CVE-2016-2076
- EPSS 1.4%
- Veröffentlicht 15.04.2016 14:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which allows remote attackers to hija...
- EPSS 89.05%
- Veröffentlicht 12.10.2015 10:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol.
- EPSS 3.32%
- Veröffentlicht 12.10.2015 10:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartbeat message.
CVE-2015-6932
- EPSS 0.74%
- Veröffentlicht 18.09.2015 22:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-4241
- EPSS 3.84%
- Veröffentlicht 17.07.2014 11:17:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect integrity via vectors related to WLS - Web Services.
CVE-2013-5971
- EPSS 2.02%
- Veröffentlicht 21.10.2013 10:54:30
- Zuletzt bearbeitet 29.04.2026 01:13:23
Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web sessions and gain privileges via unspecified vectors.
CVE-2013-1659
- EPSS 1.82%
- Veröffentlicht 22.02.2013 20:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 do not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attacke...
CVE-2012-6326
- EPSS 1.33%
- Veröffentlicht 22.02.2013 20:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
VMware vCenter Server 4.1 before Update 3 and 5.0 before Update 2, and vCSA 5.0 before Update 2, allows remote attackers to cause a denial of service (disk consumption) via vectors that trigger large log entries.
- EPSS 2.8%
- Veröffentlicht 15.02.2013 12:09:29
- Zuletzt bearbeitet 29.04.2026 01:13:23
VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update 3a, VMware VI-Client 2.5, VMware ESXi 3.5 through 4.1, and VMware ESX 3.5 through 4.1 do n...
CVE-2010-2928
- EPSS 0.36%
- Veröffentlicht 16.02.2011 01:00:02
- Zuletzt bearbeitet 16.06.2026 23:21:46
The vCenter Tomcat Management Application in VMware vCenter Server 4.1 before Update 1 stores log-on credentials in a configuration file, which allows local users to gain privileges by reading this file.