<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – VMware ESXi (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/esxi.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/esxi-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – VMware ESXi (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:48 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-62627 – An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62627</guid>
    <pubDate>Wed, 13 May 2026 04:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62627</strong></p>
  <p>An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged VM to read kernel memory or co-located guest VM memory, potentially resulting in loss of confidentiality or availability.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-822</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62624 – A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62624</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62624</guid>
    <pubDate>Wed, 13 May 2026 04:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62624</strong></p>
  <p>A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62624">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62623 – A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62623</guid>
    <pubDate>Wed, 13 May 2026 04:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62623</strong></p>
  <p>A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20879 – Out-of-bounds write for the Intel(R) Data Center Graphics Driver for VMware ESXi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20879</guid>
    <pubDate>Tue, 12 May 2026 17:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20879</strong></p>
  <p>Out-of-bounds write for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data corruption. This result may potentially occur via local access when attack requirements are not present without special inte…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-20794 – Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi sof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20794</guid>
    <pubDate>Tue, 12 May 2026 17:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-20794</strong></p>
  <p>Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable local code execution. This result may potentially occur via local access when attack requirements are not present without spec…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20751 – Out-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20751</guid>
    <pubDate>Tue, 12 May 2026 17:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20751</strong></p>
  <p>Out-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are not present without special interna…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41246 – VMware Tools for Windows contains an improper authorisation vulnerability due to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41246</guid>
    <pubDate>Mon, 29 Sep 2025 16:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41246</strong></p>
  <p>VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access other guest VMs. Successful exploitation requires knowledge of credentials of the targeted VMs and vCenter or ESX.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41239 – VMware ESXi, Workstation, Fusion, and VMware Tools contains an information discl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41239</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41239</guid>
    <pubDate>Tue, 15 Jul 2025 19:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41239</strong></p>
  <p>VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to leak memory from processes communicating with vSockets.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41239">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41238 – VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41238</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41238</guid>
    <pubDate>Tue, 15 Jul 2025 19:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41238</strong></p>
  <p>VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox and…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41238">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41237 – VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41237</guid>
    <pubDate>Tue, 15 Jul 2025 19:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41237</strong></p>
  <p>VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, o…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41236 – VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41236</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41236</guid>
    <pubDate>Tue, 15 Jul 2025 19:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41236</strong></p>
  <p>VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41236">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27147 – The GLPI Inventory Plugin handles various types of tasks for GLPI agents, includ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27147</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27147</guid>
    <pubDate>Tue, 25 Mar 2025 15:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27147</strong></p>
  <p>The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNMP), software deployment, VMWare ESX host remote inventory, and data collection (files, Windows registry, WMI). Versions prior to 1.5.0 have an improper access control vulnerability. Version 1.5.0 fixes the vulnerability.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27147">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-22226 – VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22226</guid>
    <pubDate>Tue, 04 Mar 2025 12:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-22226</strong></p>
  <p>VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-22225 – VMware ESXi contains an arbitrary write vulnerability. A malicious actor with pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22225</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22225</guid>
    <pubDate>Tue, 04 Mar 2025 12:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-22225</strong></p>
  <p>VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22225">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-22224 – VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22224</guid>
    <pubDate>Tue, 04 Mar 2025 12:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-22224</strong></p>
  <p>VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22273 – The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-boun...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22273</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22273</guid>
    <pubDate>Tue, 21 May 2024 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22273</strong></p>
