Known vulnerabilities in VMware Tanzu Application Service for VMs - page 23

Vendor: Broadcom
Software CPE: cpe:2.3:a:broadcom:vmware_tanzu_application_service_for_vms:*:*:*:*:*:*:*:*
Total vulnerabilities: 483
Public exploits: 18
Known exploited (KEV): 6
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting VMware Tanzu Application Service for VMs VMware Tanzu Application Service for VMs is affected by 483 known vulnerabilities: 5 critical, 112 high, 201 medium, 165 low Critical High Medium Low

Vulnerabilities (483)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU63055 - Unchecked Return Value
CVE-2019-9704
CWE-252 Low
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13 11.05.2022 SB2022051133
SB2022051206
SB2022051207
and 7 more
#VU63054 - Allocation of Resources Without Limits or Throttling
CVE-2019-9705
CWE-770 Low
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13 11.05.2022 SB2022051133
SB2022051206
SB2022051207
and 7 more
#VU63053 - Use After Free
CVE-2019-9706
CWE-416 Low
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13 11.05.2022 SB2022051133
SB2022051206
SB2022051207
and 3 more
#VU62883 - Use After Free
CVE-2020-35512
CWE-416 Low
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13 09.05.2022 SB2021021526
SB2022050921
SB2022051206
and 11 more
#VU62378 - Integer overflow
CVE-2021-31873
CWE-190 High
No
No
- 19.04.2022 SB2021043022
SB2022041906
SB2022041922
and 2 more
#VU62377 - Integer overflow
CVE-2021-31872
CWE-190 High
No
No
- 19.04.2022 SB2021043022
SB2022041906
SB2022041922
and 2 more
#VU62021 - Improper input validation
CVE-2022-25310
CWE-20 High
No
No
2.7.49, 2.10.31, 2.11.19, 2.12.12 08.04.2022 SB2022040808
SB2022040809
SB2022040820
and 30 more
#VU62020 - Heap-based Buffer Overflow
CVE-2022-25309
CWE-122 High
No
No
2.7.49, 2.10.31, 2.11.19, 2.12.12 08.04.2022 SB2022040808
SB2022040809
SB2022040820
and 30 more
#VU62019 - Stack-based buffer overflow
CVE-2022-25308
CWE-121 High
No
No
2.7.49, 2.10.31, 2.11.19, 2.12.12 08.04.2022 SB2022040808
SB2022040809
SB2022040820
and 30 more
#VU61756 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-22965
CWE-94 Critical
Available
Exploited
2.10.29, 2.11.17, 2.12.10, 2.13.1 31.03.2022 SB2022033109
SB2022040109
SB2022040110
and 78 more
#VU61672 - Heap-based Buffer Overflow
CVE-2022-27666
CWE-122 Low
Available
No
- 29.03.2022 SB2022032901
SB2022032902
SB2022033118
and 66 more
#VU58816 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44228
CWE-94 Critical
Available
Exploited
2.7.42, 2.10.22, 2.11.10, 2.12.3 10.12.2021 SB2021121003
SB2021121101
SB2021121201
and 338 more
#VU51741 - Improper Handling of Exceptional Conditions
CVE-2021-28831
CWE-755 Medium
No
No
2.11.46, 2.13.28, 3.0.18, 4.0.10 26.03.2021 SB2021032622
SB2021032626
SB2021032627
and 25 more
#VU48587 - Allocation of Resources Without Limits or Throttling
CVE-2020-8037
CWE-770 Medium
No
No
2.7.49, 2.10.31, 2.11.19, 2.12.12 04.11.2020 SB2020110433
SB2020112103
SB2021042704
and 12 more
#VU21949 - Out-of-bounds read
CVE-2018-16301
CWE-125 Low
No
No
2.7.49, 2.10.31, 2.11.19, 2.12.12 21.10.2019 SB2019102102
SB2019102103
SB2019100318
and 23 more
#VU19572 - Improper input validation
CVE-2019-1010204
CWE-20 Low
No
No
- 31.07.2019 SB2019022402
SB2020042840
SB2022032836
and 7 more
#VU18290 - Improper input validation
CVE-2018-1000654
CWE-20 Low
No
No
- 17.04.2019 SB2018082017
SB2019060302
SB2019060502
and 6 more
#VU15935 - NULL Pointer Dereference
CVE-2018-19211
CWE-476 Low
No
No
- 17.11.2018 SB2018111702
SB2018121002
SB2018121009
and 2 more
#VU12202 - Stack-based buffer overflow
CVE-2017-16879
CWE-121 High
No
No
- 26.04.2018 SB2018041708
SB2017120121
SB2018012328
and 2 more
#VU7010 - Permissions, Privileges, and Access Controls
CVE-2017-9525
CWE-264 Low
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13 12.06.2017 SB2017061204
SB2017061209
SB2022051133
and 5 more


Showing elements 441 - 460 out of 483