Workstation
by VMware
CVEs (253)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2007-1876 | 0.00 | — | 0.00 | May 2, 2007 | VMware Workstation before 5.5.4, when running a 64-bit Windows guest on a 64-bit host, allows local users to "corrupt the virtual machine's register context" by debugging a local program and stepping into a "syscall instruction." | |||
| CVE-2007-1056 | 0.00 | — | 0.00 | Feb 21, 2007 | VMware Workstation 5.5.3 build 34685 does not provide per-user restrictions on certain privileged actions, which allows local users to perform restricted operations such as changing system time, accessing hardware components, and stopping the "VMware tools service" service.… | |||
| CVE-2007-0833 | 0.00 | — | 0.00 | Feb 7, 2007 | VMware Workstation 5.5.3 34685, when the "Enable copy and paste to and from this virtual machine" option is enabled, preserves clipboard data on the guest operating system after it was deleted on the host operating system, which might allow local users to read clipboard contents… | |||
| CVE-2007-0832 | 0.00 | — | 0.00 | Feb 7, 2007 | VMware Workstation 5.5.3 34685 does not immediately change the availability of a shared clipboard when the "Enable copy and paste to and from this virtual machine" checkbox is changed, which allows local users to obtain sensitive information or conduct certain attacks that are… | |||
| CVE-2006-3589 | 0.00 | — | 0.00 | Jul 21, 2006 | vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the SSL key. | |||
| CVE-2005-2939 | 0.00 | — | 0.00 | Nov 18, 2005 | Unquoted Windows search path vulnerability in VMWare Workstation 5.0.0 build-13124 might allow local users to gain privileges via a malicious "program.exe" file in the C: folder. | |||
| CVE-2005-0444 | 0.00 | — | 0.00 | Feb 14, 2005 | VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the rrdharan world-writable temporary directory, which allows local users to execute arbitrary code. | |||
| CVE-2004-2515 | 0.00 | — | 0.01 | Dec 31, 2004 | Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privileges, might allow local users to execute arbitrary code via format string specifiers in command line arguments. NOTE: it is not clear if there are any default or typical… | |||
| CVE-2003-0739 | 0.00 | — | 0.00 | Oct 20, 2003 | VMware Workstation 4.0.1 for Linux, build 5289 and earlier, allows local users to delete arbitrary files via a symlink attack. | |||
| CVE-2003-0631 | 0.00 | — | 0.00 | Aug 27, 2003 | VMware GSX Server 2.5.1 build 4968 and earlier, and Workstation 4.0 and earlier, allows local users to gain root privileges via certain enivronment variables that are used when launching a virtual machine session. | |||
| CVE-2003-0480 | 0.00 | — | 0.00 | Aug 7, 2003 | VMware Workstation 4.0 for Linux allows local users to overwrite arbitrary files and gain privileges via "symlink manipulation." | |||
| CVE-2001-1059 | 0.00 | — | 0.00 | Jul 30, 2001 | VMWare creates a temporary file vmware-log.USERNAME with insecure permissions, which allows local users to read or modify license information. | |||
| CVE-2000-0090 | 0.00 | — | 0.00 | Jan 17, 2000 | VMWare 1.1.2 allows local users to cause a denial of service via a symlink attack. |
- CVE-2007-1876May 2, 2007risk 0.00cvss —epss 0.00
VMware Workstation before 5.5.4, when running a 64-bit Windows guest on a 64-bit host, allows local users to "corrupt the virtual machine's register context" by debugging a local program and stepping into a "syscall instruction."
- CVE-2007-1056Feb 21, 2007risk 0.00cvss —epss 0.00
VMware Workstation 5.5.3 build 34685 does not provide per-user restrictions on certain privileged actions, which allows local users to perform restricted operations such as changing system time, accessing hardware components, and stopping the "VMware tools service" service.…
- CVE-2007-0833Feb 7, 2007risk 0.00cvss —epss 0.00
VMware Workstation 5.5.3 34685, when the "Enable copy and paste to and from this virtual machine" option is enabled, preserves clipboard data on the guest operating system after it was deleted on the host operating system, which might allow local users to read clipboard contents…
- CVE-2007-0832Feb 7, 2007risk 0.00cvss —epss 0.00
VMware Workstation 5.5.3 34685 does not immediately change the availability of a shared clipboard when the "Enable copy and paste to and from this virtual machine" checkbox is changed, which allows local users to obtain sensitive information or conduct certain attacks that are…
- CVE-2006-3589Jul 21, 2006risk 0.00cvss —epss 0.00
vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the SSL key.
- CVE-2005-2939Nov 18, 2005risk 0.00cvss —epss 0.00
Unquoted Windows search path vulnerability in VMWare Workstation 5.0.0 build-13124 might allow local users to gain privileges via a malicious "program.exe" file in the C: folder.
- CVE-2005-0444Feb 14, 2005risk 0.00cvss —epss 0.00
VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the rrdharan world-writable temporary directory, which allows local users to execute arbitrary code.
- CVE-2004-2515Dec 31, 2004risk 0.00cvss —epss 0.01
Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privileges, might allow local users to execute arbitrary code via format string specifiers in command line arguments. NOTE: it is not clear if there are any default or typical…
- CVE-2003-0739Oct 20, 2003risk 0.00cvss —epss 0.00
VMware Workstation 4.0.1 for Linux, build 5289 and earlier, allows local users to delete arbitrary files via a symlink attack.
- CVE-2003-0631Aug 27, 2003risk 0.00cvss —epss 0.00
VMware GSX Server 2.5.1 build 4968 and earlier, and Workstation 4.0 and earlier, allows local users to gain root privileges via certain enivronment variables that are used when launching a virtual machine session.
- CVE-2003-0480Aug 7, 2003risk 0.00cvss —epss 0.00
VMware Workstation 4.0 for Linux allows local users to overwrite arbitrary files and gain privileges via "symlink manipulation."
- CVE-2001-1059Jul 30, 2001risk 0.00cvss —epss 0.00
VMWare creates a temporary file vmware-log.USERNAME with insecure permissions, which allows local users to read or modify license information.
- CVE-2000-0090Jan 17, 2000risk 0.00cvss —epss 0.00
VMWare 1.1.2 allows local users to cause a denial of service via a symlink attack.
Page 13 of 13