  <p>The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or execute code on the hypervisor from a virtual machine in conjunction with other issues.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22273">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22255 – VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22255</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22255</guid>
    <pubDate>Tue, 05 Mar 2024 18:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22255</strong></p>
  <p>VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22255">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22254 – VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor wit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22254</guid>
    <pubDate>Tue, 05 Mar 2024 18:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22254</strong></p>
  <p>VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox.</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-22253 – VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22253</guid>
    <pubDate>Tue, 05 Mar 2024 18:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-22253</strong></p>
  <p>VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code ex…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-22252 – VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22252</guid>
    <pubDate>Tue, 05 Mar 2024 18:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-22252</strong></p>
  <p>VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code ex…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-36628 – A flaw exists in VASA which allows users with access to a vSphere/ESXi VMware ad...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36628</guid>
    <pubDate>Tue, 03 Oct 2023 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-36628</strong></p>
  <p>A flaw exists in VASA which allows users with access to a vSphere/ESXi VMware admin on a FlashArray to gain root access through privilege escalation.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31705 – VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31705</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31705</guid>
    <pubDate>Wed, 14 Dec 2022 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31705</strong></p>
  <p>VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31705">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31696 – VMware ESXi contains a memory corruption vulnerability that exists in the way it...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31696</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31696</guid>
    <pubDate>Tue, 13 Dec 2022 16:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31696</strong></p>
  <p>VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31696">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22050 – ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22050</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22050</guid>
    <pubDate>Wed, 16 Feb 2022 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22050</strong></p>
  <p>ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to create a denial-of-service condition by overwhelming rhttpproxy service with multiple requests.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22050">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22043 – VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22043</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22043</guid>
    <pubDate>Wed, 16 Feb 2022 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22043</strong></p>
  <p>VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled. A malicious actor with access to settingsd, may exploit this issue to escalate their privileges by writing arbitrary files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22043">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22042 – VMware ESXi contains an unauthorized access vulnerability due to VMX having acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22042</guid>
    <pubDate>Wed, 16 Feb 2022 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22042</strong></p>
  <p>VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privileges within the VMX process only, may be able to access settingsd service running as a high privileged user.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22045 – VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-2021101...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22045</guid>
    <pubDate>Tue, 04 Jan 2022 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22045</strong></p>
  <p>VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A malicious actor with access to a virtual machine with CD-ROM device emulation may be able to exploit this vulnerability in conjunction with other issues to execute code on the hypervisor…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3960 – VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3960</guid>
    <pubDate>Wed, 15 Sep 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3960</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in NVMe functionality. A malicious actor with local non-administrative access to a virtual machine with a virtual NVMe controller present may be able to read privileged information contained in physical mem…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21995 – OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21995</guid>
    <pubDate>Tue, 13 Jul 2021 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21995</strong></p>
  <p>OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-bounds read issue. A malicious actor with network access to port 427 on ESXi may be able to trigger a heap out-of-bounds read in OpenSLP service resulting in a denial-of-service condition.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21994 – SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21994</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21994</guid>
    <pubDate>Tue, 13 Jul 2021 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21994</strong></p>
  <p>SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21994">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21974 – OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-20210...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21974</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21974</guid>
    <pubDate>Wed, 24 Feb 2021 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21974</strong></p>
  <p>OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21974">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-14483 – AdRem NetCrunch 10.6.0.4587 allows Credentials Disclosure. Every user can read t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14483</guid>
