CVE-2021-22048
- EPSS 0.87%
- Published 10.11.2021 18:15:08
- Last modified 21.11.2024 05:49:29
The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit this issue to elevate privileges ...
CVE-2021-21995
- EPSS 0.32%
- Published 13.07.2021 19:15:09
- Last modified 21.11.2024 05:49:24
OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-bounds read issue. A malicious actor with network access to port 427 on ESXi may be able to trigger a heap out-of-bounds read in OpenSLP service resulting in a denial-of-...
CVE-2021-21994
- EPSS 0.1%
- Published 13.07.2021 19:15:09
- Last modified 21.11.2024 05:49:24
SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request.
CVE-2020-4004
- EPSS 0.23%
- Published 20.11.2020 20:15:13
- Last modified 21.11.2024 05:32:08
VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x before 15.5.7), Fusion (11.x before 11.5.7) contain a use-after-free vulnerability in the XHCI USB controller. A maliciou...
CVE-2020-4005
- EPSS 0.21%
- Published 20.11.2020 20:15:13
- Last modified 21.11.2024 05:32:09
VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG) contains a privilege-escalation vulnerability that exists in the way certain system calls are being managed. A malicious actor with privileg...