|
247721
|
5.5 |
MEDIUM
Local
|
vmware
|
fusion fusion_pro esxi workstation_player workstation_pro
|
VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, 5.5 without patch …
|
CWE-908
Use of Uninitialized Resource
|
CVE-2017-4905
|
2024-11-21 12:26 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247722
|
8.8 |
HIGH
Local
|
vmware
|
esxi workstation_player workstation_pro fusion fusion_pro
|
VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without pa…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-4903
|
2024-11-21 12:26 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247723
|
8.8 |
HIGH
Local
|
vmware
|
esxi workstation_player workstation_pro fusion fusion_pro
|
VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have a Heap Bu…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-4902
|
2024-11-21 12:26 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247724
|
5.5 |
MEDIUM
Local
|
vmware
|
workstation_player workstation_pro
|
VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SVGA driver. Successful exploitation of this issue may allow attackers with norma…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-4900
|
2024-11-21 12:26 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247725
|
8.8 |
HIGH
Local
|
vmware
|
fusion fusion_pro esxi workstation_player workstation_pro
|
The XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-4904
|
2024-11-21 12:26 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247726
|
4.7 |
MEDIUM
Local
|
vmware
|
workstation_player workstation_pro
|
VMware Workstation Pro/Player 12.x before 12.5.3 contains a security vulnerability that exists in the SVGA driver. An attacker may exploit this issue to crash the VM or trigger an out-of-bound read. …
|
CWE-125
Out-of-bounds Read
|
CVE-2017-4899
|
2024-11-21 12:26 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247727
|
8.8 |
HIGH
Local
|
vmware
|
workstation_player workstation_pro
|
VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a path defined in the local environment-variable. S…
|
NVD-CWE-noinfo
|
CVE-2017-4898
|
2024-11-21 12:26 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247728
|
9.8 |
CRITICAL
Network
|
vmware
|
vsphere_data_protection
|
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2017-4917
|
2024-11-21 12:26 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247729
|
9.8 |
CRITICAL
Network
|
vmware
|
vsphere_data_protection
|
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-4914
|
2024-11-21 12:26 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247730
|
3.3 |
LOW
Local
|
lenovo
|
power_management
|
In the Lenovo Power Management driver before 1.67.12.24, a local user may alter the trackpoint's firmware and stop the trackpoint from functioning correctly. This issue only affects ThinkPad X1 Carbo…
|
NVD-CWE-noinfo
|
CVE-2017-3741
|
2024-11-21 12:26 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|