Show filters
28 Total Results
Displaying 1-10 of 28
Sort by:
Attacker Value
High
CVE-2020-3950
Disclosure Date: March 17, 2020 (last updated November 27, 2024)
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC or Horizon Client is installed.
0
Attacker Value
Unknown
CVE-2024-11468
Disclosure Date: February 04, 2025 (last updated February 05, 2025)
Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installation process. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed.
0
Attacker Value
Unknown
CVE-2024-11467
Disclosure Date: February 04, 2025 (last updated February 05, 2025)
Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed.
0
Attacker Value
Unknown
CVE-2023-34038
Disclosure Date: August 04, 2023 (last updated October 08, 2023)
VMware Horizon Server contains an information disclosure vulnerability. A malicious actor with network access may be able to access information relating to the internal network configuration.
0
Attacker Value
Unknown
CVE-2023-34037
Disclosure Date: August 04, 2023 (last updated October 08, 2023)
VMware Horizon Server contains a HTTP request smuggling vulnerability. A malicious actor with network access may be able to perform HTTP smuggle requests.
0
Attacker Value
Unknown
CVE-2021-21988
Disclosure Date: May 24, 2021 (last updated November 28, 2024)
VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (JPEG2000 Parser). A malicious actor with access to a virtual machine or remote desktop may be able to exploit these issues leading to information disclosure from the TPView process running on the system where Workstation or Horizon Client for Windows is installed.
0
Attacker Value
Unknown
CVE-2021-21987
Disclosure Date: May 24, 2021 (last updated November 28, 2024)
VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (TTC Parser). A malicious actor with access to a virtual machine or remote desktop may be able to exploit these issues leading to information disclosure from the TPView process running on the system where Workstation or Horizon Client for Windows is installed.
0
Attacker Value
Unknown
CVE-2021-21989
Disclosure Date: May 24, 2021 (last updated November 28, 2024)
VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (TTC Parser). A malicious actor with access to a virtual machine or remote desktop may be able to exploit these issues leading to information disclosure from the TPView process running on the system where Workstation or Horizon Client for Windows is installed.
0
Attacker Value
Unknown
CVE-2020-3998
Disclosure Date: October 23, 2020 (last updated November 28, 2024)
VMware Horizon Client for Windows (5.x prior to 5.5.0) contains an information disclosure vulnerability. A malicious attacker with local privileges on the machine where Horizon Client for Windows is installed may be able to retrieve hashed credentials if the client crashes.
0
Attacker Value
Unknown
CVE-2020-3991
Disclosure Date: October 16, 2020 (last updated November 28, 2024)
VMware Horizon Client for Windows (5.x before 5.5.0) contains a denial-of-service vulnerability due to a file system access control issue during install time. Successful exploitation of this issue may allow an attacker to overwrite certain admin privileged files through a symbolic link attack at install time. This will result into a denial-of-service condition on the machine where Horizon Client for Windows is installed.
0