Show filters
44 Total Results
Displaying 11-20 of 44
Sort by:
Attacker Value
Unknown

CVE-2022-31698

Disclosure Date: December 13, 2022 (last updated October 08, 2023)
The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to trigger a denial-of-service condition by sending a specially crafted header.
Attacker Value
Unknown

CVE-2024-37080

Disclosure Date: June 18, 2024 (last updated August 31, 2024)
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
Attacker Value
Unknown

CVE-2023-34056

Disclosure Date: October 25, 2023 (last updated November 01, 2023)
vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data.
Attacker Value
Unknown

CVE-2023-20896

Disclosure Date: June 22, 2023 (last updated October 08, 2023)
The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to denial-of-service of certain services (vmcad, vmdird, and vmafdd).
Attacker Value
Unknown

CVE-2023-20895

Disclosure Date: June 22, 2023 (last updated October 08, 2023)
The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass authentication.
Attacker Value
Unknown

CVE-2023-20894

Disclosure Date: June 22, 2023 (last updated October 08, 2023)
The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption.
Attacker Value
Unknown

CVE-2023-20893

Disclosure Date: June 22, 2023 (last updated October 08, 2023)
The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hosts vCenter Server.
Attacker Value
Unknown

CVE-2023-20892

Disclosure Date: June 22, 2023 (last updated October 08, 2023)
The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execute arbitrary code on the underlying operating system that hosts vCenter Server.
Attacker Value
Unknown

CVE-2022-22982

Disclosure Date: July 13, 2022 (last updated October 07, 2023)
The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service.
Attacker Value
Unknown

CVE-2022-22948

Disclosure Date: March 29, 2022 (last updated February 11, 2025)
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.