5

CVE-2009-3707

Exploit

VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, and VMware Server 2.x allows remote attackers to cause a denial of service (process crash) via a \x25\xFF sequence in the USER and PASS commands, related to a "format string DoS" issue. NOTE: some of these details are obtained from third party information.

Data is provided by the National Vulnerability Database (NVD)
VMwareAce Version2.5.0
VMwareAce Version2.5.1
VMwareAce Version2.5.2
VMwareAce Version2.5.3
VMwareAce Version2.5.4
VMwareAce Version2.6
VMwareAce Version2.6.1
VMwarePlayer Version2.5
VMwarePlayer Version2.5.1
VMwarePlayer Version2.5.2
VMwarePlayer Version2.5.3
VMwarePlayer Version2.5.4
VMwarePlayer Version3.0
VMwarePlayer Version3.0.1
VMwareServer Version2.0.0
VMwareServer Version2.0.1
VMwareServer Version2.0.2
VMwareWorkstation Version6.5.0
VMwareWorkstation Version6.5.1
VMwareWorkstation Version6.5.2
VMwareWorkstation Version6.5.3
VMwareWorkstation Version6.5.4
VMwareWorkstation Version7.0
VMwareWorkstation Version7.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 21.26% 0.955
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-134 Use of Externally-Controlled Format String

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.