Show filters
61 Total Results
Displaying 41-50 of 61
Sort by:
Attacker Value
Unknown

CVE-2014-4632

Disclosure Date: February 01, 2015 (last updated October 05, 2023)
VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly verify X.509 certificates from vCenter Server SSL servers, which allows man-in-the-middle attackers to spoof servers, and bypass intended backup and restore access restrictions, via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-3797

Disclosure Date: December 08, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in VMware vCenter Server Appliance (vCSA) 5.1 before Update 3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-8371

Disclosure Date: December 08, 2014 (last updated October 05, 2023)
VMware vCenter Server Appliance (vCSA) 5.5 before Update 2, 5.1 before Update 3, and 5.0 before Update 3c does not properly validate certificates when connecting to a CIM Server on an ESXi host, which allows man-in-the-middle attackers to spoof CIM servers via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-3790

Disclosure Date: June 01, 2014 (last updated October 05, 2023)
Ruby vSphere Console (RVC) in VMware vCenter Server Appliance allows remote authenticated users to execute arbitrary commands as root by escaping from a chroot jail.
0
Attacker Value
Unknown

CVE-2013-5973

Disclosure Date: December 23, 2013 (last updated October 05, 2023)
VMware ESXi 4.0 through 5.5 and ESX 4.0 and 4.1 allow local users to read or modify arbitrary files by leveraging the Virtual Machine Power User or Resource Pool Administrator role for a vCenter Server Add Existing Disk action with a (1) -flat, (2) -rdm, or (3) -rdmp filename.
0
Attacker Value
Unknown

CVE-2013-5971

Disclosure Date: October 21, 2013 (last updated October 05, 2023)
Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web sessions and gain privileges via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-3080

Disclosure Date: May 01, 2013 (last updated October 05, 2023)
VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to create or overwrite arbitrary files, and consequently execute arbitrary code or cause a denial of service, by leveraging Virtual Appliance Management Interface (VAMI) web-interface access.
0
Attacker Value
Unknown

CVE-2013-3107

Disclosure Date: May 01, 2013 (last updated October 05, 2023)
VMware vCenter Server 5.1 before Update 1, when anonymous LDAP binding for Active Directory is enabled, allows remote attackers to bypass authentication by providing a valid username in conjunction with an empty password.
0
Attacker Value
Unknown

CVE-2013-3079

Disclosure Date: May 01, 2013 (last updated October 05, 2023)
VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to execute arbitrary programs with root privileges by leveraging Virtual Appliance Management Interface (VAMI) access.
0
Attacker Value
Unknown

CVE-2013-1659

Disclosure Date: February 22, 2013 (last updated October 05, 2023)
VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 do not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption) by modifying the client-server data stream.
0