    <pubDate>Wed, 16 Dec 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-14483</strong></p>
  <p>AdRem NetCrunch 10.6.0.4587 allows Credentials Disclosure. Every user can read the BSD, Linux, MacOS and Solaris private keys, private keys' passwords, and root passwords stored in the credential manager. Every administrator can read the ESX and Windows passwords stored in the credential manager.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4005 – VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4005</guid>
    <pubDate>Fri, 20 Nov 2020 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4005</strong></p>
  <p>VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG) contains a privilege-escalation vulnerability that exists in the way certain system calls are being managed. A malicious actor with privileges within the VMX process only, may escalate their privileges on the affected system. Successful exploitation of this issue is only possible when cha…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4004 – VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4004</guid>
    <pubDate>Fri, 20 Nov 2020 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4004</strong></p>
  <p>VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x before 15.5.7), Fusion (11.x before 11.5.7) contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-3992 – OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3992</guid>
    <pubDate>Tue, 20 Oct 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-3992</strong></p>
  <p>OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3982 – VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3982</guid>
    <pubDate>Tue, 20 Oct 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3982</strong></p>
  <p>VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds write vulnerability due to a time-of-check time-of-use issue in ACPI device. A malicious actor with administrative access to a virtual machine may be able to exploit this vulnerability to crash the virtual mach…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3968 – VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3968</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3968</guid>
    <pubDate>Thu, 25 Jun 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3968</strong></p>
  <p>VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds write vulnerability in the USB 3.0 controller (xHCI). A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to crash the virtual mac…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3968">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3967 – VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3967</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3967</guid>
    <pubDate>Thu, 25 Jun 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3967</strong></p>
  <p>VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain a heap-overflow vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local access to a virtual machine may be able to exploit this vulnerability to execute code on the hypervisor from a v…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3967">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3966 – VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3966</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3966</guid>
    <pubDate>Thu, 25 Jun 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3966</strong></p>
  <p>VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a heap-overflow due to a race condition issue in the USB 2.0 controller (EHCI). A malicious actor with local access to a virtual machine may be able to exploit this vulnerability to execute code on the hyp…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3966">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3962 – VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3962</guid>
    <pubDate>Wed, 24 Jun 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3962</strong></p>
  <p>VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain a use-after-free vulnerability in the SVGA device. A malicious actor with local access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to execute code on the hypervi…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3969 – VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3969</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3969</guid>
    <pubDate>Wed, 24 Jun 2020 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3969</strong></p>
  <p>VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an off-by-one heap-overflow vulnerability in the SVGA device. A malicious actor with local access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to execute code on…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-193</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3969">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-3955 – ESXi 6.5 without patch ESXi650-201912104-SG and ESXi 6.7 without patch ESXi670-2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3955</guid>
    <pubDate>Wed, 29 Apr 2020 03:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-3955</strong></p>
  <p>ESXi 6.5 without patch ESXi650-201912104-SG and ESXi 6.7 without patch ESXi670-202004103-SG do not properly neutralize script-related HTML when viewing virtual machines attributes. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.3.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3955">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5544 – OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite iss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5544</guid>
    <pubDate>Fri, 06 Dec 2019 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5544</strong></p>
  <p>OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5527 – ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5527</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5527</guid>
    <pubDate>Thu, 10 Oct 2019 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5527</strong></p>
  <p>ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.5.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5527">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5521 – VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5521</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5521</guid>
    <pubDate>Fri, 20 Sep 2019 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5521</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6) and Fusion (11.x before 11.0.3 and 10.x before 10.1.6) contain an out-of-bounds read vulnerability in the pixel shader functionality. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to cr…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5521">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6981 – VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6981</guid>
