Known vulnerabilities in VMware Tanzu Application Service for VMs

Vendor: Broadcom
Software CPE: cpe:2.3:a:broadcom:vmware_tanzu_application_service_for_vms:*:*:*:*:*:*:*:*
Total vulnerabilities: 483
Public exploits: 18
Known exploited (KEV): 6
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting VMware Tanzu Application Service for VMs VMware Tanzu Application Service for VMs is affected by 483 known vulnerabilities: 5 critical, 112 high, 201 medium, 165 low Critical High Medium Low

Vulnerabilities (483)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU83863 - Resource exhaustion
CVE-2022-48063
CWE-400 Low
No
No
3.0.19, 4.0.11 05.12.2023 SB2023052341
SB2023120507
SB2023120511
and 9 more
#VU83862 - Missing release of memory after effective lifetime
CVE-2022-47011
CWE-401 Low
No
No
3.0.19, 4.0.11 05.12.2023 SB2023120506
SB2023120507
SB2023120511
and 4 more
#VU83861 - Missing release of memory after effective lifetime
CVE-2022-47010
CWE-401 Low
No
No
3.0.19, 4.0.11 05.12.2023 SB2023120506
SB2023120507
SB2023120511
and 3 more
#VU83860 - Missing release of memory after effective lifetime
CVE-2022-47008
CWE-401 Low
No
No
3.0.19, 4.0.11 05.12.2023 SB2023120506
SB2023120507
SB2023120511
and 4 more
#VU83859 - Missing release of memory after effective lifetime
CVE-2022-47007
CWE-401 Low
No
No
3.0.19, 4.0.11 05.12.2023 SB2023120506
SB2023120507
SB2023120511
and 3 more
#VU83858 - Reachable Assertion
CVE-2022-35205
CWE-617 Low
No
No
3.0.19, 4.0.11 05.12.2023 SB2023120506
SB2023120507
SB2023120511
and 8 more
#VU83856 - Integer overflow
CVE-2021-28429
CWE-190 Low
No
No
2.11.48, 2.13.30, 3.0.20, 4.0.12 05.12.2023 SB2021052656
SB2023120501
SB2023120508
and 5 more
#VU83855 - Missing release of memory after effective lifetime
CVE-2020-22051
CWE-401 Medium
No
No
2.11.48, 2.13.30, 3.0.20, 4.0.12 05.12.2023 SB2021052656
SB2023120501
SB2023120508
#VU83854 - Missing release of memory after effective lifetime
CVE-2020-22043
CWE-401 Medium
No
No
2.11.48, 2.13.30, 3.0.20, 4.0.12 05.12.2023 SB2021052656
SB2023120501
SB2023120508
#VU83853 - Missing release of memory after effective lifetime
CVE-2020-22040
CWE-401 Medium
No
No
2.11.48, 2.13.30, 3.0.20, 4.0.12 05.12.2023 SB2021052656
SB2023120501
SB2023120508
#VU83852 - Missing release of memory after effective lifetime
CVE-2020-22039
CWE-401 Medium
No
No
2.11.48, 2.13.30, 3.0.20, 4.0.12 05.12.2023 SB2021052656
SB2023120501
SB2023120508
#VU83851 - Memory corruption
CVE-2020-22024
CWE-119 Medium
No
No
2.11.48, 2.13.30, 3.0.20, 4.0.12 05.12.2023 SB2021052656
SB2023120501
SB2023120508
#VU82351 - Sequence of Processor Instructions Leads to Unexpected Behavior
CVE-2023-23583
CWE-1281 Low
No
No
- 24.10.2023 SB2023102457
SB2023111435
SB2023111436
and 34 more
#VU81863 - External Control of File Name or Path
CVE-2023-38546
CWE-73 Low
No
No
3.0.19, 4.0.11 11.10.2023 SB2023101129
SB2023101135
SB2023101149
and 125 more
#VU81244 - Heap-based Buffer Overflow
CVE-2023-5217
CWE-122 Critical
Available
Exploited
2.11.48, 2.13.30, 3.0.18, 3.0.20, 4.0.10, 4.0.12 27.09.2023 SB2023092804
SB2023092847
SB2023092851
and 101 more
#VU78419 - Improper input validation
CVE-2023-22053
CWE-20 Medium
No
No
2.3.3, 2.4.0, 2.5.0, 2.6.0, 2.7.0, 2.8.0, 2.9.0, 2.10.0, 2.11.0, 2.12.0, 2.13.0, 3.0.0, 4.0.0 19.07.2023 SB2023071997
SB2023081543
SB2023090754
and 18 more
#VU16828 - Heap-based Buffer Overflow
CVE-2018-20671
CWE-190 Low
No
No
3.0.19, 4.0.11 07.01.2019 SB2018123105
SB2023120507
SB2023120511
and 1 more
#VU10366 - Integer overflow
CVE-2018-6543
CWE-190 Low
No
No
3.0.19, 4.0.11 05.02.2018 SB2018020504
SB2019081104
SB2018112746
and 2 more
#VU37859 - Heap-based Buffer Overflow
CVE-2017-17122
CWE-122 Medium
No
No
3.0.19, 4.0.11 04.12.2017 SB2017111521
SB2018112746
SB2022032315
and 2 more
#VU39082 - Improper input validation
CVE-2017-8421
CWE-20 Medium
No
No
3.0.19, 4.0.11 02.05.2017 SB2017031704
SB2017091709
SB2023120507
and 1 more


Showing elements 1 - 20 out of 483