054 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue.
6.8
2014-04-15 CVE-2014-2384 Resource Management Errors vulnerability in VMWare Player and Workstation
vmx86.sys in VMware Workstation 10.0.1 build 1379776 and VMware Player 6.0.1 build 1379776 on Windows might allow local users to cause a denial of service (read access violation and system crash) via a crafted buffer in an IOCTL call.
local
low complexity
vmware CWE-399
4.9
2014-04-11 CVE-2014-1210 Cryptographic Issues vulnerability in VMWare Vsphere Client 5.0/5.1
VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
network
vmware CWE-310
5.8
2014-01-26 CVE-2013-6429 XXE vulnerability in multiple products
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.
6.8
2014-01-23 CVE-2013-7315 Permissions, Privileges, and Access Controls vulnerability in multiple products
The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152.
6.8
2014-01-23 CVE-2013-4152 Permissions, Privileges, and Access Controls vulnerability in multiple products
The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue.
6.8
2014-01-17 CVE-2014-1211 Cross-Site Request Forgery (CSRF) vulnerability in VMWare Vcloud Director 5.1.0/5.1.1/5.1.2
Cross-site request forgery (CSRF) vulnerability in VMware vCloud Director 5.1.x before 5.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout.
network
vmware CWE-352
6.8
2014-01-17 CVE-2014-1207 Denial of Service vulnerability in VMWare ESX and Esxi
VMware ESXi 4.0 through 5.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (NULL pointer dereference) by intercepting and modifying Network File Copy (NFC) traffic.
network
vmware
4.3