    <pubDate>Tue, 04 Dec 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6981</strong></p>
  <p>VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMware ESXi 6.0 without ESXi600-201811401-BG, VMware Workstation 15, VMware Workstation 14.1.3 or below, VMware Fusion 11, VMware Fusion 10.1.3 or below contain uninitialized stack memory usage in the vmxnet3 virtual network adapter which may allow a guest to execute code on the host.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6974 – VMware ESXi (6.7 before ESXi670-201810101-SG, 6.5 before ESXi650-201808401-BG, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6974</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6974</guid>
    <pubDate>Tue, 16 Oct 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6974</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-201810101-SG, 6.5 before ESXi650-201808401-BG, and 6.0 before ESXi600-201808401-BG), Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds read vulnerability in SVGA device. This issue may allow a guest to execute code on the host.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6974">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6967 – VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2),...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6967</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6967</guid>
    <pubDate>Mon, 09 Jul 2018 20:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6967</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash their VMs, a different vulnerability than CVE-2018-6965 and CVE-2018-6966.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6967">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6966 – VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2),...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6966</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6966</guid>
    <pubDate>Mon, 09 Jul 2018 20:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6966</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash their VMs, a different vulnerability than CVE-2018-6965 and CVE-2018-6967.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6966">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6965 – VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2),...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6965</guid>
    <pubDate>Mon, 09 Jul 2018 20:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6965</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash their VMs, a different vulnerability than CVE-2018-6966 and CVE-2018-6967.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4941 – VMware ESXi (6.0 before ESXi600-201711101-SG, 5.5 ESXi550-201709101-SG), Worksta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4941</guid>
    <pubDate>Wed, 20 Dec 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4941</strong></p>
  <p>VMware ESXi (6.0 before ESXi600-201711101-SG, 5.5 ESXi550-201709101-SG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could allow an authenticated VNC session to cause a stack overflow via a specific set of VNC packets. Successful exploitation of this issue could result in remote code execution in a virtual machine via the authenticated VNC session.…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4933 – VMware ESXi (6.5 before ESXi650-201710401-BG), Workstation (12.x before 12.5.8),...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4933</guid>
    <pubDate>Wed, 20 Dec 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4933</strong></p>
  <p>VMware ESXi (6.5 before ESXi650-201710401-BG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could allow an authenticated VNC session to cause a heap overflow via a specific set of VNC packets resulting in heap corruption. Successful exploitation of this issue could result in remote code execution in a virtual machine via the authenticated VNC sessio…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4924 – VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4924</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4924</guid>
    <pubDate>Fri, 15 Sep 2017 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4924</strong></p>
  <p>VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusion (8.x before 8.5.8) contain an out-of-bounds write vulnerability in SVGA device. This issue may allow a guest to execute code on the host.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4924">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4904 – The XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4904</guid>
    <pubDate>Wed, 07 Jun 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4904</strong></p>
  <p>The XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 has uninitialized memory usage. This issue may allow a guest…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4903 – VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4903</guid>
    <pubDate>Wed, 07 Jun 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4903</strong></p>
  <p>VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have an uninitialized stack memory usage in SVGA. This issue may allow a guest to ex…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4902 – VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4902</guid>
    <pubDate>Wed, 07 Jun 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4902</strong></p>
  <p>VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have a Heap Buffer Overflow in SVGA. This issue may allow a guest to execute code on the host.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-5330 – Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5330</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5330</guid>
    <pubDate>Mon, 08 Aug 2016 01:59:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-5330</strong></p>
  <p>Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware Workstation Pro 12.1.x before 12.1.1, VMware Workstation Player 12.1.x before 12.1.1, and VMware Fusion 8.1.x before 8.1.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5330">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-3519 – lgtosync.sys in VMware Workstation 9.x before 9.0.3, VMware Player 5.x before 5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-3519</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-3519</guid>
    <pubDate>Wed, 04 Dec 2013 18:56:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-3519</strong></p>
