← All CVEs

CVE-2005-4459

high · 10

Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT and (2) PORT FTP commands.

10
CVSS
14.2%
EPSS (exploit prob.)
96th
EPSS percentile
2005-12-21
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
vmwareace1.0.1
vmwaregsx_server2.0
vmwaregsx_server2.0.1_build_2129
vmwaregsx_server2.5.1
vmwaregsx_server2.5.1_build_5336
vmwaregsx_server2.5.2
vmwaregsx_server3.0
vmwaregsx_server3.0_build_7592
vmwaregsx_server3.1
vmwaregsx_server3.2
vmwareplayer1.0.0
vmwareworkstation3.2.1
vmwareworkstation3.4
vmwareworkstation4.0
vmwareworkstation4.0.1
vmwareworkstation4.0.2
vmwareworkstation4.5.2
vmwareworkstation4.5.2_build_8848
vmwareworkstation5.0.0_build_13124
vmwareworkstation5.5

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2005-4459