Vulnerabilities > Vmware > Workstation > 8.0.0.18997

DATE CVE VULNERABILITY TITLE RISK
2014-08-28 CVE-2014-4200 Permissions, Privileges, and Access Controls vulnerability in VMWare Tools, Vm-Support and Workstation
vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, uses 0644 permissions for the vm-support archive, which allows local users to obtain sensitive information by extracting files from this archive.
local
vmware CWE-264
4.7
2014-08-28 CVE-2014-4199 Link Following vulnerability in VMWare Tools, Vm-Support and Workstation
vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to write to arbitrary files via a symlink attack on a file in /tmp.
local
vmware CWE-59
6.3
2013-08-24 CVE-2013-1662 Permissions, Privileges, and Access Controls vulnerability in VMWare Player and Workstation
vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host OS privileges via a crafted lsb_release binary in a directory in the PATH, related to use of the popen library function.
local
vmware CWE-264
6.9
2013-02-11 CVE-2013-1406 Improper Input Validation vulnerability in VMWare products
The Virtual Machine Communication Interface (VMCI) implementation in vmci.sys in VMware Workstation 8.x before 8.0.5 and 9.x before 9.0.1 on Windows, VMware Fusion 4.1 before 4.1.4 and 5.0 before 5.0.2, VMware View 4.x before 4.6.2 and 5.x before 5.1.2 on Windows, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1 does not properly restrict memory allocation by control code, which allows local users to gain privileges via unspecified vectors.
local
low complexity
vmware microsoft CWE-20
7.2
2012-11-14 CVE-2012-5459 Unspecified vulnerability in VMWare Player and Workstation
Untrusted search path vulnerability in VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows allows host OS users to gain host OS privileges via a Trojan horse DLL in a "system folder." Per: http://cwe.mitre.org/data/definitions/426.html "CWE-426: Untrusted Search Path"
7.9
2012-11-14 CVE-2012-5458 Permissions, Privileges, and Access Controls vulnerability in VMWare Player and Workstation
VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows use weak permissions for unspecified process threads, which allows host OS users to gain host OS privileges via a crafted application.
low complexity
vmware microsoft CWE-264
8.3
2012-11-14 CVE-2012-3569 USE of Externally-Controlled Format String vulnerability in VMWare OVF Tool, Player and Workstation
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.5, and other products, allows user-assisted remote attackers to execute arbitrary code via a crafted OVF file.
network
vmware microsoft CWE-134
critical
9.3
2012-09-08 CVE-2012-1666 Unspecified vulnerability in VMWare products
Untrusted search path vulnerability in VMware Tools in VMware Workstation before 8.0.4, VMware Player before 4.0.4, VMware Fusion before 4.1.2, VMware View before 5.1, and VMware ESX 4.1 before U3 and 5.0 before P03 allows local users to gain privileges via a Trojan horse tpfc.dll file in the current working directory.
local
vmware
6.9