threat
engine
.sh
Back
·
··:··
Home
/
Product
/
vmware workstation
Product
vmware workstation
213 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2025-22226
>= 17.0 and < 17.6.3
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A mal
7.1
HIGH
CVE-2025-22224
>= 17.0 and < 17.6.3
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A
9.3
CRITICAL
CVE-2024-22273
>= 17.0.0 and < 17.5.1
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor wi
8.1
HIGH
CVE-2024-22270
>= 17.0.0 and < 17.5.2
VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality.
7.1
HIGH
CVE-2024-22269
>= 17.0.0 and < 17.5.2
VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with lo
7.1
HIGH
CVE-2024-22268
>= 17.0.0 and < 17.5.2
VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with no
7.1
HIGH
CVE-2024-22267
>= 17.0.0 and < 17.5.2
VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local admin
9.3
CRITICAL
CVE-2024-22255
>= 17.0.0 and < 17.5.1
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious acto
7.1
HIGH
CVE-2024-22253
>= 17.0.0 and < 17.5.1
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with lo
9.3
CRITICAL
CVE-2024-22252
>= 17.0.0 and < 17.5.1
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with lo
9.3
CRITICAL
CVE-2024-22251
>= 17.0 and < 17.5.1
VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicio
5.9
MEDIUM
CVE-2023-34044
>= 17.0.0 and < 17.5
VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that exists in
7.1
HIGH
CVE-2023-20870
>= 17.0.0 and < 17.0.2
VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Blueto
6.0
MEDIUM
CVE-2023-20869
>= 17.0.0 and < 17.0.2
VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the function
8.2
HIGH
CVE-2023-20872
all versions
VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation.
8.8
HIGH
CVE-2023-20854
all versions
VMware Workstation contains an arbitrary file deletion vulnerability. A malicious actor with local user privileges on the victim's
8.4
HIGH
CVE-2022-31705
>= 16.0.0 and < 16.2.5
VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A maliciou
8.2
HIGH
CVE-2022-22983
>= 16.0.0 and < 16.2.4
VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious actor with loc
5.9
MEDIUM
CVE-2021-22041
>= 16.0.0 and < 16.2.1
VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local
6.7
MEDIUM
CVE-2022-22938
>= 16.0.0 and < 16.2.2
VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-service vulnera
6.5
MEDIUM
CVE-2021-22045
>= 16.0.0 and < 16.2.0
VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fus
7.8
HIGH
CVE-2020-3960
>= 15.0.0 and < 15.5.5
VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (1
8.4
HIGH
CVE-2021-21989
>= 16.0.0 and < 16.1.2
VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerabi
6.5
MEDIUM
CVE-2021-21988
>= 16.0.0 and < 16.1.2
VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerabi
6.5
MEDIUM
CVE-2021-21987
>= 16.0.0 and < 16.1.2
VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerabi
6.5
MEDIUM
CVE-2020-3999
>= 15.0.0 and < 15.5.7
VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12
6.5
MEDIUM
CVE-2020-4004
>= 15.0.0 and < 15.5.7
VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x b
8.2
HIGH
CVE-2020-3995
>= 15.0.0 and < 15.1.0
In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x before 15.1.0), Fusion (11.x
5.3
MEDIUM
CVE-2020-3982
>= 15.0 and <= 15.5.6
VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (1
7.7
HIGH
CVE-2020-3981
>= 15.0.0 and <= 15.5.6
VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (1
5.8
MEDIUM
CVE-2020-3971
>= 15.0.0 and < 15.0.2
VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201907101-SG), Workstation (15.x before 15.0.2), and Fusion (1
5.5
MEDIUM
CVE-2020-3970
>= 15.0.0 and < 15.5.5
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstatio
3.8
LOW
CVE-2020-3968
>= 15.0.0 and < 15.5.5
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstatio
8.2
HIGH
CVE-2020-3967
>= 15.0.0 and < 15.5.5
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstatio
7.5
HIGH
CVE-2020-3966
>= 15.0.0 and < 15.5.2
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstatio
7.5
HIGH
CVE-2020-3965
>= 15.0.0 and < 15.5.2
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstatio
5.5
MEDIUM
CVE-2020-3964
>= 15.0.0 and < 15.5.2
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstatio
4.7
MEDIUM
CVE-2020-3963
>= 15.0.0 and < 15.5.2
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstatio
5.5
MEDIUM
