Show filters
100 Total Results
Displaying 21-30 of 100
Sort by:
Attacker Value
Unknown
CVE-2023-20896
Disclosure Date: June 22, 2023 (last updated October 08, 2023)
The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to denial-of-service of certain services (vmcad, vmdird, and vmafdd).
0
Attacker Value
Unknown
CVE-2023-20895
Disclosure Date: June 22, 2023 (last updated October 08, 2023)
The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass authentication.
0
Attacker Value
Unknown
CVE-2023-20894
Disclosure Date: June 22, 2023 (last updated October 08, 2023)
The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption.
0
Attacker Value
Unknown
CVE-2023-20893
Disclosure Date: June 22, 2023 (last updated October 08, 2023)
The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hosts vCenter Server.
0
Attacker Value
Unknown
CVE-2023-20892
Disclosure Date: June 22, 2023 (last updated October 08, 2023)
The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execute arbitrary code on the underlying operating system that hosts vCenter Server.
0
Attacker Value
Unknown
CVE-2022-31680
Disclosure Date: October 07, 2022 (last updated October 08, 2023)
The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit this issue to execute arbitrary code on the underlying operating system that hosts the vCenter Server.
0
Attacker Value
Unknown
CVE-2022-22982
Disclosure Date: July 13, 2022 (last updated October 07, 2023)
The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service.
0
Attacker Value
Unknown
CVE-2022-2048
Disclosure Date: July 07, 2022 (last updated October 07, 2023)
In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good requests.
0
Attacker Value
Unknown
CVE-2022-2047
Disclosure Date: July 07, 2022 (last updated October 07, 2023)
In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This can lead to failures in a Proxy scenario.
0
Attacker Value
Unknown
CVE-2022-22948
Disclosure Date: March 29, 2022 (last updated February 11, 2025)
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.
0