CVE-2021-22043
- EPSS 0.46%
- Veröffentlicht 16.02.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 05:49:29
VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled. A malicious actor with access to settingsd, may exploit this issue to escalate their privileges by writing arbitrary files.
CVE-2021-22050
- EPSS 1.41%
- Veröffentlicht 16.02.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 05:49:30
ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to create a denial-of-service condition by overwhelming rhttpproxy service with multiple requests.
CVE-2021-22045
- EPSS 2.43%
- Veröffentlicht 04.01.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 05:49:29
VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A malicious actor with access to a virtu...
CVE-2021-21994
- EPSS 0.1%
- Veröffentlicht 13.07.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 05:49:24
SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request.
CVE-2021-21995
- EPSS 0.32%
- Veröffentlicht 13.07.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 05:49:24
OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-bounds read issue. A malicious actor with network access to port 427 on ESXi may be able to trigger a heap out-of-bounds read in OpenSLP service resulting in a denial-of-...
CVE-2021-21974
- EPSS 48.35%
- Veröffentlicht 24.02.2021 17:15:16
- Zuletzt bearbeitet 21.11.2024 05:49:21
OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427...
CVE-2020-3999
- EPSS 0.14%
- Veröffentlicht 21.12.2020 16:15:13
- Zuletzt bearbeitet 08.08.2025 10:32:53
VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12.x prior to 12.0 and 11.x prior to 11.5.7) and VMware Cloud Foundation contain a denial of service vulnerability due to ...
CVE-2020-4004
- EPSS 0.23%
- Veröffentlicht 20.11.2020 20:15:13
- Zuletzt bearbeitet 21.11.2024 05:32:08
VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x before 15.5.7), Fusion (11.x before 11.5.7) contain a use-after-free vulnerability in the XHCI USB controller. A maliciou...
CVE-2020-4005
- EPSS 0.21%
- Veröffentlicht 20.11.2020 20:15:13
- Zuletzt bearbeitet 21.11.2024 05:32:09
VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG) contains a privilege-escalation vulnerability that exists in the way certain system calls are being managed. A malicious actor with privileg...
CVE-2020-3995
- EPSS 0.38%
- Veröffentlicht 20.10.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:32:07
In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x before 15.1.0), Fusion (11.x before 11.1.0), the VMCI host drivers used by VMware hypervisors contain a memory leak vulnerability. A malicious actor ...