CVE-2020-3962
>= 15.0.0 and < 15.5.5
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstatio
8.2
HIGH
CVE-2020-3969
>= 15.0.0 and < 15.5.5
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstatio
7.8
HIGH
CVE-2020-3959
>= 15.0.0 and < 15.1.0
VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.1.0) and VMw
3.3
LOW
CVE-2020-3958
>= 15.0.0 and < 15.5.2
VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.5.2) and VMw
5.5
MEDIUM
CVE-2020-3951
>= 15.0.0 and < 15.5.2
VMware Workstation (15.x before 15.5.2) and Horizon Client for Windows (5.x and prior before 5.4.0) contain a denial-of-service vu
3.8
LOW
CVE-2020-3948
>= 15.0.0 and < 15.5.2
Linux Guest VMs running on VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a local privilege escal
7.8
HIGH
CVE-2020-3947
>= 15.0.0 and < 15.5.2
VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerability in vmnetdhcp. Successful
8.8
HIGH
CVE-2019-5543
>= 15.0.0 and < 15.5.2
For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0.0), VMware
7.8
HIGH
CVE-2019-5539
>= 15.0.0 and < 15.5.1
VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL h
7.8
HIGH
CVE-2019-5098
all versions
An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.29010. A specially crafted
8.6
HIGH
CVE-2019-5542
>= 15.0.0 and < 15.5.1
VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain a denial-of-service vulnerability in the RPC handl
7.7
HIGH
CVE-2019-5541
>= 15.0.0 and < 15.5.1
VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in the e1000e
9.1
CRITICAL
CVE-2019-5540
>= 15.0.0 and < 15.5.1
VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an information disclosure vulnerability in vmnetdh
7.7
HIGH
CVE-2019-5536
>= 15.0.0 and < 15.5.0
VMware ESXi (6.7 before ESXi670-201908101-SG and 6.5 before ESXi650-201910401-SG), Workstation (15.x before 15.5.0) and Fusion (11
6.5
MEDIUM
CVE-2019-5535
>= 15.0.0 and < 15.5.0
VMware Workstation and Fusion contain a network denial-of-service vulnerability due to improper handling of certain IPv6 packets.
4.7
MEDIUM
CVE-2019-5527
>= 15.0.0 and < 15.5.0
ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has
8.8
HIGH
CVE-2019-5521
>= 14.0.0 and < 14.1.6
VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14
9.6
CRITICAL
CVE-2019-5525
>= 15.0.0 and < 15.1.0
VMware Workstation (15.x before 15.1.0) contains a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) ba
8.8
HIGH
CVE-2019-5526
>= 15.0.0 and < 15.1.0
VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by the applica
7.8
HIGH
CVE-2019-5520
>= 14.0.0 and < 14.1.6
VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14
5.9
MEDIUM
CVE-2019-5517
>= 14.0.0 and < 14.1.6
VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14
6.8
MEDIUM
CVE-2019-5516
>= 14.0.0 and < 14.1.6
VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14
6.8
MEDIUM
CVE-2019-5512
>= 14.0.0 and < 14.1.6
VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle COM classes appropriately. Successf
8.8
HIGH
CVE-2019-5511
>= 14.0.0 and < 14.1.6
VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle paths appropriately. Successful exp
8.8
HIGH
CVE-2019-5524
>= 14.0.0 and < 14.1.6
VMware Workstation (14.x before 14.1.6) and Fusion (10.x before 10.1.6) contain an out-of-bounds write vulnerability in the e1000
8.8
HIGH
CVE-2019-5515
>= 14.0.0 and < 14.1.6
VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) and Fusion (11.x before 11.0.3, 10.x before 10.1.6) updates address an
8.8
HIGH
CVE-2019-5519
>= 14.0.0 and < 14.1.7
VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 1
6.8
MEDIUM
CVE-2019-5518
>= 14.0.0 and < 14.1.7
VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 1
6.8
MEDIUM
CVE-2018-6982
>= 14.0.0 and < 14.1.4
VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contain uninitialized stack memory u
6.5
MEDIUM
CVE-2018-6981
>= 14.0.0 and < 14.1.4
VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMware ESXi 6.0 without ESXi600-201
8.8
HIGH
CVE-2018-6983
>= 14.0.0 and < 14.1.5
VMware Workstation (15.x before 15.0.2 and 14.x before 14.1.5) and Fusion (11.x before 11.0.2 and 10.x before 10.1.5) contain an i
8.8
HIGH
CVE-2018-6974
>= 14.0 and < 14.1.3
VMware ESXi (6.7 before ESXi670-201810101-SG, 6.5 before ESXi650-201808401-BG, and 6.0 before ESXi600-201808401-BG), Workstation (
8.8
HIGH
CVE-2018-6977
>= 14.0.0 and <= 14.1.5
VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due
6.5
MEDIUM
CVE-2018-6973
>= 14.0.0 and < 14.1.3
