Show filters
2,480 Total Results
Displaying 51-60 of 2,480
Sort by:
Attacker Value
Unknown

CVE-2024-22273

Disclosure Date: May 21, 2024 (last updated May 22, 2024)
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or execute code on the hypervisor from a virtual machine in conjunction with other issues.
0
Attacker Value
Unknown

CVE-2024-22270

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.
0
Attacker Value
Unknown

CVE-2024-22269

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.
0
Attacker Value
Unknown

CVE-2024-22268

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to create a denial of service condition.
0
Attacker Value
Unknown

CVE-2024-22255

Disclosure Date: March 05, 2024 (last updated March 06, 2024)
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.  
0
Attacker Value
Unknown

CVE-2024-22253

Disclosure Date: March 05, 2024 (last updated March 06, 2024)
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.
0
Attacker Value
Unknown

CVE-2024-22252

Disclosure Date: March 05, 2024 (last updated March 06, 2024)
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.
0
Attacker Value
Unknown

CVE-2024-22251

Disclosure Date: February 29, 2024 (last updated February 29, 2024)
VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on a virtual machine may trigger an out-of-bounds read leading to information disclosure.
0
Attacker Value
Unknown

CVE-2023-6138

Disclosure Date: February 14, 2024 (last updated February 15, 2024)
A potential security vulnerability has been identified in the system BIOS for certain HP Workstation PCs, which might allow escalation of privilege, arbitrary code execution, or denial of service. HP is releasing mitigation for the potential vulnerability.
0
Attacker Value
Unknown

CVE-2024-23622

Disclosure Date: January 26, 2024 (last updated February 01, 2024)
A stack-based buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vulnerability to achieve remote code execution with SYSTEM privileges.