<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – VMware ESXi</title>
  <link>https://cvedaily.com/pages/tags/esxi.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/esxi.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – VMware ESXi</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:48 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-62627 – An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62627</guid>
    <pubDate>Wed, 13 May 2026 04:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62627</strong></p>
  <p>An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged VM to read kernel memory or co-located guest VM memory, potentially resulting in loss of confidentiality or availability.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-822</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62624 – A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62624</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62624</guid>
    <pubDate>Wed, 13 May 2026 04:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62624</strong></p>
  <p>A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62624">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62623 – A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62623</guid>
    <pubDate>Wed, 13 May 2026 04:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62623</strong></p>
  <p>A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20879 – Out-of-bounds write for the Intel(R) Data Center Graphics Driver for VMware ESXi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20879</guid>
    <pubDate>Tue, 12 May 2026 17:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20879</strong></p>
  <p>Out-of-bounds write for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data corruption. This result may potentially occur via local access when attack requirements are not present without special inte…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-20794 – Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi sof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20794</guid>
    <pubDate>Tue, 12 May 2026 17:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-20794</strong></p>
  <p>Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable local code execution. This result may potentially occur via local access when attack requirements are not present without spec…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20751 – Out-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20751</guid>
    <pubDate>Tue, 12 May 2026 17:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20751</strong></p>
  <p>Out-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are not present without special interna…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-25058 – Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethern...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25058</guid>
    <pubDate>Tue, 10 Feb 2026 17:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-25058</strong></p>
  <p>Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethernet 800-Series before version 2.2.2.0 (esxi 8.0) &amp; 2.2.3.0 (esxi 9.0) within Ring 1: Device Drivers may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-665</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2025-40104 – In the Linux kernel, the following vulnerability has been resolved:

ixgbevf: fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40104</guid>
    <pubDate>Thu, 30 Oct 2025 10:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2025-40104</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ixgbevf: fix mailbox API compatibility by negotiating supported features  There was backward compatibility in the terms of mailbox API. Various drivers from various OSes supporting 10G adapters from Intel portfolio could easily negotiate mailbox API.  This convention has been broken since introducing API 1.4. Commit 0062e7cc955e…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41246 – VMware Tools for Windows contains an improper authorisation vulnerability due to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41246</guid>
    <pubDate>Mon, 29 Sep 2025 16:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41246</strong></p>
  <p>VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access other guest VMs. Successful exploitation requires knowledge of credentials of the targeted VMs and vCenter or ESX.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41239 – VMware ESXi, Workstation, Fusion, and VMware Tools contains an information discl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41239</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41239</guid>
    <pubDate>Tue, 15 Jul 2025 19:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41239</strong></p>
  <p>VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to leak memory from processes communicating with vSockets.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41239">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41238 – VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41238</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41238</guid>
    <pubDate>Tue, 15 Jul 2025 19:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41238</strong></p>
  <p>VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox and…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41238">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41237 – VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41237</guid>
    <pubDate>Tue, 15 Jul 2025 19:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41237</strong></p>
  <p>VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, o…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41236 – VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41236</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41236</guid>
    <pubDate>Tue, 15 Jul 2025 19:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41236</strong></p>
  <p>VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41236">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20112 – A vulnerability in multiple Cisco Unified Communications and Contact Center Solu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20112</guid>
    <pubDate>Wed, 21 May 2025 17:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20112</strong></p>
  <p>A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate privileges to root on an affected device.  This vulnerability is due to excessive permissions that have been assigned to system commands.&nbsp;An attacker could exploit this vulnerability by executing crafted commands on the underlying operating…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-268</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-41228 – VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41228</guid>
    <pubDate>Tue, 20 May 2025 15:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-41228</strong></p>
  <p>VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-41227 – VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41227</guid>