  <p>lgtosync.sys in VMware Workstation 9.x before 9.0.3, VMware Player 5.x before 5.0.3, VMware Fusion 5.x before 5.0.4, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1, when a 32-bit Windows guest OS is used, allows guest OS users to gain guest OS privileges via an application that performs a crafted memory allocation.</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-3519">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-5970 – hostd-vmdb in VMware ESXi 4.0 through 5.0 and ESX 4.0 through 4.1 allows remote ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-5970</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-5970</guid>
    <pubDate>Mon, 21 Oct 2013 10:54:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-5970</strong></p>
  <p>hostd-vmdb in VMware ESXi 4.0 through 5.0 and ESX 4.0 through 4.1 allows remote attackers to cause a denial of service (hostd-vmdb service outage) by modifying management traffic.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-5970">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-3658 – Directory traversal vulnerability in VMware ESXi 4.0 through 5.0, and ESX 4.0 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-3658</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-3658</guid>
    <pubDate>Tue, 10 Sep 2013 11:28:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-3658</strong></p>
  <p>Directory traversal vulnerability in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to delete arbitrary host OS files via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-3658">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-3657 – Buffer overflow in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-3657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-3657</guid>
    <pubDate>Tue, 10 Sep 2013 11:28:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-3657</strong></p>
  <p>Buffer overflow in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-3657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-1659 – VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1659</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1659</guid>
    <pubDate>Fri, 22 Feb 2013 20:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-1659</strong></p>
  <p>VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 do not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption) by modifying the client-server data stream.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1659">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-1405 – VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware Virt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1405</guid>
    <pubDate>Fri, 15 Feb 2013 12:09:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-1405</strong></p>
  <p>VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update 3a, VMware VI-Client 2.5, VMware ESXi 3.5 through 4.1, and VMware ESX 3.5 through 4.1 do not properly implement the management authentication protocol, which allow remote servers to execute arbitrary code or cause a denial of service (memo…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-1406 – The Virtual Machine Communication Interface (VMCI) implementation in vmci.sys in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1406</guid>
    <pubDate>Mon, 11 Feb 2013 22:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-1406</strong></p>
  <p>The Virtual Machine Communication Interface (VMCI) implementation in vmci.sys in VMware Workstation 8.x before 8.0.5 and 9.x before 9.0.1 on Windows, VMware Fusion 4.1 before 4.1.4 and 5.0 before 5.0.2, VMware View 4.x before 4.6.2 and 5.x before 5.1.2 on Windows, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1 does not properly restrict memory allocation by control code, which allows loc…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-3289 – VMware Workstation 8.x before 8.0.4, VMware Player 4.x before 4.0.4, VMware ESXi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-3289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-3289</guid>
    <pubDate>Thu, 14 Jun 2012 20:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-3289</strong></p>
  <p>VMware Workstation 8.x before 8.0.4, VMware Player 4.x before 4.0.4, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 allow remote attackers to cause a denial of service (guest OS crash) via crafted traffic from a remote virtual device.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-3289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-3288 – VMware Workstation 7.x before 7.1.6 and 8.x before 8.0.4, VMware Player 3.x befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-3288</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-3288</guid>
    <pubDate>Thu, 14 Jun 2012 20:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-3288</strong></p>
  <p>VMware Workstation 7.x before 7.1.6 and 8.x before 8.0.4, VMware Player 3.x before 3.1.6 and 4.x before 4.0.4, VMware Fusion 4.x before 4.1.3, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 allow user-assisted remote attackers to execute arbitrary code on the host OS or cause a denial of service (memory corruption) on the host OS via a crafted Checkpoint file.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-3288">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-2450 – VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-2450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-2450</guid>
    <pubDate>Fri, 04 May 2012 16:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-2450</strong></p>
  <p>VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 do not properly register SCSI devices, which allows guest OS users to cause a denial of service (invalid write operation and VMX process crash) or possibly execute arbitrary code on the host OS by leveraging administrative privileges on t…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-2449 – VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-2449</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-2449</guid>
    <pubDate>Fri, 04 May 2012 16:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-2449</strong></p>
  <p>VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x through 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 do not properly configure the virtual floppy device, which allows guest OS users to cause a denial of service (out-of-bounds write operation and VMX process crash) or possibly execute arbitrary code on the host OS by leveraging administr…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2449">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-2448 – VMware ESXi 3.5 through 5.0 and ESX 3.5 through 4.1 allow remote attackers to ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-2448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-2448</guid>
    <pubDate>Fri, 04 May 2012 16:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-2448</strong></p>
