Show filters
121 Total Results
Displaying 101-110 of 121
Sort by:
Attacker Value
Unknown

CVE-2013-5971

Disclosure Date: October 21, 2013 (last updated October 05, 2023)
Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web sessions and gain privileges via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-4092

Disclosure Date: September 26, 2013 (last updated October 05, 2023)
The management interface in the Central Software component in Cisco Unified Computing System (UCS) does not properly validate the identity of vCenter consoles, which allows man-in-the-middle attackers to read or modify an inter-device data stream by spoofing an identity, aka Bug ID CSCtk00683.
0
Attacker Value
Unknown

CVE-2013-3520

Disclosure Date: June 17, 2013 (last updated October 05, 2023)
VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-1212

Disclosure Date: May 29, 2013 (last updated October 05, 2023)
The SSL functionality in Cisco NX-OS on the Nexus 1000V does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof servers, and intercept or modify Virtual Supervisor Module (VSM) to VMware vCenter communication, via a crafted certificate, aka Bug ID CSCud14837.
0
Attacker Value
Unknown

CVE-2013-3080

Disclosure Date: May 01, 2013 (last updated October 05, 2023)
VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to create or overwrite arbitrary files, and consequently execute arbitrary code or cause a denial of service, by leveraging Virtual Appliance Management Interface (VAMI) web-interface access.
0
Attacker Value
Unknown

CVE-2013-3107

Disclosure Date: May 01, 2013 (last updated October 05, 2023)
VMware vCenter Server 5.1 before Update 1, when anonymous LDAP binding for Active Directory is enabled, allows remote attackers to bypass authentication by providing a valid username in conjunction with an empty password.
0
Attacker Value
Unknown

CVE-2013-3079

Disclosure Date: May 01, 2013 (last updated October 05, 2023)
VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to execute arbitrary programs with root privileges by leveraging Virtual Appliance Management Interface (VAMI) access.
0
Attacker Value
Unknown

CVE-2013-1659

Disclosure Date: February 22, 2013 (last updated October 05, 2023)
VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 do not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption) by modifying the client-server data stream.
0
Attacker Value
Unknown

CVE-2012-6326

Disclosure Date: February 22, 2013 (last updated October 05, 2023)
VMware vCenter Server 4.1 before Update 3 and 5.0 before Update 2, and vCSA 5.0 before Update 2, allows remote attackers to cause a denial of service (disk consumption) via vectors that trigger large log entries.
0
Attacker Value
Unknown

CVE-2013-1405

Disclosure Date: February 15, 2013 (last updated October 05, 2023)
VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update 3a, VMware VI-Client 2.5, VMware ESXi 3.5 through 4.1, and VMware ESX 3.5 through 4.1 do not properly implement the management authentication protocol, which allow remote servers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
0