VMware

Horizon

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 11.04.2022 20:15:19
  • Zuletzt bearbeitet 21.11.2024 06:47:41

VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder location due to a vulnerable symbolic link. Successful exploitation can result in linking to a root owned file.

  • EPSS 0.04%
  • Veröffentlicht 11.04.2022 20:15:19
  • Zuletzt bearbeitet 21.11.2024 06:47:41

VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to root due to a vulnerable configuration file.

  • EPSS 0.08%
  • Veröffentlicht 28.01.2022 20:15:12
  • Zuletzt bearbeitet 21.11.2024 06:47:38

VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-service vulnerability in the Cortado ThinPrint component. The issue exists in TrueType font parser. A malicious actor with access to a ...

  • EPSS 0.23%
  • Veröffentlicht 23.10.2020 14:15:12
  • Zuletzt bearbeitet 21.11.2024 05:32:08

VMware Horizon Server (7.x prior to 7.10.3 or 7.13.0) contains a Cross Site Scripting (XSS) vulnerability. Successful exploitation of this issue may allow an attacker to inject malicious script which will be executed.

  • EPSS 0.03%
  • Veröffentlicht 10.10.2019 17:15:18
  • Zuletzt bearbeitet 21.11.2024 04:45:07

ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.5.

  • EPSS 0.31%
  • Veröffentlicht 09.04.2019 20:30:20
  • Zuletzt bearbeitet 21.11.2024 04:45:05

VMware Horizon Connection Server (7.x before 7.8, 7.5.x before 7.5.2, 6.x before 6.2.8) contains an information disclosure vulnerability. Successful exploitation of this issue may allow disclosure of internal domain names, the Connection Server’s int...