VMware Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds write vulnerability in the e1000
8.8
HIGH
CVE-2018-6972
>= 14.0 and < 14.1.2
VMware ESXi (6.7 before ESXi670-201806401-BG, 6.5 before ESXi650-201806401-BG, 6.0 before ESXi600-201806401-BG and 5.5 before ESXi
6.5
MEDIUM
CVE-2018-6967
>= 14.0 and < 14.1.2
VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of
8.1
HIGH
CVE-2018-6966
>= 14.0 and < 14.1.2
VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of
8.1
HIGH
CVE-2018-6965
>= 14.0 and < 14.1.2
VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of
8.1
HIGH
CVE-2018-6963
>= 14.0 and < 14.1.2
VMware Workstation (14.x before 14.1.2) and Fusion (10.x before 10.1.2) contain multiple denial-of-service vulnerabilities that oc
5.5
MEDIUM
CVE-2018-5511
all versions
On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User In
7.2
HIGH
CVE-2017-4950
>= 12.0 and < 12.5.9
VMware Workstation and Fusion contain an integer overflow vulnerability in VMware NAT service when IPv6 mode is enabled. This issu
7.0
HIGH
CVE-2017-4949
>= 12.0 and < 12.5.9
VMware Workstation and Fusion contain a use-after-free vulnerability in VMware NAT service when IPv6 mode is enabled. This issue m
7.0
HIGH
CVE-2017-4948
all versions
VMware Workstation (14.x before 14.1.0 and 12.x) and Horizon View Client (4.x before 4.7.0) contain an out-of-bounds read vulnerab
7.1
HIGH
CVE-2017-4945
all versions
VMware Workstation (14.x and 12.x) and Fusion (10.x and 8.x) contain a guest access control vulnerability. This issue may allow pr
5.5
MEDIUM
CVE-2017-5753
>= 12.0.0 and < 12.5.8
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of informatio
5.6
MEDIUM
CVE-2017-4941
>= 12.0.0 and < 12.5.8
VMware ESXi (6.0 before ESXi600-201711101-SG, 5.5 ESXi550-201709101-SG), Workstation (12.x before 12.5.8), and Fusion (8.x before
8.8
HIGH
CVE-2017-4939
all versions
VMware Workstation (12.x before 12.5.8) installer contains a DLL hijacking issue that exists due to some DLL files loaded by the a
7.8
HIGH
CVE-2017-4938
all versions
VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL pointer dereference vulnerability.
6.5
MEDIUM
CVE-2017-4937
all versions
VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulne
7.8
HIGH
CVE-2017-4936
all versions
VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulne
7.8
HIGH
CVE-2017-4935
all versions
VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds write vuln
7.8
HIGH
CVE-2017-4934
all versions
VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a heap buffer-overflow vulnerability in VMNAT device
8.8
HIGH
CVE-2017-4925
>= 12.0.0 and < 12.5.3
VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-20
5.5
MEDIUM
CVE-2017-4913
all versions
VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain an integer-overflow vulnerability i
7.8
HIGH
CVE-2017-4912
all versions
VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnera
7.8
HIGH
CVE-2017-4911
all versions
VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds write vulner
7.8
HIGH
CVE-2017-4910
all versions
VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnera
7.8
HIGH
CVE-2017-4909
all versions
VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain a heap buffer-overflow vulnerabilit
7.8
HIGH
CVE-2017-4908
all versions
VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple heap buffer-overflow vulne
7.8
HIGH
CVE-2017-4901
all versions
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-o
9.9
CRITICAL
CVE-2016-2077
all versions
VMware Workstation 11.x before 11.1.3 and VMware Player 7.x before 7.1.3 on Windows incorrectly access an executable file, which a
9.8
CRITICAL
CVE-2015-6933
all versions
The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2
6.3
MEDIUM
CVE-2015-3650
all versions
vmware-vmx.exe in VMware Workstation 7.x through 10.x before 10.0.7 and 11.x before 11.1.1, VMware Player 5.x and 6.x before 6.0.7
CVE-2015-2341
all versions
VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.6, and VMware Fusion 6.x before 6.0.6 and 7.x before 7.0.1 all
CVE-2015-2340
all versions
TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, an
CVE-2015-2339
all versions
TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, a
CVE-2015-2338
all versions
TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, a
CVE-2015-2337
all versions
TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, an
CVE-2015-2336
all versions
