The OVAL Repository5.102015-09-03T11:13:53.208-04:00VMware ESX Openwsman Lets Local Users Gain Root PrivilegesVMWare ESX Server 3VMWare ESX Server 2Buffer overflow in the openwsman management service in VMware ESXi 3.5 and ESX 3.5 allows remote authenticated users to gain privileges via an "invalid Content-Length."Michael WoodDRAFTINTERIMACCEPTEDJ. Daniel BrownINTERIMACCEPTEDACCEPTEDVMware Tools Input Validation Flaw in Windows Guest OS Lets Local Users Gain Elevated PrivilegesVMWare ESX Server 3VMWare ESX Server 2HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Player before 1.0.6 build 80404, VMware ACE before 1.0.5 build 79846, VMware Server before 1.0.5 build 80187, and VMware ESX 2.5.4 through 3.0.2 does not properly validate arguments in user-mode METHOD_NEITHER IOCTLs to the \\.\hgfs device, which allows guest OS users to modify arbitrary memory locations in guest kernel memory and gain privileges.Michael WoodDRAFTINTERIMACCEPTEDJ. Daniel BrownINTERIMACCEPTEDACCEPTEDVMware Buffer Overflows in VIX API Let Local Users Execute Arbitrary CodeVMWare ESX Server 3VMWare ESX Server 2Multiple buffer overflows in VIX API 1.1.x before 1.1.4 build 93057 on VMware Workstation 5.x and 6.x, VMware Player 1.x and 2.x, VMware ACE 2.x, VMware Server 1.x, VMware Fusion 1.x, VMware ESXi 3.5, and VMware ESX 3.0.1 through 3.5 allow guest OS users to execute arbitrary code on the host OS via unspecified vectors.Michael WoodDRAFTINTERIMACCEPTEDJ. Daniel BrownINTERIMACCEPTEDACCEPTEDVMware ESX Openwsman Lets Local Users Gain Root PrivilegesVMWare ESX Server 3VMWare ESX Server 2Buffer overflow in the openwsman management service in VMware ESXi 3.5 and ESX 3.5 allows remote authenticated users to gain privileges via an "invalid Content-Length."Michael WoodDRAFTINTERIMACCEPTEDJ. Daniel BrownINTERIMACCEPTEDACCEPTEDVMware Unsafe Library Path in vmware-authd Lets Local Users Gain Elevated PrivilegesVMWare ESX Server 3VMWare ESX Server 2Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware Player 1.x before 1.0.7 build 91707 and 2.x before 2.0.4 build 93057, and VMware Server before 1.0.6 build 91891 on Linux, and VMware ESXi 3.5 and VMware ESX 2.5.4 through 3.5, allows local users to gain privileges via a library path option in a configuration file.Michael WoodDRAFTINTERIMACCEPTEDJ. Daniel BrownINTERIMACCEPTEDACCEPTEDVMware Tools Input Validation Flaw in Windows Guest OS Lets Local Users Gain Elevated PrivilegesVMWare ESX Server 3VMWare ESX Server 2HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Player before 1.0.6 build 80404, VMware ACE before 1.0.5 build 79846, VMware Server before 1.0.5 build 80187, and VMware ESX 2.5.4 through 3.0.2 does not properly validate arguments in user-mode METHOD_NEITHER IOCTLs to the \\.\hgfs device, which allows guest OS users to modify arbitrary memory locations in guest kernel memory and gain privileges.Michael WoodDRAFTINTERIMACCEPTEDJ. Daniel BrownINTERIMACCEPTEDACCEPTEDVMware Buffer Overflows in VIX API Let Local Users Execute Arbitrary CodeVMWare ESX Server 3VMWare ESX Server 2Multiple buffer overflows in VIX API 1.1.x before 1.1.4 build 93057 on VMware Workstation 5.x and 6.x, VMware Player 1.x and 2.x, VMware ACE 2.x, VMware Server 1.x, VMware Fusion 1.x, VMware ESXi 3.5, and VMware ESX 3.0.1 through 3.5 allow guest OS users to execute arbitrary code on the host OS via unspecified vectors.Michael WoodDRAFTINTERIMACCEPTEDJ. Daniel BrownINTERIMACCEPTEDACCEPTEDVMware Unsafe Library Path in vmware-authd Lets Local Users Gain Elevated PrivilegesVMWare ESX Server 3VMWare ESX Server 2Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware Player 1.x before 1.0.7 build 91707 and 2.x before 2.0.4 build 93057, and VMware Server before 1.0.6 build 91891 on Linux, and VMware ESXi 3.5 and VMware ESX 2.5.4 through 3.5, allows local users to gain privileges via a library path option in a configuration file.Michael WoodDRAFTINTERIMACCEPTEDJonathan BakerINTERIMACCEPTEDACCEPTEDVMWare ESX Server 3.0.2 is installedVMWare ESX Server 3The operating system installed on the system is VMWare ESX Server 3.0.2.Yuzheng ZhouDRAFTINTERIMACCEPTEDDavid RothenbergINTERIMACCEPTEDACCEPTEDVMWare ESX Server 3.0.1 is installedVMWare ESX Server 3The operating system installed on the system is VMWare ESX Server 3.0.1.Yuzheng ZhouDRAFTINTERIMACCEPTEDDavid RothenbergINTERIMACCEPTEDACCEPTED100472610041869052110042191004723100472810047211004821100472410047251004216905201004190100472210047191004727100418910047281004721100472710041861004725100419090520100472410042191004216905211004722100471910047261004723100418910048211004189100419010048211004186100472390520100472610047271004722100472510042191004216100472810047191004721905211004724100472410047251004727100421910042161004723100472190520100482110041861004189100472810041909052110047191004726100472290521100482110041901004728100472110047271004219100472410047261004186100472310047221004216100472590520100471910041892.5.4322332.5.5576192.5.5576192.5.4322332.5.4322332.5.5576192.5.5576192.5.4322333.0.23.0.12.5.5576192.5.432233