Known vulnerabilities in VMware Tanzu Application Service for VMs - page 16

Vendor: Broadcom
Software CPE: cpe:2.3:a:broadcom:vmware_tanzu_application_service_for_vms:*:*:*:*:*:*:*:*
Total vulnerabilities: 483
Public exploits: 18
Known exploited (KEV): 6
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting VMware Tanzu Application Service for VMs VMware Tanzu Application Service for VMs is affected by 483 known vulnerabilities: 5 critical, 112 high, 201 medium, 165 low Critical High Medium Low

Vulnerabilities (483)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU74149 - Security Features
CVE-2023-0466
CWE-254 Low
No
No
- 28.03.2023 SB2023032241
SB2023040666
SB2023040730
and 86 more
#VU74148 - Improper Verification of Cryptographic Signature
CVE-2023-0465
CWE-347 Low
No
No
- 28.03.2023 SB2023032241
SB2023040666
SB2023040730
and 100 more
#VU73960 - Resource exhaustion
CVE-2023-0464
CWE-400 Medium
No
No
- 22.03.2023 SB2023032241
SB2023033057
SB2023033058
and 100 more
#VU72246 - Improper Link Resolution Before File Access ('Link Following')
CVE-2023-22490
CWE-59 Low
No
No
2.11.36, 2.12.25, 2.13.18, 3.0.8, 4.0.0 15.02.2023 SB2023021529
SB2023021528
SB2023021533
and 31 more
#VU72125 - Inadequate Encryption Strength
CVE-2023-0361
CWE-326 Medium
No
No
- 11.02.2023 SB2023021103
SB2023021109
SB2023021561
and 88 more
#VU72088 - Out-of-bounds read
CVE-2022-41862
CWE-125 Medium
No
No
3.0.8, 4.0.0 09.02.2023 SB2023020953
SB2023021334
SB2023021335
and 47 more
#VU71995 - Use After Free
CVE-2023-0215
CWE-416 Medium
No
No
2.11.35, 2.12.24, 2.13.17, 3.0.7, 4.0.0 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 209 more
#VU71992 - Type confusion
CVE-2023-0286
CWE-843 High
No
No
2.11.35, 2.12.24, 2.13.17, 3.0.7, 4.0.0 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 223 more
#VU71560 - Heap-based Buffer Overflow
CVE-2023-0288
CWE-122 High
No
No
- 26.01.2023 SB2023012622
SB2023013071
SB2023013073
and 15 more
#VU71559 - NULL Pointer Dereference
CVE-2022-47024
CWE-476 Low
No
No
- 26.01.2023 SB2023012623
SB2023013121
SB2023022848
and 16 more
#VU71558 - Heap-based Buffer Overflow
CVE-2023-0433
CWE-122 High
No
No
- 26.01.2023 SB2023012624
SB2023012627
SB2023013071
and 21 more
#VU70723 - Out-of-bounds write
CVE-2023-0054
CWE-787 High
No
No
- 05.01.2023 SB2023010521
SB2023013071
SB2023013073
and 16 more
#VU70721 - Out-of-bounds read
CVE-2023-0049
CWE-125 Low
No
No
- 05.01.2023 SB2023010521
SB2023010522
SB2023013071
and 18 more
#VU70457 - Security Features
CVE-2022-43551
CWE-254 Medium
No
No
2.11.33, 2.12.22, 2.13.15, 3.0.7 21.12.2022 SB2022122102
SB2022122620
SB2023010612
and 32 more
#VU70456 - Use After Free
CVE-2022-43552
CWE-416 Low
No
No
2.11.33, 2.12.22, 2.13.15, 3.0.7 21.12.2022 SB2022122102
SB2022122620
SB2022122621
and 66 more
#VU70142 - Improper Locking
CVE-2022-3996
CWE-667 Low
No
No
- 13.12.2022 SB2022121328
SB2022122614
SB2023011834
and 12 more
#VU68517 - Improper input validation
CVE-2022-39253
CWE-20 Low
Available
No
2.11.36, 2.12.25, 2.13.18, 3.0.8, 4.0.0 19.10.2022 SB2022101995
SB2022101996
SB2022101997
and 41 more
#VU55149 - Use of Uninitialized Variable
CVE-2021-22925
CWE-457 Medium
No
No
- 21.07.2021 SB2021072108
SB2021072162
SB2021072202
and 38 more
#VU53587 - Use of Uninitialized Variable
CVE-2021-22898
CWE-457 Medium
No
No
- 26.05.2021 SB2021052620
SB2021052711
SB2021060128
and 47 more
#VU12267 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2017-11671
CWE-338 Low
No
No
- 27.04.2018 SB2017032501
SB2018041052
SB2022120851
and 2 more


Showing elements 301 - 320 out of 483