Show filters
27 Total Results
Displaying 11-20 of 27
Sort by:
Attacker Value
Unknown

CVE-2017-4945

Disclosure Date: January 05, 2018 (last updated November 26, 2024)
VMware Workstation (14.x and 12.x) and Fusion (10.x and 8.x) contain a guest access control vulnerability. This issue may allow program execution via Unity on locked Windows VMs. VMware Tools must be updated to 10.2.0 for each VM to resolve CVE-2017-4945. VMware Tools 10.2.0 is consumed by Workstation 14.1.0 and Fusion 10.1.0 by default.
0
Attacker Value
Unknown

CVE-2017-4938

Disclosure Date: November 17, 2017 (last updated November 26, 2024)
VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL pointer dereference vulnerability. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.
0
Attacker Value
Unknown

CVE-2017-4934

Disclosure Date: November 17, 2017 (last updated November 26, 2024)
VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a heap buffer-overflow vulnerability in VMNAT device. This issue may allow a guest to execute code on the host.
0
Attacker Value
Unknown

CVE-2017-4901

Disclosure Date: June 08, 2017 (last updated November 26, 2024)
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.
0
Attacker Value
Unknown

CVE-2016-5329

Disclosure Date: December 29, 2016 (last updated November 25, 2024)
VMware Fusion 8.x before 8.5 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and bypass the kASLR protection mechanism via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-7461

Disclosure Date: December 29, 2016 (last updated November 25, 2024)
The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion and Fusion Pro 8.x before 8.5.2 allows guest OS users to execute arbitrary code on the host OS or cause a denial of service (out-of-bounds memory access on the host OS) via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-3576

Disclosure Date: August 14, 2015 (last updated November 08, 2023)
The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.
0
Attacker Value
Unknown

CVE-2011-0735

Disclosure Date: February 01, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via vectors involving a "tag script."
0
Attacker Value
Unknown

CVE-2011-0734

Disclosure Date: February 01, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via an id parameter containing a JavaScript onLoad event handler for a BODY element, related to a "tag body" attack. NOTE: this was originally reported as affecting 9.0.1 CHF1 and earlier.
0
Attacker Value
Unknown

CVE-2011-0737

Disclosure Date: February 01, 2011 (last updated November 08, 2023)
Adobe ColdFusion 9.0.1 CHF1 and earlier allows remote attackers to obtain sensitive information via an id=- query to a .cfm file, which reveals the installation path in an error message. NOTE: the vendor disputes the significance of this issue because the Site-wide Error Handler and Debug Output Settings sections of the ColdFusion Lockdown guide explain the requirement for settings that prevent this information disclosure
0