|
250441
|
5.5 |
MEDIUM
Local
|
vmware
|
workstation fusion
|
VMware Workstation (14.x and 12.x) and Fusion (10.x and 8.x) contain a guest access control vulnerability. This issue may allow program execution via Unity on locked Windows VMs. VMware Tools must be…
|
NVD-CWE-noinfo
|
CVE-2017-4945
|
2024-11-21 12:26 |
2018-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250442
|
7.8 |
HIGH
Local
|
vmware
|
vcenter_server
|
VMware vCenter Server Appliance (vCSA) (6.5 before 6.5 U1d) contains a local privilege escalation vulnerability via the 'showlog' plugin. Successful exploitation of this issue could result in a low p…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-4943
|
2024-11-21 12:26 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250443
|
8.8 |
HIGH
Network
|
vmware
|
fusion workstation esxi
|
VMware ESXi (6.0 before ESXi600-201711101-SG, 5.5 ESXi550-201709101-SG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could allow an authenticated VNC …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-4941
|
2024-11-21 12:26 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250444
|
6.1 |
MEDIUM
Network
|
vmware
|
esxi
|
The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESXi550-201709102-SG) contains a vulnerability that may allow for stored cross-sit…
|
CWE-79
Cross-site Scripting
|
CVE-2017-4940
|
2024-11-21 12:26 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250445
|
8.8 |
HIGH
Network
|
vmware
|
workstation_pro esxi fusion
|
VMware ESXi (6.5 before ESXi650-201710401-BG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could allow an authenticated VNC session to cause a heap ov…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-4933
|
2024-11-21 12:26 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250446
|
4.9 |
MEDIUM
Network
|
vmware
|
airwatch_console
|
VMware AirWatch Console (AWC) contains a Broken Access Control vulnerability. Successful exploitation of this issue could result in end-user device details being disclosed to an unauthorized administ…
|
NVD-CWE-noinfo
|
CVE-2017-4942
|
2024-11-21 12:26 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250447
|
5.9 |
MEDIUM
Network
|
openssl debian nodejs
|
openssl debian_linux node.js
|
There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA…
|
CWE-200
Information Exposure
|
CVE-2017-3738
|
2024-11-21 12:26 |
2017-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250448
|
5.9 |
MEDIUM
Network
|
openssl debian
|
openssl debian_linux
|
OpenSSL 1.0.2 (starting from version 1.0.2b) introduced an "error state" mechanism. The intent was that if a fatal error occurred during a handshake then OpenSSL would move into the error state and w…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2017-3737
|
2024-11-21 12:26 |
2017-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250449
|
5.9 |
MEDIUM
Network
|
vmware
|
nsx-v_edge
|
The implementation of the OSPF protocol in VMware NSX-V Edge 6.2.x prior to 6.2.8 and NSX-V Edge 6.3.x prior to 6.3.3 doesn't correctly handle the link-state advertisement (LSA). A rogue LSA may expl…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-4920
|
2024-11-21 12:26 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250450
|
5.3 |
MEDIUM
Network
|
lenovo
|
xclarity_administrator
|
A vulnerability was identified in Lenovo XClarity Administrator (LXCA) before 1.4.0 where LXCA user account names may be exposed to unauthenticated users with access to the LXCA web user interface. N…
|
CWE-200
Information Exposure
|
CVE-2017-3764
|
2024-11-21 12:26 |
2017-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|