Show filters
61 Total Results
Displaying 31-40 of 61
Sort by:
Attacker Value
Unknown
CVE-2016-7458
Disclosure Date: December 29, 2016 (last updated November 25, 2024)
VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
0
Attacker Value
Unknown
CVE-2016-7460
Disclosure Date: December 29, 2016 (last updated November 25, 2024)
The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
0
Attacker Value
Unknown
CVE-2016-7459
Disclosure Date: December 29, 2016 (last updated November 25, 2024)
VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distributed Switch setup, or (3) Content Library XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
0
Attacker Value
Unknown
CVE-2016-5331
Disclosure Date: August 08, 2016 (last updated November 25, 2024)
CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-6931
Disclosure Date: July 03, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the vSphere Web Client in VMware vCenter Server 5.0 before U3g, 5.1 before U3d, and 5.5 before U2d allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
0
Attacker Value
Unknown
CVE-2016-2078
Disclosure Date: June 08, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5.1 before update 3d, 5.5 before update 3d, and 6.0 before update 2 on Windows allows remote attackers to inject arbitrary web script or HTML via the flashvars parameter.
0
Attacker Value
Unknown
CVE-2016-2076
Disclosure Date: April 15, 2016 (last updated November 25, 2024)
Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which allows remote attackers to hijack sessions via a crafted web site.
0
Attacker Value
Unknown
CVE-2015-2342
Disclosure Date: October 12, 2015 (last updated October 05, 2023)
The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol.
0
Attacker Value
Unknown
CVE-2015-1047
Disclosure Date: October 12, 2015 (last updated October 05, 2023)
vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartbeat message.
0
Attacker Value
Unknown
CVE-2015-6932
Disclosure Date: September 18, 2015 (last updated October 05, 2023)
VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0