Show filters
100 Total Results
Displaying 61-70 of 100
Sort by:
Attacker Value
Unknown
CVE-2019-5531
Disclosure Date: September 18, 2019 (last updated November 27, 2024)
VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 prior to ESXi600-201807103-SG) and VMware vCenter Server (6.7 prior to 6.7 U1b, 6.5 prior to 6.5 U2b, and 6.0 prior to 6.0 U3j) contain an information disclosure vulnerability in clients arising from insufficient session expiration. An attacker with physical access or an ability to mimic a websocket connection to a user’s browser may be able to obtain control of a VM Console after the user has logged out or their session has timed out.
0
Attacker Value
Unknown
CVE-2019-5534
Disclosure Date: September 18, 2019 (last updated November 27, 2024)
VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability where Virtual Machines deployed from an OVF could expose login information via the virtual machine's vAppConfig properties. A malicious actor with access to query the vAppConfig properties of a virtual machine deployed from an OVF may be able to view the credentials used to deploy the OVF (typically the root account of the virtual machine).
0
Attacker Value
Unknown
CVE-2019-5532
Disclosure Date: September 18, 2019 (last updated November 27, 2024)
VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability due to the logging of credentials in plain-text for virtual machines deployed through OVF. A malicious user with access to the log files containing vCenter OVF-properties of a virtual machine deployed from an OVF may be able to view the credentials used to deploy the OVF (typically the root account of the virtual machine).
0
Attacker Value
Unknown
CVE-2019-5492
Disclosure Date: April 29, 2019 (last updated November 27, 2024)
Element Plug-in for vCenter Server versions prior to 4.2.3 may disclose sensitive account information to an unauthenticated attacker. NetApp HCI Compute Node versions prior to 1.4P2 bundle affected versions of Element Plug-in for vCenter Server.
0
Attacker Value
Unknown
CVE-2017-4943
Disclosure Date: December 20, 2017 (last updated November 26, 2024)
VMware vCenter Server Appliance (vCSA) (6.5 before 6.5 U1d) contains a local privilege escalation vulnerability via the 'showlog' plugin. Successful exploitation of this issue could result in a low privileged user gaining root level privileges over the appliance base OS.
0
Attacker Value
Unknown
CVE-2017-4928
Disclosure Date: November 17, 2017 (last updated November 26, 2024)
The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRLF injection issues due to improper neutralization of URLs. An attacker may exploit these issues by sending a POST request with modified headers towards internal services leading to information disclosure.
0
Attacker Value
Unknown
CVE-2017-4927
Disclosure Date: November 17, 2017 (last updated November 26, 2024)
VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP network packets which may allow for remote denial of service.
0
Attacker Value
Unknown
CVE-2017-4926
Disclosure Date: September 15, 2017 (last updated November 26, 2024)
VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which will get executed when other VC users access the page.
0
Attacker Value
Unknown
CVE-2017-4922
Disclosure Date: August 01, 2017 (last updated November 26, 2024)
VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script using world writable directories as temporary storage for critical information. Successful exploitation of this issue may allow unprivileged host users to access certain critical information when the service gets restarted.
0
Attacker Value
Unknown
CVE-2017-4921
Disclosure Date: August 01, 2017 (last updated November 26, 2024)
VMware vCenter Server (6.5 prior to 6.5 U1) contains an insecure library loading issue that occurs due to the use of LD_LIBRARY_PATH variable in an unsafe manner. Successful exploitation of this issue may allow unprivileged host users to load a shared library that may lead to privilege escalation.
0