10
CVE-2005-4459
- EPSS 14.12%
- Veröffentlicht 21.12.2005 20:03:00
- Zuletzt bearbeitet 07.07.2026 22:01:29
- Erkennungen
Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT and (2) PORT FTP commands.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Gsx Server Version 2.0
VMware ≫ Gsx Server Version 2.0.1_build_2129
VMware ≫ Gsx Server Version 2.5.1
VMware ≫ Gsx Server Version 2.5.1_build_5336
VMware ≫ Gsx Server Version 2.5.2
VMware ≫ Gsx Server Version 3.0
VMware ≫ Gsx Server Version 3.0_build_7592
VMware ≫ Gsx Server Version 3.1
VMware ≫ Gsx Server Version 3.2
VMware ≫ Workstation Version 3.2.1 Update patch1
VMware ≫ Workstation Version 3.4
VMware ≫ Workstation Version 4.0
VMware ≫ Workstation Version 4.0.1
VMware ≫ Workstation Version 4.0.2
VMware ≫ Workstation Version 4.5.2
VMware ≫ Workstation Version 4.5.2_build_8848 Update r4
VMware ≫ Workstation Version 5.0.0_build_13124
VMware ≫ Workstation Version 5.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 14.12% | 0.961 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
http://secunia.com/advisories/18162
http://secunia.com/advisories/18344
http://securityreason.com/securityalert/282
http://securityreason.com/securityalert/289
http://securitytracker.com/id?1015401
http://www.gentoo.org/security/en/glsa/glsa-200601-04.xml
http://www.kb.cert.org/vuls/id/856689
http://www.securityfocus.com/archive/1/419997/100/0/threaded
http://www.securityfocus.com/archive/1/420017/100/0/threaded
http://www.securityfocus.com/bid/15998
http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=2000
http://www.vupen.com/english/advisories/2005/3013
http://lists.grok.org.uk/pipermail/full-disclosure/2005-December/040442.html