CVE-2005-4459
high · 10Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT and (2) PORT FTP commands.
10
CVSS
14.2%
EPSS (exploit prob.)
96th
EPSS percentile
2005-12-21
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| vmware | ace | 1.0.1 |
| vmware | gsx_server | 2.0 |
| vmware | gsx_server | 2.0.1_build_2129 |
| vmware | gsx_server | 2.5.1 |
| vmware | gsx_server | 2.5.1_build_5336 |
| vmware | gsx_server | 2.5.2 |
| vmware | gsx_server | 3.0 |
| vmware | gsx_server | 3.0_build_7592 |
| vmware | gsx_server | 3.1 |
| vmware | gsx_server | 3.2 |
| vmware | player | 1.0.0 |
| vmware | workstation | 3.2.1 |
| vmware | workstation | 3.4 |
| vmware | workstation | 4.0 |
| vmware | workstation | 4.0.1 |
| vmware | workstation | 4.0.2 |
| vmware | workstation | 4.5.2 |
| vmware | workstation | 4.5.2_build_8848 |
| vmware | workstation | 5.0.0_build_13124 |
| vmware | workstation | 5.5 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-December/040442.html
- http://secunia.com/advisories/18162
- http://secunia.com/advisories/18344
- http://securityreason.com/securityalert/282
- http://securityreason.com/securityalert/289
- http://securitytracker.com/id?1015401
- http://www.gentoo.org/security/en/glsa/glsa-200601-04.xml
- http://www.kb.cert.org/vuls/id/856689
- http://www.securityfocus.com/archive/1/419997/100/0/threaded
- http://www.securityfocus.com/archive/1/420017/100/0/threaded
- http://www.securityfocus.com/bid/15998
- http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=2000
- http://www.vupen.com/english/advisories/2005/3013
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-December/040442.html
- http://secunia.com/advisories/18162
- http://secunia.com/advisories/18344
- http://securityreason.com/securityalert/282
- http://securityreason.com/securityalert/289
- http://securitytracker.com/id?1015401
- http://www.gentoo.org/security/en/glsa/glsa-200601-04.xml
- http://www.kb.cert.org/vuls/id/856689
- http://www.securityfocus.com/archive/1/419997/100/0/threaded
- http://www.securityfocus.com/archive/1/420017/100/0/threaded
- http://www.securityfocus.com/bid/15998
- http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=2000
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2005-4459