VMware / Esx
86 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-41709 | ESX insufficient logging vulnerability | LOW | 2.7 | Jul 30, 2026 |
| CVE-2026-41703 | Out-of-bounds read vulnerability | HIGH | 7.6 | Jul 30, 2026 |
| CVE-2026-47876 | VMXNET3 out-of-bounds write vulnerability | CRITICAL | 9.3 | Jul 30, 2026 |
| CVE-2014-7169 KEV | bash: code execution via specially-crafted environment (Incomplete fix for CVE-2014-6271) | CRITICAL | 9.8 | Sep 25, 2014 |
| CVE-2014-6271 KEV | bash: specially-crafted environment variables can be used to inject shell commands | CRITICAL | 9.8 | Sep 24, 2014 |
| CVE-2014-1208 | VMware Workstation 9.x before 9.0.1, VMware Player 5.x before 5.0.1, VMware Fusion 5.x before 5.0.1, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1 al… | LOW | 3.3 | Jan 17, 2014 |
| CVE-2014-1207 | VMware ESXi 4.0 through 5.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (NULL pointer dereference) by intercepting and modifying Ne… | MEDIUM | 4.3 | Jan 17, 2014 |
| CVE-2013-5973 | VMware ESXi 4.0 through 5.5 and ESX 4.0 and 4.1 allow local users to read or modify arbitrary files by leveraging the Virtual Machine Power User or Resource Po… | MEDIUM | 4.4 | Dec 23, 2013 |
| CVE-2013-3519 | lgtosync.sys in VMware Workstation 9.x before 9.0.3, VMware Player 5.x before 5.0.3, VMware Fusion 5.x before 5.0.4, VMware ESXi 4.0 through 5.1, and VMware ES… | HIGH | 7.9 | Dec 4, 2013 |
| CVE-2013-5970 | hostd-vmdb in VMware ESXi 4.0 through 5.0 and ESX 4.0 through 4.1 allows remote attackers to cause a denial of service (hostd-vmdb service outage) by modifying… | HIGH | 7.1 | Oct 21, 2013 |
| CVE-2013-3658 | Directory traversal vulnerability in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to delete arbitrary host OS files via unspecifie… | HIGH | 9.4 | Sep 10, 2013 |
| CVE-2013-3657 | Buffer overflow in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to execute arbitrary code or cause a denial of service via unspeci… | HIGH | 7.5 | Sep 10, 2013 |
| CVE-2013-1661 | VMware ESXi 4.0 through 5.1, and ESX 4.0 and 4.1, does not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to… | MEDIUM | 4.3 | Sep 4, 2013 |
| CVE-2013-1405 | VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update… | HIGH | 10.0 | Feb 15, 2013 |
| CVE-2013-1406 | The Virtual Machine Communication Interface (VMCI) implementation in vmci.sys in VMware Workstation 8.x before 8.0.5 and 9.x before 9.0.1 on Windows, VMware Fu… | HIGH | 7.2 | Feb 11, 2013 |
| CVE-2012-5703 | The vSphere API in VMware ESXi 4.1 and ESX 4.1 allows remote attackers to cause a denial of service (host daemon crash) via an invalid value in a (1) RetrieveP… | MEDIUM | 5.0 | Nov 20, 2012 |
| CVE-2012-1666 | Untrusted search path vulnerability in VMware Tools in VMware Workstation before 8.0.4, VMware Player before 4.0.4, VMware Fusion before 4.1.2, VMware View bef… | MEDIUM | 6.9 | Sep 8, 2012 |
| CVE-2012-3289 | VMware Workstation 8.x before 8.0.4, VMware Player 4.x before 4.0.4, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 allow remote attackers to caus… | HIGH | 7.8 | Jun 14, 2012 |
| CVE-2012-3288 | VMware Workstation 7.x before 7.1.6 and 8.x before 8.0.4, VMware Player 3.x before 3.1.6 and 4.x before 4.0.4, VMware Fusion 4.x before 4.1.3, VMware ESXi 3.5… | HIGH | 9.3 | Jun 14, 2012 |
| CVE-2012-2450 | VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.… | HIGH | 9.0 | May 4, 2012 |
| CVE-2012-2449 | VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x through 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4… | HIGH | 9.0 | May 4, 2012 |
| CVE-2012-2448 | VMware ESXi 3.5 through 5.0 and ESX 3.5 through 4.1 allow remote attackers to execute arbitrary code or cause a denial of service (memory overwrite) via NFS tr… | HIGH | 7.5 | May 4, 2012 |
| CVE-2012-1517 | The VMX process in VMware ESXi 4.1 and ESX 4.1 does not properly handle RPC commands, which allows guest OS users to cause a denial of service (memory overwrit… | HIGH | 9.0 | May 4, 2012 |
| CVE-2012-1516 | The VMX process in VMware ESXi 3.5 through 4.1 and ESX 3.5 through 4.1 does not properly handle RPC commands, which allows guest OS users to cause a denial of… | CRITICAL | 9.9 | May 4, 2012 |
| CVE-2012-1518 | VMware Workstation 8.x before 8.0.2, VMware Player 4.x before 4.0.2, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.… | HIGH | 8.3 | Apr 17, 2012 |
Showing 1 to 25 of 86 CVEs