Known vulnerabilities in VMware Horizon Client - page 6
Vendor:
VMware, Inc
Software:
VMware Horizon Client
Software CPE:
cpe:2.3:a:vmware:vmware_horizon_client:*:*:*:*:*:*:*:*
Website:
https://www.vmware.com
Total vulnerabilities:
166
Public exploits:
12
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
3.2.1
3.4.0
2312.1.8.12.1.5 on Thin OS 2405
2309.8.11.0.22660930.37 on Thin OS 2402
2312
2309
2306
2303
2212
2209
2206
2111
2203
5.5.3
5.5
2106
5.5.1
5.5.2
2103
2012
5.5.0
5.4.4
2006
5.4.2
5.4.1
5.4.3
5.4
5.3
5.2
5.1
5.0
4.10
4.9
4.8
4.7
4.6
4.5
4.4
4.3
4.2
4.1
3.0.0
4.0.0
4.1.0
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.8.0
4.9.0
4.10.0
5.0.0
5.1.0
5.2.0
Vulnerabilities (166)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU92115 - Improper Handling of Length Parameter Inconsistency CVE-2023-43114 |
CWE-130 | Medium | 2312.1.8.12.1.5 on Thin OS 2405 | 14.06.2024 |
SB2024061410 SB2023120199 SB20231201100 and 5 more |
||
| #VU85067 - Integer overflow CVE-2023-51714 |
CWE-190 | High | 2312.1.8.12.1.5 on Thin OS 2405 | 08.01.2024 |
SB2024010825 SB2024010826 SB2024011838 and 13 more |
||
| #VU79632 - Memory corruption CVE-2023-37369 |
CWE-119 | Medium | 2312.1.8.12.1.5 on Thin OS 2405 | 16.08.2023 |
SB2023072654 SB20230821210 SB20230821234 and 29 more |
||
| #VU79310 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2022-25634 |
CWE-22 | Medium | 2312.1.8.12.1.5 on Thin OS 2405 | 09.08.2023 |
SB2023080946 SB2023080947 SB2024031127 and 3 more |
||
| #VU78697 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2023-38197 |
CWE-835 | Medium | 2312.1.8.12.1.5 on Thin OS 2405 | 26.07.2023 |
SB2023072654 SB2023072656 SB2023072657 and 31 more |
||
| #VU78696 - Improper Certificate Validation CVE-2023-34410 |
CWE-295 | Medium | 2312.1.8.12.1.5 on Thin OS 2405 | 26.07.2023 |
SB2023072654 SB2023072656 SB2023072657 and 28 more |
||
| #VU76668 - Memory corruption CVE-2023-32763 |
CWE-119 | High | 2312.1.8.12.1.5 on Thin OS 2405 | 30.05.2023 |
SB2023053068 SB2023070436 SB2023071741 and 17 more |
||
| #VU76667 - Out-of-bounds read CVE-2023-33285 |
CWE-125 | Medium | 2312.1.8.12.1.5 on Thin OS 2405 | 30.05.2023 |
SB2023053067 SB2023072656 SB2023072657 and 17 more |
||
| #VU76666 - Cleartext Transmission of Sensitive Information CVE-2023-32762 |
CWE-319 | Medium | 2312.1.8.12.1.5 on Thin OS 2405 | 30.05.2023 |
SB2023053067 SB2023072656 SB2023072905 and 16 more |
||
| #VU76665 - Divide By Zero CVE-2023-32573 |
CWE-369 | Medium | 2312.1.8.12.1.5 on Thin OS 2405 | 30.05.2023 |
SB2023053067 SB2023072568 SB2023072625 and 28 more |
||
| #VU64559 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2022-2068 |
CWE-78 | Medium | 2312.1.8.12.1.5 on Thin OS 2405 | 21.06.2022 |
SB2022062120 SB2022062125 SB2022062236 and 135 more |
||
| #VU61391 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2022-0778 |
CWE-835 | Medium | 2312.1.8.12.1.5 on Thin OS 2405 | 15.03.2022 |
SB2022031520 SB2022031522 SB2022031611 and 238 more |
||
| #VU59648 - Integer overflow CVE-2022-22825 |
CWE-190 | High | 2312.1.8.12.1.5 on Thin OS 2405 | 17.01.2022 |
SB2022011711 SB2022011713 SB2022020902 and 56 more |
||
| #VU59647 - Integer overflow CVE-2022-22824 |
CWE-190 | High | 2312.1.8.12.1.5 on Thin OS 2405 | 17.01.2022 |
SB2022011711 SB2022011713 SB2022020902 and 57 more |
||
| #VU59646 - Integer overflow CVE-2022-22823 |
CWE-190 | High | 2312.1.8.12.1.5 on Thin OS 2405 | 17.01.2022 |
SB2022011711 SB2022011713 SB2022020902 and 57 more |
||
| #VU59645 - Integer overflow CVE-2022-22822 |
CWE-190 | High | 2312.1.8.12.1.5 on Thin OS 2405 | 17.01.2022 |
SB2022011711 SB2022011713 SB2022020902 and 59 more |
||
| #VU18657 - Out-of-bounds read CVE-2019-8457 |
CWE-125 | Low | 2312.1.8.12.1.5 on Thin OS 2405 | 31.05.2019 |
SB2019053112 SB2019060401 SB2019060407 and 16 more |
||
| #VU18574 - Heap-based Buffer Overflow CVE-2017-10989 |
CWE-122 | Low | 2312.1.8.12.1.5 on Thin OS 2405 | 22.05.2019 |
SB2019052208 SB2019061913 SB2017100225 and 9 more |
||
| #VU17162 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2018-20346 |
CWE-89 | Low | 2312.1.8.12.1.5 on Thin OS 2405 | 23.01.2019 |
SB2019012301 SB2019012302 SB2019012304 and 16 more |
||
| #VU11173 - NULL Pointer Dereference CVE-2018-8740 |
CWE-476 | Low | 2312.1.8.12.1.5 on Thin OS 2405 | 20.03.2018 |
SB2018032005 SB2019052208 SB2019120212 and 10 more |
Showing elements 101 - 120 out of 166