10

CVE-2005-4459

Exploit

Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT and (2) PORT FTP commands.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMwareAce Version1.0
VMwareGsx Server Version2.0
VMwareGsx Server Version2.0.1_build_2129
VMwareGsx Server Version2.5.1
VMwareGsx Server Version2.5.1_build_5336
VMwareGsx Server Version2.5.2
VMwareGsx Server Version3.0
VMwareGsx Server Version3.0_build_7592
VMwareGsx Server Version3.1
VMwareGsx Server Version3.2
VMwarePlayer Version1.0.0
VMwareWorkstation Version3.2.1 Updatepatch1
VMwareWorkstation Version3.4
VMwareWorkstation Version4.0
VMwareWorkstation Version4.0.1
VMwareWorkstation Version4.0.2
VMwareWorkstation Version4.5.2
VMwareWorkstation Version4.5.2_build_8848 Updater4
VMwareWorkstation Version5.0.0_build_13124
VMwareWorkstation Version5.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 63.37% 0.982
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.