CVE-2021-22040
- EPSS 0.67%
- Published 16.02.2022 17:15:10
- Last modified 21.11.2024 05:49:29
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX pr...
CVE-2020-3990
- EPSS 0.04%
- Published 16.09.2020 17:15:14
- Last modified 21.11.2024 05:32:07
VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an information disclosure vulnerability due to an integer overflow issue in Cortado ThinPrint component. A malicious actor with normal access to a virtual machine may...
CVE-2020-3989
- EPSS 0.04%
- Published 16.09.2020 17:15:14
- Last modified 21.11.2024 05:32:07
VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain a denial of service vulnerability due to an out-of-bounds write issue in Cortado ThinPrint component. A malicious actor with normal access to a virtual machine may be...
CVE-2020-3988
- EPSS 0.05%
- Published 16.09.2020 17:15:14
- Last modified 21.11.2024 05:32:07
VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (JPEG2000 parser). A malicious actor with normal access to a virtual machine may be able to exploit...
CVE-2020-3987
- EPSS 0.05%
- Published 16.09.2020 17:15:13
- Last modified 21.11.2024 05:32:07
VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMR STRETCHDIBITS parser). A malicious actor with normal access to a virtual machine may be able t...
CVE-2020-3986
- EPSS 0.05%
- Published 16.09.2020 17:15:13
- Last modified 21.11.2024 05:32:06
VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMF Parser). A malicious actor with normal access to a virtual machine may be able to exploit thes...
CVE-2018-6957
- EPSS 0.38%
- Published 15.03.2018 19:29:01
- Last modified 21.11.2024 04:11:28
VMware Workstation (14.x before 14.1.1, 12.x) and Fusion (10.x before 10.1.1 and 8.x) contain a denial-of-service vulnerability which can be triggered by opening a large number of VNC sessions. Note: In order for exploitation to be possible on Workst...
CVE-2017-4933
- EPSS 7.08%
- Published 20.12.2017 15:29:00
- Last modified 20.04.2025 01:37:25
VMware ESXi (6.5 before ESXi650-201710401-BG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could allow an authenticated VNC session to cause a heap overflow via a specific set of VNC packets resulting ...
CVE-2017-4925
- EPSS 0.19%
- Published 15.09.2017 13:29:00
- Last modified 20.04.2025 01:37:25
VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Workstation (12.x before 12.5.3), Fusion (8.x before 8.5.4) contain a NULL pointer dereference vulnerability...
CVE-2017-4924
- EPSS 0.07%
- Published 15.09.2017 13:29:00
- Last modified 20.04.2025 01:37:25
VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusion (8.x before 8.5.8) contain an out-of-bounds write vulnerability in SVGA device. This issue may allow a guest to execute code on the host.