VYPR

Horizon

by VMware

CVEs (8)

  • CVE-2019-5527HigOct 10, 2019
    risk 0.57cvss 8.8epss 0.00

    ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.5.

  • CVE-2022-22964HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.00

    VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to root due to a vulnerable configuration file.

  • CVE-2022-22962HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.00

    VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder location due to a vulnerable symbolic link. Successful exploitation can result in linking to a root owned file.

  • CVE-2025-58131MedSep 9, 2025
    risk 0.43cvss 6.6epss 0.00

    Race condition in the Zoom Workplace VDI Plugin macOS Universal installer for VMware Horizon before version 6.4.10 (or before 6.2.15 and 6.3.12 in their respective tracks) may allow an authenticated user to conduct a disclosure of information via network access.

  • CVE-2022-22938MedJan 28, 2022
    risk 0.42cvss 6.5epss 0.00

    VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-service vulnerability in the Cortado ThinPrint component. The issue exists in TrueType font parser. A malicious actor with access to a virtual machine or remote…

  • CVE-2018-6970MedAug 13, 2018
    risk 0.42cvss 6.5epss 0.02

    VMware Horizon 6 (6.x.x before 6.2.7), Horizon 7 (7.x.x before 7.5.1), and Horizon Client (4.x.x and prior before 4.8.1) contain an out-of-bounds read vulnerability in the Message Framework library. Successfully exploiting this issue may allow a less-privileged user to leak…

  • CVE-2020-3997MedOct 23, 2020
    risk 0.35cvss 5.4epss 0.01

    VMware Horizon Server (7.x prior to 7.10.3 or 7.13.0) contains a Cross Site Scripting (XSS) vulnerability. Successful exploitation of this issue may allow an attacker to inject malicious script which will be executed.

  • CVE-2019-5513MedApr 9, 2019
    risk 0.35cvss 5.3epss 0.01

    VMware Horizon Connection Server (7.x before 7.8, 7.5.x before 7.5.2, 6.x before 6.2.8) contains an information disclosure vulnerability. Successful exploitation of this issue may allow disclosure of internal domain names, the Connection Server’s internal name, or the…