  <p>VMware ESXi 3.5 through 5.0 and ESX 3.5 through 4.1 allow remote attackers to execute arbitrary code or cause a denial of service (memory overwrite) via NFS traffic.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-1517 – The VMX process in VMware ESXi 4.1 and ESX 4.1 does not properly handle RPC comm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-1517</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-1517</guid>
    <pubDate>Fri, 04 May 2012 16:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-1517</strong></p>
  <p>The VMX process in VMware ESXi 4.1 and ESX 4.1 does not properly handle RPC commands, which allows guest OS users to cause a denial of service (memory overwrite and process crash) or possibly execute arbitrary code on the host OS via vectors involving function pointers.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-1517">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-1516 – The VMX process in VMware ESXi 3.5 through 4.1 and ESX 3.5 through 4.1 does not ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-1516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-1516</guid>
    <pubDate>Fri, 04 May 2012 16:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-1516</strong></p>
  <p>The VMX process in VMware ESXi 3.5 through 4.1 and ESX 3.5 through 4.1 does not properly handle RPC commands, which allows guest OS users to cause a denial of service (memory overwrite and process crash) or possibly execute arbitrary code on the host OS via vectors involving data pointers.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-1516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-1518 – VMware Workstation 8.x before 8.0.2, VMware Player 4.x before 4.0.2, VMware Fusi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-1518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-1518</guid>
    <pubDate>Tue, 17 Apr 2012 21:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-1518</strong></p>
  <p>VMware Workstation 8.x before 8.0.2, VMware Player 4.x before 4.0.2, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 use an incorrect ACL for the VMware Tools folder, which allows guest OS users to gain guest OS privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-1518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-1515 – VMware ESXi 3.5, 4.0, and 4.1 and ESX 3.5, 4.0, and 4.1 do not properly implemen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-1515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-1515</guid>
    <pubDate>Mon, 02 Apr 2012 10:46:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-1515</strong></p>
  <p>VMware ESXi 3.5, 4.0, and 4.1 and ESX 3.5, 4.0, and 4.1 do not properly implement port-based I/O operations, which allows guest OS users to gain guest OS privileges by overwriting memory locations in a read-only memory block associated with the Virtual DOS Machine.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-1515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-1510 – Buffer overflow in the WDDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMw...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-1510</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-1510</guid>
    <pubDate>Fri, 16 Mar 2012 20:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-1510</strong></p>
  <p>Buffer overflow in the WDDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-1510">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-1508 – The XPDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-1508</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-1508</guid>
    <pubDate>Fri, 16 Mar 2012 20:55:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-1508</strong></p>
  <p>The XPDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-1508">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-1785 – VMware ESXi 4.0 and 4.1 and ESX 4.0 and 4.1 allow remote attackers to cause a de...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-1785</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-1785</guid>
    <pubDate>Tue, 03 May 2011 22:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-1785</strong></p>
  <p>VMware ESXi 4.0 and 4.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (socket exhaustion) via unspecified network traffic.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-1785">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-0355 – Cisco Nexus 1000V Virtual Ethernet Module (VEM) 4.0(4) SV1(1) through SV1(3b), a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-0355</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-0355</guid>
    <pubDate>Thu, 17 Feb 2011 18:00:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-0355</strong></p>
  <p>Cisco Nexus 1000V Virtual Ethernet Module (VEM) 4.0(4) SV1(1) through SV1(3b), as used in VMware ESX 4.0 and 4.1 and ESXi 4.0 and 4.1, does not properly handle dropped packets, which allows guest OS users to cause a denial of service (ESX or ESXi host OS crash) by sending an 802.1Q tagged packet over an access vEthernet port, aka Cisco Bug ID CSCtj17451.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-0355">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-4573 – The Update Installer in VMware ESXi 4.1, when a modified sfcb.cfg is present, do...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-4573</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-4573</guid>
    <pubDate>Wed, 22 Dec 2010 21:00:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-4573</strong></p>
  <p>The Update Installer in VMware ESXi 4.1, when a modified sfcb.cfg is present, does not properly configure the SFCB authentication mode, which allows remote attackers to obtain access via an arbitrary username and password.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-4573">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-4297 – The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-4297</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-4297</guid>
    <pubDate>Mon, 06 Dec 2010 21:05:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-4297</strong></p>
  <p>The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548; VMware Player 2.5.x before 2.5.5 build 328052 and 3.1.x before 3.1.2 build 301548; VMware Server 2.0.2; VMware Fusion 2.x before 2.0.8 build 328035 and 3.1.x before 3.1.2 build 332101; VMware ESXi 3.5, 4.0, and 4.1; and VMware ESX 3.0.3, 3.5, 4.0, and 4.1 allows host OS u…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-4297">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-1142 – VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Playe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1142</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1142</guid>
    <pubDate>Mon, 12 Apr 2010 18:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-1142</strong></p>