    <pubDate>Tue, 20 May 2025 15:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-41227</strong></p>
  <p>VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest options. A malicious actor with non-administrative privileges within a guest operating system may be able to exploit this issue by exhausting memory of the host process leading to a denial-of-service condition.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-41226 – VMware ESXi contains a denial-of-service vulnerability that occurs when performi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41226</guid>
    <pubDate>Tue, 20 May 2025 15:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-41226</strong></p>
  <p>VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or ESXi may trigger this issue to create a denial-of-service condition of guest VMs with VMware Tools running and guest operations enabled.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27147 – The GLPI Inventory Plugin handles various types of tasks for GLPI agents, includ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27147</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27147</guid>
    <pubDate>Tue, 25 Mar 2025 15:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27147</strong></p>
  <p>The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNMP), software deployment, VMWare ESX host remote inventory, and data collection (files, Windows registry, WMI). Versions prior to 1.5.0 have an improper access control vulnerability. Version 1.5.0 fixes the vulnerability.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27147">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-22226 – VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22226</guid>
    <pubDate>Tue, 04 Mar 2025 12:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-22226</strong></p>
  <p>VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-22225 – VMware ESXi contains an arbitrary write vulnerability. A malicious actor with pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22225</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22225</guid>
    <pubDate>Tue, 04 Mar 2025 12:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-22225</strong></p>
  <p>VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22225">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-22224 – VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22224</guid>
    <pubDate>Tue, 04 Mar 2025 12:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-22224</strong></p>
  <p>VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-37086 – VMware ESXi contains an out-of-bounds read vulnerability. A
 malicious actor wit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37086</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37086</guid>
    <pubDate>Tue, 25 Jun 2024 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-37086</strong></p>
  <p>VMware ESXi contains an out-of-bounds read vulnerability. A  malicious actor with local administrative privileges on a virtual  machine with an existing snapshot may trigger an out-of-bounds read  leading to a denial-of-service condition of the host.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37086">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-37085 – VMware ESXi contains an authentication bypass vulnerability. A malicious actor w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37085</guid>
    <pubDate>Tue, 25 Jun 2024 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-37085</strong></p>
  <p>VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously  configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html  by re-creating the configured AD group ('ESXi Admins' by default) after it was del…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22273 – The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-boun...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22273</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22273</guid>
    <pubDate>Tue, 21 May 2024 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22273</strong></p>
  <p>The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or execute code on the hypervisor from a virtual machine in conjunction with other issues.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22273">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22255 – VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22255</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22255</guid>
    <pubDate>Tue, 05 Mar 2024 18:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22255</strong></p>
  <p>VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22255">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22254 – VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor wit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22254</guid>
    <pubDate>Tue, 05 Mar 2024 18:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22254</strong></p>
  <p>VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox.</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-22253 – VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22253</guid>
    <pubDate>Tue, 05 Mar 2024 18:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-22253</strong></p>
  <p>VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code ex…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-22252 – VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22252</guid>
    <pubDate>Tue, 05 Mar 2024 18:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-22252</strong></p>
  <p>VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code ex…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-36628 – A flaw exists in VASA which allows users with access to a vSphere/ESXi VMware ad...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36628</guid>
    <pubDate>Tue, 03 Oct 2023 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-36628</strong></p>
  <p>A flaw exists in VASA which allows users with access to a vSphere/ESXi VMware admin on a FlashArray to gain root access through privilege escalation.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-20867 – A fully compromised ESXi host can force VMware Tools to fail to authenticate hos...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20867</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20867</guid>
    <pubDate>Tue, 13 Jun 2023 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-20867</strong></p>
  <p>A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.</p>
  <p><strong>CVSS:</strong> 3.9 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20867">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31705 – VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31705</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31705</guid>
    <pubDate>Wed, 14 Dec 2022 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31705</strong></p>
  <p>VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31705">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2022-31699 – VMware ESXi contains a heap-overflow vulnerability. A malicious local actor with...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31699</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31699</guid>