TPView.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, a
CVE-2015-1044
all versions
vmware-authd (aka the Authorization process) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, and VMware
CVE-2015-1043
all versions
The Host Guest File System (HGFS) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, and VMware Fusion 6.x
CVE-2014-8370
all versions
VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, VMware Fusion 6.x before 6.0.5, and VMware ESXi 5.0 through
CVE-2014-4200
<= 10.0.3
vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, uses 0644 permissions f
CVE-2014-4199
<= 10.0.3
vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to w
CVE-2014-3793
all versions
VMware Tools in VMware Workstation 10.x before 10.0.2, VMware Player 6.x before 6.0.2, VMware Fusion 6.x before 6.0.3, and VMware
CVE-2014-2384
all versions
vmx86.sys in VMware Workstation 10.0.1 build 1379776 and VMware Player 6.0.1 build 1379776 on Windows might allow local users to c
CVE-2014-1208
all versions
VMware Workstation 9.x before 9.0.1, VMware Player 5.x before 5.0.1, VMware Fusion 5.x before 5.0.1, VMware ESXi 4.0 through 5.1,
CVE-2013-3519
all versions
lgtosync.sys in VMware Workstation 9.x before 9.0.3, VMware Player 5.x before 5.0.3, VMware Fusion 5.x before 5.0.4, VMware ESXi 4
CVE-2013-5972
all versions
VMware Workstation 9.x before 9.0.3 and VMware Player 5.x before 5.0.3 on Linux do not properly handle shared libraries, which all
CVE-2013-1662
all versions
vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS
CVE-2013-1406
all versions
The Virtual Machine Communication Interface (VMCI) implementation in vmci.sys in VMware Workstation 8.x before 8.0.5 and 9.x befor
CVE-2012-5459
all versions
Untrusted search path vulnerability in VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows allows ho
CVE-2012-5458
all versions
VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows use weak permissions for unspecified process thr
CVE-2012-3569
all versions
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x b
CVE-2012-1666
<= 8.0.3
Untrusted search path vulnerability in VMware Tools in VMware Workstation before 8.0.4, VMware Player before 4.0.4, VMware Fusion
CVE-2012-3289
all versions
VMware Workstation 8.x before 8.0.4, VMware Player 4.x before 4.0.4, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 a
CVE-2012-3288
all versions
VMware Workstation 7.x before 7.1.6 and 8.x before 8.0.4, VMware Player 3.x before 3.1.6 and 4.x before 4.0.4, VMware Fusion 4.x b
CVE-2012-2450
all versions
VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0,
CVE-2012-2449
all versions
VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x through 4.1.2, VMware ESXi 3.5 through 5.0,
CVE-2012-1518
all versions
VMware Workstation 8.x before 8.0.2, VMware Player 4.x before 4.0.2, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0,
CVE-2011-3868
all versions
Buffer overflow in VMware Workstation 7.x before 7.1.5, VMware Player 3.x before 3.1.5, VMware Fusion 3.1.x before 3.1.3, and VMwa
CVE-2011-2146
all versions
mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.
CVE-2011-2145
all versions
mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.
CVE-2011-1787
all versions
Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player
CVE-2011-1126
all versions
VMware vmrun, as used in VIX API 1.x before 1.10.3 and VMware Workstation 6.5.x and 7.x before 7.1.4 build 385536 on Linux, might
CVE-2010-4297
all versions
The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548; VMw
CVE-2010-4296
all versions
vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux,
CVE-2010-4295
all versions
Race condition in the mounting process in vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player
CVE-2010-4294
all versions
The frame decompression functionality in the VMnc media codec in VMware Movie Decoder before 6.5.5 build 328052 and 7.x before 7.1
CVE-2010-3277
all versions
The installer in VMware Workstation 7.x before 7.1.2 build 301548 and VMware Player 3.x before 3.1.2 build 301548 renders an index
CVE-2010-2249
>= 6.5.0 and < 6.5.5
Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (m
6.5
MEDIUM
CVE-2010-1205
>= 6.5.0 and < 6.5.5
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow rem
9.8
CRITICAL
CVE-2009-4811
all versions
VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 bu
CVE-2010-1142
all versions
VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.
