Known vulnerabilities in VMware Tanzu Application Service for VMs - page 21

Vendor: Broadcom
Software CPE: cpe:2.3:a:broadcom:vmware_tanzu_application_service_for_vms:*:*:*:*:*:*:*:*
Total vulnerabilities: 483
Public exploits: 18
Known exploited (KEV): 6
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting VMware Tanzu Application Service for VMs VMware Tanzu Application Service for VMs is affected by 483 known vulnerabilities: 5 critical, 112 high, 201 medium, 165 low Critical High Medium Low

Vulnerabilities (483)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU64685 - Improper Verification of Cryptographic Signature
CVE-2022-32208
CWE-347 Medium
No
No
2.7.52, 2.10.34, 2.11.22, 2.12.16, 2.13.7 27.06.2022 SB2022062711
SB2022062724
SB2022062816
and 73 more
#VU64684 - Incorrect Default Permissions
CVE-2022-32207
CWE-276 Low
No
No
2.7.52, 2.10.34, 2.11.22, 2.12.16, 2.13.7 27.06.2022 SB2022062711
SB2022062724
SB2022062816
and 35 more
#VU64682 - Resource exhaustion
CVE-2022-32206
CWE-400 Medium
No
No
2.7.52, 2.10.34, 2.11.22, 2.12.16, 2.13.7 27.06.2022 SB2022062711
SB2022062724
SB2022062816
and 80 more
#VU64681 - Resource exhaustion
CVE-2022-32205
CWE-400 Medium
No
No
2.7.52, 2.10.34, 2.11.22, 2.12.16, 2.13.7 27.06.2022 SB2022062711
SB2022062724
SB2022062816
and 32 more
#VU64464 - Missing release of memory after effective lifetime
CVE-2016-5011
CWE-401 Low
No
No
- 17.06.2022 SB2022061729
SB2022080146
#VU63058 - Use After Free
CVE-2021-3974
CWE-416 High
No
No
- 11.05.2022 SB2022051173
SB2022052327
SB2022012777
and 21 more
#VU63051 - Heap-based Buffer Overflow
CVE-2021-3973
CWE-122 High
No
No
- 11.05.2022 SB2022051173
SB2022052327
SB2022012777
and 21 more
#VU62002 - Improper input validation
CVE-2022-1271
CWE-20 High
No
No
2.7.49, 2.10.31, 2.11.19, 2.12.12, 2.13.4 08.04.2022 SB2022040803
SB2022040804
SB2022040822
and 134 more
#VU20060 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2019-11922
CWE-362 Medium
No
No
- 12.08.2019 SB2019081211
SB2019072506
SB2019081905
and 5 more
#VU12201 - Improper input validation
CVE-2017-13734
CWE-20 Low
No
No
- 26.04.2018 SB2018041708
SB2017100328
SB2022052624
and 1 more
#VU12200 - Improper input validation
CVE-2017-13733
CWE-20 Low
No
No
- 26.04.2018 SB2018041708
SB2017120121
SB2017100327
and 4 more
#VU12199 - Improper input validation
CVE-2017-13732
CWE-20 Low
No
No
- 26.04.2018 SB2018041708
SB2017120121
SB2017100326
and 2 more
#VU12198 - Improper input validation
CVE-2017-13731
CWE-20 Low
No
No
- 26.04.2018 SB2018041708
SB2017120121
SB2017100325
and 2 more
#VU12197 - Improper input validation
CVE-2017-13730
CWE-20 Low
No
No
- 26.04.2018 SB2018041708
SB2017120121
SB2017100324
and 2 more
#VU12196 - Improper input validation
CVE-2017-13729
CWE-20 Low
No
No
- 26.04.2018 SB2018041708
SB2017120121
SB2017100323
and 2 more
#VU12195 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2017-13728
CWE-835 Low
No
No
- 26.04.2018 SB2018041708
SB2017120121
SB2017100322
and 2 more
#VU12193 - NULL Pointer Dereference
CVE-2017-11113
CWE-476 Low
No
No
- 26.04.2018 SB2018041708
SB2017100321
SB2022052624
and 1 more
#VU12191 - Improper input validation
CVE-2017-11112
CWE-20 Low
No
No
- 26.04.2018 SB2018041708
SB2017100320
SB2022052624
and 1 more
#VU12190 - Use of Externally-Controlled Format String
CVE-2017-10685
CWE-134 High
No
No
- 26.04.2018 SB2017071502
SB2017070709
SB2017070623
and 5 more
#VU12110 - Stack-based buffer overflow
CVE-2017-10684
CWE-121 High
No
No
- 20.04.2018 SB2017070103
SB2017071502
SB2017070709
and 6 more


Showing elements 401 - 420 out of 483