    <pubDate>Tue, 13 Dec 2022 16:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2022-31699</strong></p>
  <p>VMware ESXi contains a heap-overflow vulnerability. A malicious local actor with restricted privileges within a sandbox process may exploit this issue to achieve a partial information disclosure.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31699">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31696 – VMware ESXi contains a memory corruption vulnerability that exists in the way it...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31696</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31696</guid>
    <pubDate>Tue, 13 Dec 2022 16:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31696</strong></p>
  <p>VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31696">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31681 – VMware ESXi contains a null-pointer deference vulnerability. A malicious actor w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31681</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31681</guid>
    <pubDate>Fri, 07 Oct 2022 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31681</strong></p>
  <p>VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process only, may create a denial of service condition on the host.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31681">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22050 – ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22050</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22050</guid>
    <pubDate>Wed, 16 Feb 2022 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22050</strong></p>
  <p>ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to create a denial-of-service condition by overwhelming rhttpproxy service with multiple requests.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22050">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22043 – VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22043</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22043</guid>
    <pubDate>Wed, 16 Feb 2022 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22043</strong></p>
  <p>VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled. A malicious actor with access to settingsd, may exploit this issue to escalate their privileges by writing arbitrary files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22043">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22042 – VMware ESXi contains an unauthorized access vulnerability due to VMX having acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22042</guid>
    <pubDate>Wed, 16 Feb 2022 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22042</strong></p>
  <p>VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privileges within the VMX process only, may be able to access settingsd service running as a high privileged user.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-22041 – VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22041</guid>
    <pubDate>Wed, 16 Feb 2022 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-22041</strong></p>
  <p>VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-22040 – VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22040</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22040</guid>
    <pubDate>Wed, 16 Feb 2022 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-22040</strong></p>
  <p>VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22040">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22045 – VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-2021101...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22045</guid>
    <pubDate>Tue, 04 Jan 2022 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22045</strong></p>
  <p>VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A malicious actor with access to a virtual machine with CD-ROM device emulation may be able to exploit this vulnerability in conjunction with other issues to execute code on the hypervisor…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3960 – VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3960</guid>
    <pubDate>Wed, 15 Sep 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3960</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in NVMe functionality. A malicious actor with local non-administrative access to a virtual machine with a virtual NVMe controller present may be able to read privileged information contained in physical mem…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21995 – OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21995</guid>
    <pubDate>Tue, 13 Jul 2021 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21995</strong></p>
  <p>OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-bounds read issue. A malicious actor with network access to port 427 on ESXi may be able to trigger a heap out-of-bounds read in OpenSLP service resulting in a denial-of-service condition.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21994 – SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21994</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21994</guid>
    <pubDate>Tue, 13 Jul 2021 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21994</strong></p>
  <p>SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21994">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-28972 – In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28972</guid>
    <pubDate>Sat, 27 Feb 2021 05:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-28972</strong></p>
  <p>In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and esxi servers (in the vmware.py files) does not always validate the SSL/TLS certificate.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21974 – OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-20210...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21974</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21974</guid>
    <pubDate>Wed, 24 Feb 2021 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21974</strong></p>
  <p>OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21974">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-3999 – VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3999</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3999</guid>
    <pubDate>Mon, 21 Dec 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-3999</strong></p>
  <p>VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12.x prior to 12.0 and 11.x prior to 11.5.7) and VMware Cloud Foundation contain a denial of service vulnerability due to improper input validation in GuestInfo. A malicious actor with normal user privilege access to a virtual machine can crash the virtual machine's vmx…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3999">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-14483 – AdRem NetCrunch 10.6.0.4587 allows Credentials Disclosure. Every user can read t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14483</guid>