  <p>VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 203138; VMware Fusion 2.x before 2.0.6 build 246742; VMware ESXi 3.5 and 4.0; and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0 does not properly load VMware programs, which might allow Windows guest OS users to…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1142">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-1141 – VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Playe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1141</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1141</guid>
    <pubDate>Mon, 12 Apr 2010 18:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-1141</strong></p>
  <p>VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 203138; VMware Fusion 2.x before 2.0.6 build 246742; VMware ESXi 3.5 and 4.0; and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0 does not properly access libraries, which allows user-assisted remote attackers to…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1141">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-0686 – WebAccess in VMware VirtualCenter 2.0.2 and 2.5, VMware Server 2.0, and VMware E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-0686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-0686</guid>
    <pubDate>Thu, 01 Apr 2010 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-0686</strong></p>
  <p>WebAccess in VMware VirtualCenter 2.0.2 and 2.5, VMware Server 2.0, and VMware ESX 3.0.3 and 3.5 allows remote attackers to leverage proxy-server functionality to spoof the origin of requests via unspecified vectors, related to a "URL forwarding vulnerability."</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-0686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-4917 – Unspecified vulnerability in VMware Workstation 5.5.8 and earlier, and 6.0.5 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-4917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-4917</guid>
    <pubDate>Tue, 09 Dec 2008 00:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-4917</strong></p>
  <p>Unspecified vulnerability in VMware Workstation 5.5.8 and earlier, and 6.0.5 and earlier 6.x versions; VMware Player 1.0.8 and earlier, and 2.0.5 and earlier 2.x versions; VMware Server 1.0.9 and earlier; VMware ESXi 3.5; and VMware ESX 3.0.2 through 3.5 allows guest OS users to have an unknown impact by sending the virtual hardware a request that triggers an arbitrary physical-memory write opera…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-4917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-4281 – Directory traversal vulnerability in VMWare ESXi 3.5 before ESXe350-200810401-O-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-4281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-4281</guid>
    <pubDate>Mon, 10 Nov 2008 14:12:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-4281</strong></p>
  <p>Directory traversal vulnerability in VMWare ESXi 3.5 before ESXe350-200810401-O-UG and ESX 3.5 before ESX350-200810201-UG allows administrators with the Datastore.FileManagement privilege to gain privileges via unknown vectors.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-4281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-2097 – Buffer overflow in the openwsman management service in VMware ESXi 3.5 and ESX 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-2097</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-2097</guid>
    <pubDate>Thu, 05 Jun 2008 20:32:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-2097</strong></p>
  <p>Buffer overflow in the openwsman management service in VMware ESXi 3.5 and ESX 3.5 allows remote authenticated users to gain privileges via an "invalid Content-Length."</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-2097">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-2100 – Multiple buffer overflows in VIX API 1.1.x before 1.1.4 build 93057 on VMware Wo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-2100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-2100</guid>
    <pubDate>Thu, 05 Jun 2008 20:32:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-2100</strong></p>
  <p>Multiple buffer overflows in VIX API 1.1.x before 1.1.4 build 93057 on VMware Workstation 5.x and 6.x, VMware Player 1.x and 2.x, VMware ACE 2.x, VMware Server 1.x, VMware Fusion 1.x, VMware ESXi 3.5, and VMware ESX 3.0.1 through 3.5 allow guest OS users to execute arbitrary code on the host OS via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-2100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-5360 – Buffer overflow in OpenPegasus Management server, when compiled to use PAM and w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-5360</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-5360</guid>
    <pubDate>Tue, 08 Jan 2008 20:46:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-5360</strong></p>
  <p>Buffer overflow in OpenPegasus Management server, when compiled to use PAM and with PEGASUS_USE_PAM_STANDALONE_PROC defined, as used in VMWare ESX Server 3.0.1 and 3.0.2, might allow remote attackers to execute arbitrary code via vectors related to PAM authentication, a different vulnerability than CVE-2008-0003.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-5360">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-3618 – Cross-site request forgery (CSRF) vulnerability in the management interface for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-3618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-3618</guid>
    <pubDate>Sat, 31 Dec 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-3618</strong></p>
  <p>Cross-site request forgery (CSRF) vulnerability in the management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch 1, and 2.x before 2.5.3 patch 2 allows allows remote attackers to perform unauthorized actions as the administrator via URLs, as demonstrated using the setUsr operation to change a password.  NOTE: this issue can be leveraged with CVE-2005-3619 to…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-3618">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2003-1291 – VMware ESX Server 1.5.2 before Patch 4 allows local users to execute arbitrary p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2003-1291</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2003-1291</guid>
    <pubDate>Wed, 31 Dec 2003 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2003-1291</strong></p>
  <p>VMware ESX Server 1.5.2 before Patch 4 allows local users to execute arbitrary programs as root via certain modified VMware ESX Server environment variables.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2003-1291">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
