Vulnerabilities > Vmware > Vcenter Server > 5.1

DATE CVE VULNERABILITY TITLE RISK
2016-07-03 CVE-2015-6931 Cross-site Scripting vulnerability in VMWare Vcenter Server 5.0/5.1/5.5
Cross-site scripting (XSS) vulnerability in the vSphere Web Client in VMware vCenter Server 5.0 before U3g, 5.1 before U3d, and 5.5 before U2d allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
network
vmware CWE-79
4.3
2016-06-08 CVE-2016-2078 Cross-site Scripting vulnerability in VMWare Vcenter Server
Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5.1 before update 3d, 5.5 before update 3d, and 6.0 before update 2 on Windows allows remote attackers to inject arbitrary web script or HTML via the flashvars parameter.
4.3
2015-10-12 CVE-2015-2342 Remote Code Execution vulnerability in VMware vCenter Server
The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol.
network
low complexity
vmware
critical
10.0
2015-10-12 CVE-2015-1047 Improper Input Validation vulnerability in VMWare Vcenter Server 5.0/5.1/5.5
vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartbeat message.
network
low complexity
vmware CWE-20
5.0
2014-07-17 CVE-2014-4241 Remote Security vulnerability in Oracle WebLogic Server
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect integrity via vectors related to WLS - Web Services.
network
vmware oracle
4.3