    <pubDate>Wed, 16 Dec 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-14483</strong></p>
  <p>AdRem NetCrunch 10.6.0.4587 allows Credentials Disclosure. Every user can read the BSD, Linux, MacOS and Solaris private keys, private keys' passwords, and root passwords stored in the credential manager. Every administrator can read the ESX and Windows passwords stored in the credential manager.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4005 – VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4005</guid>
    <pubDate>Fri, 20 Nov 2020 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4005</strong></p>
  <p>VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG) contains a privilege-escalation vulnerability that exists in the way certain system calls are being managed. A malicious actor with privileges within the VMX process only, may escalate their privileges on the affected system. Successful exploitation of this issue is only possible when cha…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4004 – VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4004</guid>
    <pubDate>Fri, 20 Nov 2020 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4004</strong></p>
  <p>VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x before 15.5.7), Fusion (11.x before 11.5.7) contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-3995 – In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3995</guid>
    <pubDate>Tue, 20 Oct 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-3995</strong></p>
  <p>In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x before 15.1.0), Fusion (11.x before 11.1.0), the VMCI host drivers used by VMware hypervisors contain a memory leak vulnerability. A malicious actor with access to a virtual machine may be able to trigger a memory leak issue resulting in memory resource exhaustion on the hypervisor if the attack i…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-3992 – OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3992</guid>
    <pubDate>Tue, 20 Oct 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-3992</strong></p>
  <p>OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3982 – VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3982</guid>
    <pubDate>Tue, 20 Oct 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3982</strong></p>
  <p>VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds write vulnerability due to a time-of-check time-of-use issue in ACPI device. A malicious actor with administrative access to a virtual machine may be able to exploit this vulnerability to crash the virtual mach…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-3981 – VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3981</guid>
    <pubDate>Tue, 20 Oct 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-3981</strong></p>
  <p>VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds read vulnerability due to a time-of-check time-of-use issue in ACPI device. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx proces…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-24623 – A potential security vulnerability has been identified in Hewlett Packard Enterp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24623</guid>
    <pubDate>Fri, 18 Sep 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-24623</strong></p>
  <p>A potential security vulnerability has been identified in Hewlett Packard Enterprise Universal API Framework. The vulnerability could be remotely exploited to allow SQL injection in HPE Universal API Framework for VMware Esxi v2.5.2 and HPE Universal API Framework for Microsoft Hyper-V (VHD).</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-3976 – VMware ESXi and vCenter Server contain a partial denial of service vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3976</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3976</guid>
    <pubDate>Fri, 21 Aug 2020 13:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-3976</strong></p>
  <p>VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective authentication services. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3976">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-3971 – VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201907101-SG...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3971</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3971</guid>
    <pubDate>Thu, 25 Jun 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-3971</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201907101-SG), Workstation (15.x before 15.0.2), and Fusion (11.x before 11.0.2) contain a heap overflow vulnerability in the vmxnet3 virtual network adapter. A malicious actor with local access to a virtual machine with a vmxnet3 network adapter present may be able to read privileged information contained in physical memory.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3971">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2020-3970 – VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3970</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3970</guid>
    <pubDate>Thu, 25 Jun 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2020-3970</strong></p>
  <p>VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in the Shader functionality. A malicious actor with non-administrative local access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerabili…</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3970">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3968 – VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3968</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3968</guid>
    <pubDate>Thu, 25 Jun 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3968</strong></p>
  <p>VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds write vulnerability in the USB 3.0 controller (xHCI). A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to crash the virtual mac…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3968">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3967 – VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3967</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3967</guid>
    <pubDate>Thu, 25 Jun 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3967</strong></p>
  <p>VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain a heap-overflow vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local access to a virtual machine may be able to exploit this vulnerability to execute code on the hypervisor from a v…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3967">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3966 – VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3966</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3966</guid>
    <pubDate>Thu, 25 Jun 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3966</strong></p>
  <p>VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a heap-overflow due to a race condition issue in the USB 2.0 controller (EHCI). A malicious actor with local access to a virtual machine may be able to exploit this vulnerability to execute code on the hyp…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3966">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-3965 – VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3965</guid>
    <pubDate>Thu, 25 Jun 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-3965</strong></p>
  <p>VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain an information leak in the XHCI USB controller. A malicious actor with local access to a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-3964 – VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3964</guid>
    <pubDate>Thu, 25 Jun 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-3964</strong></p>
  <p>VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain an information leak in the EHCI USB controller. A malicious actor with local access to a virtual machine may be able to read privileged information contained in the hypervisor's memory. Additional conditio…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-3963 – VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3963</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3963</guid>
    <pubDate>Thu, 25 Jun 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-3963</strong></p>
  <p>VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a use-after-free vulnerability in PVNVRAM. A malicious actor with local access to a virtual machine may be able to read privileged information contained in physical memory.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3963">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3962 – VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3962</guid>
    <pubDate>Wed, 24 Jun 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3962</strong></p>
  <p>VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain a use-after-free vulnerability in the SVGA device. A malicious actor with local access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to execute code on the hypervi…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3969 – VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3969</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3969</guid>
    <pubDate>Wed, 24 Jun 2020 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3969</strong></p>
  <p>VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an off-by-one heap-overflow vulnerability in the SVGA device. A malicious actor with local access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to execute code on…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-193</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3969">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2020-3959 – VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3959</guid>
    <pubDate>Fri, 29 May 2020 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2020-3959</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.1.0) and VMware Fusion (11.x before 11.1.0) contain a memory leak vulnerability in the VMCI module. A malicious actor with local non-administrative access to a virtual machine may be able to crash the virtual machine's vmx process leading to a partial denial of service.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3959">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-3958 – VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3958</guid>
    <pubDate>Fri, 29 May 2020 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-3958</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.5.2) and VMware Fusion (11.x before 11.5.2) contain a denial-of-service vulnerability in the shader functionality. Successful exploitation of this issue may allow attackers with non-administrative access to a virtual machine to crash the virtual machine's vmx process leading to a…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-617</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-3955 – ESXi 6.5 without patch ESXi650-201912104-SG and ESXi 6.7 without patch ESXi670-2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3955</guid>
    <pubDate>Wed, 29 Apr 2020 03:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-3955</strong></p>
  <p>ESXi 6.5 without patch ESXi650-201912104-SG and ESXi 6.7 without patch ESXi670-202004103-SG do not properly neutralize script-related HTML when viewing virtual machines attributes. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.3.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3955">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5544 – OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite iss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5544</guid>
    <pubDate>Fri, 06 Dec 2019 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5544</strong></p>
  <p>OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-5536 – VMware ESXi (6.7 before ESXi670-201908101-SG and 6.5 before ESXi650-201910401-SG...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5536</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5536</guid>
    <pubDate>Mon, 28 Oct 2019 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-5536</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-201908101-SG and 6.5 before ESXi650-201910401-SG), Workstation (15.x before 15.5.0) and Fusion (11.x before 11.5.0) contain a denial-of-service vulnerability in the shader functionality. Successful exploitation of this issue may allow attackers with normal user privileges to create a denial-of-service condition on their own VM. Exploitation of this issue require an…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5536">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5527 – ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5527</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5527</guid>
    <pubDate>Thu, 10 Oct 2019 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5527</strong></p>
  <p>ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.5.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5527">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5521 – VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5521</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5521</guid>
    <pubDate>Fri, 20 Sep 2019 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5521</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6) and Fusion (11.x before 11.0.3 and 10.x before 10.1.6) contain an out-of-bounds read vulnerability in the pixel shader functionality. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to cr…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5521">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-5531 – VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5531</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5531</guid>
    <pubDate>Wed, 18 Sep 2019 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-5531</strong></p>
  <p>VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 prior to ESXi600-201807103-SG) and VMware vCenter Server (6.7 prior to 6.7 U1b, 6.5 prior to 6.5 U2b, and 6.0 prior to 6.0 U3j) contain an information disclosure vulnerability in clients arising from insufficient session expiration. An attacker with physical access or an ability to mimic a websocket…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5531">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-5528 – VMware ESXi 6.5 suffers from partial denial of service vulnerability in hostd pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5528</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5528</guid>
    <pubDate>Thu, 11 Jul 2019 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-5528</strong></p>
  <p>VMware ESXi 6.5 suffers from partial denial of service vulnerability in hostd process. Patch ESXi650-201907201-UG for this issue is available.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5528">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-5520 – VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5520</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5520</guid>
    <pubDate>Mon, 15 Apr 2019 18:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-5520</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before 10.1.6) updates address an out-of-bounds read vulnerability. Exploitation of this issue requires an attacker to have access to a virtual machine with 3D graphics enabled. Successful exploitation of this issue may lead t…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5520">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-5517 – VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5517</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5517</guid>
    <pubDate>Mon, 15 Apr 2019 18:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-5517</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before 10.1.6) contain multiple out-of-bounds read vulnerabilities in the shader translator. Exploitation of these issues requires an attacker to have access to a virtual machine with 3D graphics enabled. Successful exploitati…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5517">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-5516 – VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5516</guid>
    <pubDate>Mon, 15 Apr 2019 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-5516</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before 10.1.6) updates address an out-of-bounds vulnerability with the vertex shader functionality. Exploitation of this issue requires an attacker to have access to a virtual machine with 3D graphics enabled. Successful explo…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-5519 – VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5519</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5519</guid>
    <pubDate>Mon, 01 Apr 2019 21:30:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-5519</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 10.1.6) contain a Time-of-check Time-of-use (TOCTOU) vulnerability in the virtual USB 1.1 UHCI (Universal Host Controller Interface). Exploitation of this issue requires an attacker to have access to a…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5519">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-5518 – VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5518</guid>
    <pubDate>Mon, 01 Apr 2019 21:30:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-5518</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 10.1.6) contain an out-of-bounds read/write vulnerability in the virtual USB 1.1 UHCI (Universal Host Controller Interface). Exploitation of this issue requires an attacker to have access to a virtual…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-6982 – VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6982</guid>
    <pubDate>Tue, 04 Dec 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-6982</strong></p>
  <p>VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contain uninitialized stack memory usage in the vmxnet3 virtual network adapter which may lead to an information leak from host to guest.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6981 – VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6981</guid>
    <pubDate>Tue, 04 Dec 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6981</strong></p>
  <p>VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMware ESXi 6.0 without ESXi600-201811401-BG, VMware Workstation 15, VMware Workstation 14.1.3 or below, VMware Fusion 11, VMware Fusion 10.1.3 or below contain uninitialized stack memory usage in the vmxnet3 virtual network adapter which may allow a guest to execute code on the host.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6974 – VMware ESXi (6.7 before ESXi670-201810101-SG, 6.5 before ESXi650-201808401-BG, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6974</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6974</guid>
    <pubDate>Tue, 16 Oct 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6974</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-201810101-SG, 6.5 before ESXi650-201808401-BG, and 6.0 before ESXi600-201808401-BG), Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds read vulnerability in SVGA device. This issue may allow a guest to execute code on the host.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6974">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-6977 – VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6977</guid>
    <pubDate>Tue, 09 Oct 2018 20:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-6977</strong></p>
  <p>VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a 3D-rendering shader. Successfully exploiting this issue may allow an attacker with normal user privileges in the guest to make the VM unresponsive, and in some cases, possibly result other VMs on the host or the host itself becoming unresponsiv…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-6972 – VMware ESXi (6.7 before ESXi670-201806401-BG, 6.5 before ESXi650-201806401-BG, 6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6972</guid>
    <pubDate>Wed, 25 Jul 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-6972</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-201806401-BG, 6.5 before ESXi650-201806401-BG, 6.0 before ESXi600-201806401-BG and 5.5 before ESXi550-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain a denial-of-service vulnerability due to NULL pointer dereference issue in RPC handler. Successful exploitation of this issue may allow attackers with normal user privileges to…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6967 – VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2),...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6967</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6967</guid>
    <pubDate>Mon, 09 Jul 2018 20:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6967</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash their VMs, a different vulnerability than CVE-2018-6965 and CVE-2018-6966.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6967">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6966 – VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2),...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6966</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6966</guid>
    <pubDate>Mon, 09 Jul 2018 20:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6966</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash their VMs, a different vulnerability than CVE-2018-6965 and CVE-2018-6967.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6966">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6965 – VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2),...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6965</guid>
    <pubDate>Mon, 09 Jul 2018 20:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6965</strong></p>
  <p>VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash their VMs, a different vulnerability than CVE-2018-6966 and CVE-2018-6967.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4941 – VMware ESXi (6.0 before ESXi600-201711101-SG, 5.5 ESXi550-201709101-SG), Worksta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4941</guid>
    <pubDate>Wed, 20 Dec 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4941</strong></p>
  <p>VMware ESXi (6.0 before ESXi600-201711101-SG, 5.5 ESXi550-201709101-SG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could allow an authenticated VNC session to cause a stack overflow via a specific set of VNC packets. Successful exploitation of this issue could result in remote code execution in a virtual machine via the authenticated VNC session.…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-4940 – The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4940</guid>
    <pubDate>Wed, 20 Dec 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-4940</strong></p>
  <p>The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESXi550-201709102-SG) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker can exploit this vulnerability by injecting Javascript, which might get executed when other users access the Host Client.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4940">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4933 – VMware ESXi (6.5 before ESXi650-201710401-BG), Workstation (12.x before 12.5.8),...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4933</guid>
    <pubDate>Wed, 20 Dec 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4933</strong></p>
  <p>VMware ESXi (6.5 before ESXi650-201710401-BG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could allow an authenticated VNC session to cause a heap overflow via a specific set of VNC packets resulting in heap corruption. Successful exploitation of this issue could result in remote code execution in a virtual machine via the authenticated VNC sessio…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-4925 – VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4925</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4925</guid>
    <pubDate>Fri, 15 Sep 2017 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-4925</strong></p>
  <p>VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Workstation (12.x before 12.5.3), Fusion (8.x before 8.5.4) contain a NULL pointer dereference vulnerability. This issue occurs when handling guest RPC requests. Successful exploitation of this issue may allow attackers with normal user privileges to crash…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4925">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4924 – VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4924</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4924</guid>
    <pubDate>Fri, 15 Sep 2017 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4924</strong></p>
  <p>VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusion (8.x before 8.5.8) contain an out-of-bounds write vulnerability in SVGA device. This issue may allow a guest to execute code on the host.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4924">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-4905 – VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4905</guid>
    <pubDate>Wed, 07 Jun 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-4905</strong></p>
  <p>VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have uninitialized memory usage. This issue may lead to an information leak.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4904 – The XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4904</guid>
    <pubDate>Wed, 07 Jun 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4904</strong></p>
  <p>The XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 has uninitialized memory usage. This issue may allow a guest…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4903 – VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4903</guid>
    <pubDate>Wed, 07 Jun 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4903</strong></p>
  <p>VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have an uninitialized stack memory usage in SVGA. This issue may allow a guest to ex…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4902 – VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4902</guid>
    <pubDate>Wed, 07 Jun 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4902</strong></p>
  <p>VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have a Heap Buffer Overflow in SVGA. This issue may allow a guest to execute code on the host.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-7463 – Cross-site scripting (XSS) vulnerability in the Host Client in VMware vSphere Hy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-7463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-7463</guid>
    <pubDate>Thu, 29 Dec 2016 09:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-7463</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in the Host Client in VMware vSphere Hypervisor (aka ESXi) 5.5 and 6.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted VM.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-7458 – VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-7458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-7458</guid>
    <pubDate>Thu, 29 Dec 2016 09:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-7458</strong></p>
  <p>VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-5331 – CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5331</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5331</guid>
    <pubDate>Mon, 08 Aug 2016 01:59:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-5331</strong></p>
  <p>CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-93</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5331">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-5330 – Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5330</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5330</guid>
    <pubDate>Mon, 08 Aug 2016 01:59:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-5330</strong></p>
  <p>Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware Workstation Pro 12.1.x before 12.1.1, VMware Workstation Player 12.1.x before 12.1.1, and VMware Fusion 8.1.x before 8.1.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5330">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
