Home/Product/vmware workstation
Product

vmware workstation

213 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-22226
>= 17.0 and < 17.6.3
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A mal
7.1HIGH
CVE-2025-22224
>= 17.0 and < 17.6.3
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A
9.3CRITICAL
CVE-2024-22273
>= 17.0.0 and < 17.5.1
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor wi
8.1HIGH
CVE-2024-22270
>= 17.0.0 and < 17.5.2
VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality.
7.1HIGH
CVE-2024-22269
>= 17.0.0 and < 17.5.2
VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with lo
7.1HIGH
CVE-2024-22268
>= 17.0.0 and < 17.5.2
VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with no
7.1HIGH
CVE-2024-22267
>= 17.0.0 and < 17.5.2
VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local admin
9.3CRITICAL
CVE-2024-22255
>= 17.0.0 and < 17.5.1
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious acto
7.1HIGH
CVE-2024-22253
>= 17.0.0 and < 17.5.1
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with lo
9.3CRITICAL
CVE-2024-22252
>= 17.0.0 and < 17.5.1
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with lo
9.3CRITICAL
CVE-2024-22251
>= 17.0 and < 17.5.1
VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicio
5.9MEDIUM
CVE-2023-34044
>= 17.0.0 and < 17.5
VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that exists in
7.1HIGH
CVE-2023-20870
>= 17.0.0 and < 17.0.2
VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Blueto
6.0MEDIUM
CVE-2023-20869
>= 17.0.0 and < 17.0.2
VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the function
8.2HIGH
CVE-2023-20872
all versions
VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation.
8.8HIGH
CVE-2023-20854
all versions
VMware Workstation contains an arbitrary file deletion vulnerability. A malicious actor with local user privileges on the victim's
8.4HIGH
CVE-2022-31705
>= 16.0.0 and < 16.2.5
VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A maliciou
8.2HIGH
CVE-2022-22983
>= 16.0.0 and < 16.2.4
VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious actor with loc
5.9MEDIUM
CVE-2021-22041
>= 16.0.0 and < 16.2.1
VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local
6.7MEDIUM
CVE-2022-22938
>= 16.0.0 and < 16.2.2
VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-service vulnera
6.5MEDIUM
CVE-2021-22045
>= 16.0.0 and < 16.2.0
VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fus
7.8HIGH
CVE-2020-3960
>= 15.0.0 and < 15.5.5
VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (1
8.4HIGH
CVE-2021-21989
>= 16.0.0 and < 16.1.2
VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerabi
6.5MEDIUM
CVE-2021-21988
>= 16.0.0 and < 16.1.2
VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerabi
6.5MEDIUM
CVE-2021-21987
>= 16.0.0 and < 16.1.2
VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerabi
6.5MEDIUM
CVE-2020-3999
>= 15.0.0 and < 15.5.7
VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12
6.5MEDIUM
CVE-2020-4004
>= 15.0.0 and < 15.5.7
VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x b
8.2HIGH
CVE-2020-3995
>= 15.0.0 and < 15.1.0
In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x before 15.1.0), Fusion (11.x
5.3MEDIUM
CVE-2020-3982
>= 15.0 and <= 15.5.6
VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (1
7.7HIGH
CVE-2020-3981
>= 15.0.0 and <= 15.5.6
VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (1
5.8MEDIUM
CVE-2020-3971
>= 15.0.0 and < 15.0.2
VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201907101-SG), Workstation (15.x before 15.0.2), and Fusion (1
5.5MEDIUM
CVE-2020-3970
>= 15.0.0 and < 15.5.5
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstatio
3.8LOW
CVE-2020-3968
>= 15.0.0 and < 15.5.5
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstatio
8.2HIGH
CVE-2020-3967
>= 15.0.0 and < 15.5.5
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstatio
7.5HIGH
CVE-2020-3966
>= 15.0.0 and < 15.5.2
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstatio
7.5HIGH
CVE-2020-3965
>= 15.0.0 and < 15.5.2
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstatio
5.5MEDIUM
CVE-2020-3964
>= 15.0.0 and < 15.5.2
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstatio
4.7MEDIUM
CVE-2020-3963
>= 15.0.0 and < 15.5.2
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstatio
5.5MEDIUM
CVE-2020-3962
>= 15.0.0 and < 15.5.5
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstatio
8.2HIGH
CVE-2020-3969
>= 15.0.0 and < 15.5.5
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstatio
7.8HIGH
CVE-2020-3959
>= 15.0.0 and < 15.1.0
VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.1.0) and VMw
3.3LOW
CVE-2020-3958
>= 15.0.0 and < 15.5.2
VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.5.2) and VMw
5.5MEDIUM
CVE-2020-3951
>= 15.0.0 and < 15.5.2
VMware Workstation (15.x before 15.5.2) and Horizon Client for Windows (5.x and prior before 5.4.0) contain a denial-of-service vu
3.8LOW
CVE-2020-3948
>= 15.0.0 and < 15.5.2
Linux Guest VMs running on VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a local privilege escal
7.8HIGH
CVE-2020-3947
>= 15.0.0 and < 15.5.2
VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerability in vmnetdhcp. Successful
8.8HIGH
CVE-2019-5543
>= 15.0.0 and < 15.5.2
For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0.0), VMware
7.8HIGH
CVE-2019-5539
>= 15.0.0 and < 15.5.1
VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL h
7.8HIGH
CVE-2019-5098
all versions
An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.29010. A specially crafted
8.6HIGH
CVE-2019-5542
>= 15.0.0 and < 15.5.1
VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain a denial-of-service vulnerability in the RPC handl
7.7HIGH
CVE-2019-5541
>= 15.0.0 and < 15.5.1
VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in the e1000e
9.1CRITICAL
CVE-2019-5540
>= 15.0.0 and < 15.5.1
VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an information disclosure vulnerability in vmnetdh
7.7HIGH
CVE-2019-5536
>= 15.0.0 and < 15.5.0
VMware ESXi (6.7 before ESXi670-201908101-SG and 6.5 before ESXi650-201910401-SG), Workstation (15.x before 15.5.0) and Fusion (11
6.5MEDIUM
CVE-2019-5535
>= 15.0.0 and < 15.5.0
VMware Workstation and Fusion contain a network denial-of-service vulnerability due to improper handling of certain IPv6 packets.
4.7MEDIUM
CVE-2019-5527
>= 15.0.0 and < 15.5.0
ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has
8.8HIGH
CVE-2019-5521
>= 14.0.0 and < 14.1.6
VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14
9.6CRITICAL
CVE-2019-5525
>= 15.0.0 and < 15.1.0
VMware Workstation (15.x before 15.1.0) contains a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) ba
8.8HIGH
CVE-2019-5526
>= 15.0.0 and < 15.1.0
VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by the applica
7.8HIGH
CVE-2019-5520
>= 14.0.0 and < 14.1.6
VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14
5.9MEDIUM
CVE-2019-5517
>= 14.0.0 and < 14.1.6
VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14
6.8MEDIUM
CVE-2019-5516
>= 14.0.0 and < 14.1.6
VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14
6.8MEDIUM
CVE-2019-5512
>= 14.0.0 and < 14.1.6
VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle COM classes appropriately. Successf
8.8HIGH
CVE-2019-5511
>= 14.0.0 and < 14.1.6
VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle paths appropriately. Successful exp
8.8HIGH
CVE-2019-5524
>= 14.0.0 and < 14.1.6
VMware Workstation (14.x before 14.1.6) and Fusion (10.x before 10.1.6) contain an out-of-bounds write vulnerability in the e1000
8.8HIGH
CVE-2019-5515
>= 14.0.0 and < 14.1.6
VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) and Fusion (11.x before 11.0.3, 10.x before 10.1.6) updates address an
8.8HIGH
CVE-2019-5519
>= 14.0.0 and < 14.1.7
VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 1
6.8MEDIUM
CVE-2019-5518
>= 14.0.0 and < 14.1.7
VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 1
6.8MEDIUM
CVE-2018-6982
>= 14.0.0 and < 14.1.4
VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contain uninitialized stack memory u
6.5MEDIUM
CVE-2018-6981
>= 14.0.0 and < 14.1.4
VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMware ESXi 6.0 without ESXi600-201
8.8HIGH
CVE-2018-6983
>= 14.0.0 and < 14.1.5
VMware Workstation (15.x before 15.0.2 and 14.x before 14.1.5) and Fusion (11.x before 11.0.2 and 10.x before 10.1.5) contain an i
8.8HIGH
CVE-2018-6974
>= 14.0 and < 14.1.3
VMware ESXi (6.7 before ESXi670-201810101-SG, 6.5 before ESXi650-201808401-BG, and 6.0 before ESXi600-201808401-BG), Workstation (
8.8HIGH
CVE-2018-6977
>= 14.0.0 and <= 14.1.5
VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due
6.5MEDIUM
CVE-2018-6973
>= 14.0.0 and < 14.1.3
VMware Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds write vulnerability in the e1000
8.8HIGH
CVE-2018-6972
>= 14.0 and < 14.1.2
VMware ESXi (6.7 before ESXi670-201806401-BG, 6.5 before ESXi650-201806401-BG, 6.0 before ESXi600-201806401-BG and 5.5 before ESXi
6.5MEDIUM
CVE-2018-6967
>= 14.0 and < 14.1.2
VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of
8.1HIGH
CVE-2018-6966
>= 14.0 and < 14.1.2
VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of
8.1HIGH
CVE-2018-6965
>= 14.0 and < 14.1.2
VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of
8.1HIGH
CVE-2018-6963
>= 14.0 and < 14.1.2
VMware Workstation (14.x before 14.1.2) and Fusion (10.x before 10.1.2) contain multiple denial-of-service vulnerabilities that oc
5.5MEDIUM
CVE-2018-5511
all versions
On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User In
7.2HIGH
CVE-2017-4950
>= 12.0 and < 12.5.9
VMware Workstation and Fusion contain an integer overflow vulnerability in VMware NAT service when IPv6 mode is enabled. This issu
7.0HIGH
CVE-2017-4949
>= 12.0 and < 12.5.9
VMware Workstation and Fusion contain a use-after-free vulnerability in VMware NAT service when IPv6 mode is enabled. This issue m
7.0HIGH
CVE-2017-4948
all versions
VMware Workstation (14.x before 14.1.0 and 12.x) and Horizon View Client (4.x before 4.7.0) contain an out-of-bounds read vulnerab
7.1HIGH
CVE-2017-4945
all versions
VMware Workstation (14.x and 12.x) and Fusion (10.x and 8.x) contain a guest access control vulnerability. This issue may allow pr
5.5MEDIUM
CVE-2017-5753
>= 12.0.0 and < 12.5.8
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of informatio
5.6MEDIUM
CVE-2017-4941
>= 12.0.0 and < 12.5.8
VMware ESXi (6.0 before ESXi600-201711101-SG, 5.5 ESXi550-201709101-SG), Workstation (12.x before 12.5.8), and Fusion (8.x before
8.8HIGH
CVE-2017-4939
all versions
VMware Workstation (12.x before 12.5.8) installer contains a DLL hijacking issue that exists due to some DLL files loaded by the a
7.8HIGH
CVE-2017-4938
all versions
VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL pointer dereference vulnerability.
6.5MEDIUM
CVE-2017-4937
all versions
VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulne
7.8HIGH
CVE-2017-4936
all versions
VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulne
7.8HIGH
CVE-2017-4935
all versions
VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds write vuln
7.8HIGH
CVE-2017-4934
all versions
VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a heap buffer-overflow vulnerability in VMNAT device
8.8HIGH
CVE-2017-4925
>= 12.0.0 and < 12.5.3
VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-20
5.5MEDIUM
CVE-2017-4913
all versions
VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain an integer-overflow vulnerability i
7.8HIGH
CVE-2017-4912
all versions
VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnera
7.8HIGH
CVE-2017-4911
all versions
VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds write vulner
7.8HIGH
CVE-2017-4910
all versions
VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnera
7.8HIGH
CVE-2017-4909
all versions
VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain a heap buffer-overflow vulnerabilit
7.8HIGH
CVE-2017-4908
all versions
VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple heap buffer-overflow vulne
7.8HIGH
CVE-2017-4901
all versions
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-o
9.9CRITICAL
CVE-2016-2077
all versions
VMware Workstation 11.x before 11.1.3 and VMware Player 7.x before 7.1.3 on Windows incorrectly access an executable file, which a
9.8CRITICAL
CVE-2015-6933
all versions
The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2
6.3MEDIUM
CVE-2015-3650
all versions
vmware-vmx.exe in VMware Workstation 7.x through 10.x before 10.0.7 and 11.x before 11.1.1, VMware Player 5.x and 6.x before 6.0.7
CVE-2015-2341
all versions
VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.6, and VMware Fusion 6.x before 6.0.6 and 7.x before 7.0.1 all
CVE-2015-2340
all versions
TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, an
CVE-2015-2339
all versions
TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, a
CVE-2015-2338
all versions
TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, a
CVE-2015-2337
all versions
TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, an
CVE-2015-2336
all versions
TPView.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, a
CVE-2015-1044
all versions
vmware-authd (aka the Authorization process) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, and VMware
CVE-2015-1043
all versions
The Host Guest File System (HGFS) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, and VMware Fusion 6.x
CVE-2014-8370
all versions
VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, VMware Fusion 6.x before 6.0.5, and VMware ESXi 5.0 through
CVE-2014-4200
<= 10.0.3
vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, uses 0644 permissions f
CVE-2014-4199
<= 10.0.3
vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to w
CVE-2014-3793
all versions
VMware Tools in VMware Workstation 10.x before 10.0.2, VMware Player 6.x before 6.0.2, VMware Fusion 6.x before 6.0.3, and VMware
CVE-2014-2384
all versions
vmx86.sys in VMware Workstation 10.0.1 build 1379776 and VMware Player 6.0.1 build 1379776 on Windows might allow local users to c
CVE-2014-1208
all versions
VMware Workstation 9.x before 9.0.1, VMware Player 5.x before 5.0.1, VMware Fusion 5.x before 5.0.1, VMware ESXi 4.0 through 5.1,
CVE-2013-3519
all versions
lgtosync.sys in VMware Workstation 9.x before 9.0.3, VMware Player 5.x before 5.0.3, VMware Fusion 5.x before 5.0.4, VMware ESXi 4
CVE-2013-5972
all versions
VMware Workstation 9.x before 9.0.3 and VMware Player 5.x before 5.0.3 on Linux do not properly handle shared libraries, which all
CVE-2013-1662
all versions
vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS
CVE-2013-1406
all versions
The Virtual Machine Communication Interface (VMCI) implementation in vmci.sys in VMware Workstation 8.x before 8.0.5 and 9.x befor
CVE-2012-5459
all versions
Untrusted search path vulnerability in VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows allows ho
CVE-2012-5458
all versions
VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows use weak permissions for unspecified process thr
CVE-2012-3569
all versions
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x b
CVE-2012-1666
<= 8.0.3
Untrusted search path vulnerability in VMware Tools in VMware Workstation before 8.0.4, VMware Player before 4.0.4, VMware Fusion
CVE-2012-3289
all versions
VMware Workstation 8.x before 8.0.4, VMware Player 4.x before 4.0.4, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 a
CVE-2012-3288
all versions
VMware Workstation 7.x before 7.1.6 and 8.x before 8.0.4, VMware Player 3.x before 3.1.6 and 4.x before 4.0.4, VMware Fusion 4.x b
CVE-2012-2450
all versions
VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0,
CVE-2012-2449
all versions
VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x through 4.1.2, VMware ESXi 3.5 through 5.0,
CVE-2012-1518
all versions
VMware Workstation 8.x before 8.0.2, VMware Player 4.x before 4.0.2, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0,
CVE-2011-3868
all versions
Buffer overflow in VMware Workstation 7.x before 7.1.5, VMware Player 3.x before 3.1.5, VMware Fusion 3.1.x before 3.1.3, and VMwa
CVE-2011-2146
all versions
mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.
CVE-2011-2145
all versions
mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.
CVE-2011-1787
all versions
Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player
CVE-2011-1126
all versions
VMware vmrun, as used in VIX API 1.x before 1.10.3 and VMware Workstation 6.5.x and 7.x before 7.1.4 build 385536 on Linux, might
CVE-2010-4297
all versions
The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548; VMw
CVE-2010-4296
all versions
vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux,
CVE-2010-4295
all versions
Race condition in the mounting process in vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player
CVE-2010-4294
all versions
The frame decompression functionality in the VMnc media codec in VMware Movie Decoder before 6.5.5 build 328052 and 7.x before 7.1
CVE-2010-3277
all versions
The installer in VMware Workstation 7.x before 7.1.2 build 301548 and VMware Player 3.x before 3.1.2 build 301548 renders an index
CVE-2010-2249
>= 6.5.0 and < 6.5.5
Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (m
6.5MEDIUM
CVE-2010-1205
>= 6.5.0 and < 6.5.5
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow rem
9.8CRITICAL
CVE-2009-4811
all versions
VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 bu
CVE-2010-1142
all versions
VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.
CVE-2010-1141
all versions
VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.
CVE-2010-1140
all versions
The USB service in VMware Workstation 7.0 before 7.0.1 build 227600 and VMware Player 3.0 before 3.0.1 build 227600 on Windows mig
CVE-2010-1139
all versions
Format string vulnerability in vmrun in VMware VIX API 1.6.x, VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.
CVE-2010-1138
all versions
The virtual networking stack in VMware Workstation 7.0 before 7.0.1 build 227600, VMware Workstation 6.5.x before 6.5.4 build 2464
CVE-2009-3732
>= 6.5.0 and < 6.5.4
Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute
CVE-2009-1565
all versions
vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Wor
CVE-2009-1564
all versions
Heap-based buffer overflow in vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and t
CVE-2009-2267
all versions
VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 b
CVE-2009-3707
all versions
VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 bu
CVE-2009-2628
all versions
The VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 18
CVE-2009-0199
all versions
Heap-based buffer overflow in the VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstati
CVE-2009-1805
<= 6.5.1
Unspecified vulnerability in the VMware Descheduled Time Accounting driver in VMware Workstation 6.5.1 and earlier, VMware Player
CVE-2009-1244
<= 6.5.1
Unspecified vulnerability in the virtual machine display function in VMware Workstation 6.5.1 and earlier; VMware Player 2.5.1 and
CVE-2009-1147
all versions
Unspecified vulnerability in vmci.sys in the Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.5.1 and earlie
CVE-2009-1146
<= 6.5.1
Unspecified vulnerability in an ioctl in hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMwar
CVE-2009-0910
all versions
Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5
CVE-2009-0909
all versions
Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5
CVE-2008-4917
>= 5.5 and <= 5.5.8
Unspecified vulnerability in VMware Workstation 5.5.8 and earlier, and 6.0.5 and earlier 6.x versions; VMware Player 1.0.8 and ear
CVE-2008-4915
>= 5.5 and <= 5.5.8
The CPU hardware emulation in VMware Workstation 6.0.5 and earlier and 5.5.8 and earlier; Player 2.0.x through 2.0.5 and 1.0.x thr
CVE-2008-4279
>= 5.5 and < 5.5.8
The CPU hardware emulation for 64-bit guest operating systems in VMware Workstation 6.0.x before 6.0.5 build 109488 and 5.x before
CVE-2008-3892
>= 5.5 and < 5.5.8
Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstat
CVE-2008-3698
>= 5.5 and < 5.5.8
Unspecified vulnerability in the OpenProcess function in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.
CVE-2008-3696
>= 5.5 and < 5.5.8
Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6
CVE-2008-3695
>= 5.5 and < 5.5.8
Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6
CVE-2008-3694
>= 5.5 and < 5.5.8
Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6
CVE-2008-3693
>= 5.5 and < 5.5.8
Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6
CVE-2008-3692
>= 5.5 and < 5.5.8
Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6
CVE-2008-3691
>= 5.5 and < 5.5.8
Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6
CVE-2008-2100
>= 5.5 and <= 5.5.6
Multiple buffer overflows in VIX API 1.1.x before 1.1.4 build 93057 on VMware Workstation 5.x and 6.x, VMware Player 1.x and 2.x,
CVE-2008-0967
all versions
Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build
CVE-2007-5671
all versions
HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Player before 1.0.6 build 80404, V
CVE-2008-2099
all versions
Unspecified vulnerability in VMCI in VMware Workstation 6 before 6.0.4 build 93057, VMware Player 2 before 2.0.4 build 93057, and
CVE-2008-2098
all versions
Heap-based buffer overflow in the VMware Host Guest File System (HGFS) in VMware Workstation 6 before 6.0.4 build 93057, VMware Pl
CVE-2008-1364
all versions
Unspecified vulnerability in the DHCP service in VMware Workstation 5.5.x before 5.5.6, VMware Player 1.0.x before 1.0.6, VMware A
CVE-2008-1363
>= 5.5 and < 5.5.6
VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE
CVE-2008-1362
all versions
VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE
CVE-2008-1361
all versions
VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE
CVE-2008-1340
all versions
Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.0.x before 6.0.3, VMware Player 2.0.x before 2.0.3, and VMw
CVE-2008-0923
all versions
Directory traversal vulnerability in the Shared Folders feature for VMWare ACE 1.0.2 and 2.0.2, Player 1.0.4 and 2.0.2, and Workst
CVE-2007-5618
>= 5.5 and < 5.5.5
Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player 1.0.x before 1.0.5 and 2.0 bef
CVE-2007-5617
>= 5.5 and < 5.5.5
Unspecified vulnerability in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, and Workstation 5.x before 5.5.5 and 6.x befor
CVE-2007-5023
>= 5 and <= 5.5.5
Unquoted Windows search path vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Pl
CVE-2007-4497
>= 5 and <= 5.5.5
Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5
CVE-2007-4496
>= 5 and <= 5.5.5
Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5
CVE-2007-0063
>= 5.5 and < 5.5.5
Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player b
CVE-2007-0062
all versions
Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before
CVE-2007-0061
>= 5.5 and < 5.5.5
The DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 564
CVE-2007-4593
all versions
Unspecified vulnerability in vstor2-ws60.sys in VMWare Workstation 6.0 allows local users to cause a denial of service (host opera
CVE-2007-4591
all versions
vstor-ws60.sys in VMWare Workstation 6.0 allows local users to cause a denial of service (host operating system crash) and possibl
CVE-2007-4059
all versions
Absolute path traversal vulnerability in a certain ActiveX control in IntraProcessLogging.dll 5.5.3.42958 in EMC VMware allows rem
CVE-2007-2491
all versions
The PIIX4 power management subsystem in EMC VMware Workstation 5.5.3.34685 and VMware Server 1.0.1.29996 allows local users to wri
CVE-2007-1877
<= 5.5.3
VMware Workstation before 5.5.4 allows attackers to cause a denial of service against the guest OS by causing the virtual machine
CVE-2007-1876
<= 5.5.3
VMware Workstation before 5.5.4, when running a 64-bit Windows guest on a 64-bit host, allows local users to "corrupt the virtual
CVE-2007-1744
<= 5.5.3
Directory traversal vulnerability in the Shared Folders feature for VMware Workstation before 5.5.4, when a folder is shared, allo
CVE-2007-1337
<= 5.5.3
The virtual machine process (VMX) in VMware Workstation before 5.5.4 does not properly read state information when moving from the
CVE-2007-1069
<= 5.5.3
The memory management in VMware Workstation before 5.5.4 allows attackers to cause a denial of service (Windows virtual machine cr
CVE-2007-1056
all versions
VMware Workstation 5.5.3 build 34685 does not provide per-user restrictions on certain privileged actions, which allows local user
CVE-2007-0833
all versions
VMware Workstation 5.5.3 34685, when the "Enable copy and paste to and from this virtual machine" option is enabled, preserves cli
CVE-2007-0832
all versions
VMware Workstation 5.5.3 34685 does not immediately change the availability of a shared clipboard when the "Enable copy and paste
CVE-2006-6410
all versions
Buffer overflow in an ActiveX control in VMWare 5.5.1 allows local users to execute arbitrary code via a long VmdbDb parameter to
CVE-2006-3589
all versions
vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod functi
CVE-2005-4459
all versions
Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, AC
CVE-2005-2939
all versions
Unquoted Windows search path vulnerability in VMWare Workstation 5.0.0 build-13124 might allow local users to gain privileges via
CVE-2005-0444
<= 4.5.2_build_8848
VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the rrdharan world-writable tempor
CVE-2004-2515
all versions
Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privileges, might allow local users t
CVE-2003-0739
<= 4.0.1_build_5289
VMware Workstation 4.0.1 for Linux, build 5289 and earlier, allows local users to delete arbitrary files via a symlink attack.
CVE-2003-0631
all versions
VMware GSX Server 2.5.1 build 4968 and earlier, and Workstation 4.0 and earlier, allows local users to gain root privileges via ce
CVE-2003-0480
all versions
VMware Workstation 4.0 for Linux allows local users to overwrite arbitrary files and gain privileges via "symlink manipulation."
CVE-2001-1059
all versions
VMWare creates a temporary file vmware-log.USERNAME with insecure permissions, which allows local users to read or modify license
CVE-2000-0090
all versions
VMWare 1.1.2 allows local users to cause a denial of service via a symlink attack.
CVE-1999-0733
all versions
Buffer overflow in VMWare 1.0.1 for Linux via a long HOME environmental variable.
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin