Show filters
121 Total Results
Displaying 81-90 of 121
Sort by:
Attacker Value
Unknown
CVE-2017-4919
Disclosure Date: July 28, 2017 (last updated October 05, 2023)
VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating Systems without the need to authenticate.
0
Attacker Value
Unknown
CVE-2017-4917
Disclosure Date: June 07, 2017 (last updated October 05, 2023)
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained.
0
Attacker Value
Unknown
CVE-2015-4057
Disclosure Date: February 21, 2017 (last updated October 05, 2023)
The "Plug-in for VMware vCenter" in VCE Vision Intelligent Operations before 2.6.5 sends a cleartext HTTP response upon a request for the Settings screen, which allows remote attackers to discover the admin user password by sniffing the network.
0
Attacker Value
Unknown
CVE-2016-6110
Disclosure Date: February 01, 2017 (last updated October 05, 2023)
IBM Tivoli Storage Manager discloses unencrypted login credentials to Vmware vCenter that could be obtained by a local user.
0
Attacker Value
Unknown
CVE-2016-7458
Disclosure Date: December 29, 2016 (last updated October 05, 2023)
VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
0
Attacker Value
Unknown
CVE-2016-7460
Disclosure Date: December 29, 2016 (last updated October 05, 2023)
The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
0
Attacker Value
Unknown
CVE-2016-7459
Disclosure Date: December 29, 2016 (last updated October 05, 2023)
VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distributed Switch setup, or (3) Content Library XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
0
Attacker Value
Unknown
CVE-2016-5331
Disclosure Date: August 08, 2016 (last updated October 05, 2023)
CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-6931
Disclosure Date: July 03, 2016 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the vSphere Web Client in VMware vCenter Server 5.0 before U3g, 5.1 before U3d, and 5.5 before U2d allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
0
Attacker Value
Unknown
CVE-2016-2078
Disclosure Date: June 08, 2016 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5.1 before update 3d, 5.5 before update 3d, and 6.0 before update 2 on Windows allows remote attackers to inject arbitrary web script or HTML via the flashvars parameter.
0