CVE-2010-1141
all versions
VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.
CVE-2010-1140
all versions
The USB service in VMware Workstation 7.0 before 7.0.1 build 227600 and VMware Player 3.0 before 3.0.1 build 227600 on Windows mig
CVE-2010-1139
all versions
Format string vulnerability in vmrun in VMware VIX API 1.6.x, VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.
CVE-2010-1138
all versions
The virtual networking stack in VMware Workstation 7.0 before 7.0.1 build 227600, VMware Workstation 6.5.x before 6.5.4 build 2464
CVE-2009-3732
>= 6.5.0 and < 6.5.4
Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute
CVE-2009-1565
all versions
vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Wor
CVE-2009-1564
all versions
Heap-based buffer overflow in vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and t
CVE-2009-2267
all versions
VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 b
CVE-2009-3707
all versions
VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 bu
CVE-2009-2628
all versions
The VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 18
CVE-2009-0199
all versions
Heap-based buffer overflow in the VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstati
CVE-2009-1805
<= 6.5.1
Unspecified vulnerability in the VMware Descheduled Time Accounting driver in VMware Workstation 6.5.1 and earlier, VMware Player
CVE-2009-1244
<= 6.5.1
Unspecified vulnerability in the virtual machine display function in VMware Workstation 6.5.1 and earlier; VMware Player 2.5.1 and
CVE-2009-1147
all versions
Unspecified vulnerability in vmci.sys in the Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.5.1 and earlie
CVE-2009-1146
<= 6.5.1
Unspecified vulnerability in an ioctl in hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMwar
CVE-2009-0910
all versions
Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5
CVE-2009-0909
all versions
Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5
CVE-2008-4917
>= 5.5 and <= 5.5.8
Unspecified vulnerability in VMware Workstation 5.5.8 and earlier, and 6.0.5 and earlier 6.x versions; VMware Player 1.0.8 and ear
CVE-2008-4915
>= 5.5 and <= 5.5.8
The CPU hardware emulation in VMware Workstation 6.0.5 and earlier and 5.5.8 and earlier; Player 2.0.x through 2.0.5 and 1.0.x thr
CVE-2008-4279
>= 5.5 and < 5.5.8
The CPU hardware emulation for 64-bit guest operating systems in VMware Workstation 6.0.x before 6.0.5 build 109488 and 5.x before
CVE-2008-3892
>= 5.5 and < 5.5.8
Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstat
CVE-2008-3698
>= 5.5 and < 5.5.8
Unspecified vulnerability in the OpenProcess function in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.
CVE-2008-3696
>= 5.5 and < 5.5.8
Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6
CVE-2008-3695
>= 5.5 and < 5.5.8
Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6
CVE-2008-3694
>= 5.5 and < 5.5.8
Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6
CVE-2008-3693
>= 5.5 and < 5.5.8
Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6
CVE-2008-3692
>= 5.5 and < 5.5.8
Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6
CVE-2008-3691
>= 5.5 and < 5.5.8
Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6
CVE-2008-2100
>= 5.5 and <= 5.5.6
Multiple buffer overflows in VIX API 1.1.x before 1.1.4 build 93057 on VMware Workstation 5.x and 6.x, VMware Player 1.x and 2.x,
CVE-2008-0967
all versions
Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build
CVE-2007-5671
all versions
HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Player before 1.0.6 build 80404, V
CVE-2008-2099
all versions
Unspecified vulnerability in VMCI in VMware Workstation 6 before 6.0.4 build 93057, VMware Player 2 before 2.0.4 build 93057, and
CVE-2008-2098
all versions
Heap-based buffer overflow in the VMware Host Guest File System (HGFS) in VMware Workstation 6 before 6.0.4 build 93057, VMware Pl
CVE-2008-1364
all versions
Unspecified vulnerability in the DHCP service in VMware Workstation 5.5.x before 5.5.6, VMware Player 1.0.x before 1.0.6, VMware A
CVE-2008-1363
>= 5.5 and < 5.5.6
VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE
CVE-2008-1362
all versions
VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE
CVE-2008-1361
all versions
VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE
CVE-2008-1340
all versions
Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.0.x before 6.0.3, VMware Player 2.0.x before 2.0.3, and VMw
CVE-2008-0923
all versions
Directory traversal vulnerability in the Shared Folders feature for VMWare ACE 1.0.2 and 2.0.2, Player 1.0.4 and 2.0.2, and Workst
CVE-2007-5618
>= 5.5 and < 5.5.5
Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player 1.0.x before 1.0.5 and 2.0 bef
CVE-2007-5617
>= 5.5 and < 5.5.5
Unspecified vulnerability in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, and Workstation 5.x before 5.5.5 and 6.x befor
CVE-2007-5023
>= 5 and <= 5.5.5
Unquoted Windows search path vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Pl
CVE-2007-4497
>= 5 and <= 5.5.5
Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5
CVE-2007-4496
>= 5 and <= 5.5.5
Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5
CVE-2007-0063
>= 5.5 and < 5.5.5
Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player b
CVE-2007-0062
all versions
Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before
CVE-2007-0061
>= 5.5 and < 5.5.5
The DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 564
CVE-2007-4593
all versions
Unspecified vulnerability in vstor2-ws60.sys in VMWare Workstation 6.0 allows local users to cause a denial of service (host opera
CVE-2007-4591
all versions
vstor-ws60.sys in VMWare Workstation 6.0 allows local users to cause a denial of service (host operating system crash) and possibl
CVE-2007-4059
all versions
Absolute path traversal vulnerability in a certain ActiveX control in IntraProcessLogging.dll 5.5.3.42958 in EMC VMware allows rem
CVE-2007-2491
all versions
The PIIX4 power management subsystem in EMC VMware Workstation 5.5.3.34685 and VMware Server 1.0.1.29996 allows local users to wri
CVE-2007-1877
<= 5.5.3
VMware Workstation before 5.5.4 allows attackers to cause a denial of service against the guest OS by causing the virtual machine
CVE-2007-1876
<= 5.5.3
VMware Workstation before 5.5.4, when running a 64-bit Windows guest on a 64-bit host, allows local users to "corrupt the virtual
CVE-2007-1744
<= 5.5.3
Directory traversal vulnerability in the Shared Folders feature for VMware Workstation before 5.5.4, when a folder is shared, allo
CVE-2007-1337
<= 5.5.3
The virtual machine process (VMX) in VMware Workstation before 5.5.4 does not properly read state information when moving from the
CVE-2007-1069
<= 5.5.3
The memory management in VMware Workstation before 5.5.4 allows attackers to cause a denial of service (Windows virtual machine cr
CVE-2007-1056
all versions
VMware Workstation 5.5.3 build 34685 does not provide per-user restrictions on certain privileged actions, which allows local user
CVE-2007-0833
all versions
VMware Workstation 5.5.3 34685, when the "Enable copy and paste to and from this virtual machine" option is enabled, preserves cli
CVE-2007-0832
all versions
VMware Workstation 5.5.3 34685 does not immediately change the availability of a shared clipboard when the "Enable copy and paste
CVE-2006-6410
all versions
Buffer overflow in an ActiveX control in VMWare 5.5.1 allows local users to execute arbitrary code via a long VmdbDb parameter to
CVE-2006-3589
all versions
vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod functi
CVE-2005-4459
all versions
Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, AC
CVE-2005-2939
all versions
Unquoted Windows search path vulnerability in VMWare Workstation 5.0.0 build-13124 might allow local users to gain privileges via
CVE-2005-0444
<= 4.5.2_build_8848
VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the rrdharan world-writable tempor
CVE-2004-2515
all versions
Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privileges, might allow local users t
CVE-2003-0739
<= 4.0.1_build_5289
VMware Workstation 4.0.1 for Linux, build 5289 and earlier, allows local users to delete arbitrary files via a symlink attack.
CVE-2003-0631
all versions
VMware GSX Server 2.5.1 build 4968 and earlier, and Workstation 4.0 and earlier, allows local users to gain root privileges via ce
CVE-2003-0480
all versions
VMware Workstation 4.0 for Linux allows local users to overwrite arbitrary files and gain privileges via "symlink manipulation."
CVE-2001-1059
all versions
VMWare creates a temporary file vmware-log.USERNAME with insecure permissions, which allows local users to read or modify license
CVE-2000-0090
all versions
VMWare 1.1.2 allows local users to cause a denial of service via a symlink attack.
CVE-1999-0733
all versions
Buffer overflow in VMWare 1.0.1 for Linux via a long HOME environmental variable.
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin