Lucene search

K
cve[email protected]CVE-2008-2100
HistoryJun 05, 2008 - 8:32 p.m.

CVE-2008-2100

2008-06-0520:32:00
CWE-119
web.nvd.nist.gov
1391
cve-2008-2100
vix api
buffer overflow
vmware workstation
vmware player
vmware ace
vmware server
vmware fusion
vmware esxi
vmware esx
arbitrary code execution
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.9%

Multiple buffer overflows in VIX API 1.1.x before 1.1.4 build 93057 on VMware Workstation 5.x and 6.x, VMware Player 1.x and 2.x, VMware ACE 2.x, VMware Server 1.x, VMware Fusion 1.x, VMware ESXi 3.5, and VMware ESX 3.0.1 through 3.5 allow guest OS users to execute arbitrary code on the host OS via unspecified vectors.

Affected configurations

NVD
Node
vmwareaceRange1.01.0.5
OR
vmwareaceRange2.02.0.3
OR
vmwareesx_serverMatch3.0
OR
vmwareesx_serverMatch3.5
OR
vmwareesxiMatch3.5
OR
vmwarefusionRange1.1.1
OR
vmwareplayerRange1.0.01.0.6
OR
vmwareplayerRange2.02.0.3
OR
vmwareserverRange1.0.5
OR
vmwareworkstationRange5.55.5.6
OR
vmwareworkstationRange6.06.0.3
OR
vmwareesxMatch2.5.4
OR
vmwareesxMatch2.5.5
OR
vmwareesxMatch3.0.0
OR
vmwareesxMatch3.0.1
OR
vmwareesxMatch3.0.2
OR
vmwareesxMatch3.5

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.9%