Show filters
139 Total Results
Displaying 11-20 of 139
Sort by:
Attacker Value
Unknown
CVE-2024-22253
Disclosure Date: March 05, 2024 (last updated March 06, 2024)
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.
0
Attacker Value
Unknown
CVE-2024-22252
Disclosure Date: March 05, 2024 (last updated March 06, 2024)
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.
0
Attacker Value
Unknown
CVE-2023-29552
Disclosure Date: April 25, 2023 (last updated October 08, 2023)
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
0
Attacker Value
Unknown
CVE-2022-31705
Disclosure Date: December 14, 2022 (last updated October 08, 2023)
VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.
0
Attacker Value
Unknown
CVE-2022-31681
Disclosure Date: October 07, 2022 (last updated October 08, 2023)
VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process only, may create a denial of service condition on the host.
0
Attacker Value
Unknown
CVE-2022-29901
Disclosure Date: July 12, 2022 (last updated October 18, 2023)
Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.
0
Attacker Value
Unknown
CVE-2022-23825
Disclosure Date: July 12, 2022 (last updated November 08, 2023)
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.
0
Attacker Value
Unknown
CVE-2022-21166
Disclosure Date: June 15, 2022 (last updated October 07, 2023)
Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
0
Attacker Value
Unknown
CVE-2022-21125
Disclosure Date: June 15, 2022 (last updated October 07, 2023)
Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
0
Attacker Value
Unknown
CVE-2022-21123
Disclosure Date: June 15, 2022 (last updated October 07, 2023)
Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
0