|
250671
|
7.8 |
HIGH
Local
|
vmware
|
workstation horizon_view
|
VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple heap buffer-overflow vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-4908
|
2024-11-21 12:26 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250672
|
5.5 |
MEDIUM
Local
|
vmware
|
fusion fusion_pro esxi workstation_player workstation_pro
|
VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, 5.5 without patch …
|
CWE-908
Use of Uninitialized Resource
|
CVE-2017-4905
|
2024-11-21 12:26 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250673
|
8.8 |
HIGH
Local
|
vmware
|
esxi workstation_player workstation_pro fusion fusion_pro
|
VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without pa…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-4903
|
2024-11-21 12:26 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250674
|
8.8 |
HIGH
Local
|
vmware
|
esxi workstation_player workstation_pro fusion fusion_pro
|
VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have a Heap Bu…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-4902
|
2024-11-21 12:26 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250675
|
5.5 |
MEDIUM
Local
|
vmware
|
workstation_player workstation_pro
|
VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SVGA driver. Successful exploitation of this issue may allow attackers with norma…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-4900
|
2024-11-21 12:26 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250676
|
8.8 |
HIGH
Local
|
vmware
|
fusion fusion_pro esxi workstation_player workstation_pro
|
The XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-4904
|
2024-11-21 12:26 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250677
|
4.7 |
MEDIUM
Local
|
vmware
|
workstation_player workstation_pro
|
VMware Workstation Pro/Player 12.x before 12.5.3 contains a security vulnerability that exists in the SVGA driver. An attacker may exploit this issue to crash the VM or trigger an out-of-bound read. …
|
CWE-125
Out-of-bounds Read
|
CVE-2017-4899
|
2024-11-21 12:26 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250678
|
8.8 |
HIGH
Local
|
vmware
|
workstation_player workstation_pro
|
VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a path defined in the local environment-variable. S…
|
NVD-CWE-noinfo
|
CVE-2017-4898
|
2024-11-21 12:26 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250679
|
9.8 |
CRITICAL
Network
|
vmware
|
vsphere_data_protection
|
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2017-4917
|
2024-11-21 12:26 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250680
|
9.8 |
CRITICAL
Network
|
vmware
|
vsphere_data_protection
|
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-4914
|
2024-11-21 12:26 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|