Player
Vendor:
First CVE: Dec 21, 2005 · Active for 20 years
89
Total CVEs
More Total CVEs than 99% of tracked products
7.4
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Player over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 21, 2005
20 years ago
Most Recent CVE
May 18, 2016
3,719 days ago
CVE Severity & Scoring
Player89 CVEs
38%
53%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.1%)
Network4 (4.5%)
Unknown84 (94.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (5.6%)
High0 (0.0%)
Unknown84 (94.4%)
User Interaction
None4 (4.5%)
Unknown84 (94.4%)
Required1 (1.1%)
Privileges Required
Low2 (2.2%)
High0 (0.0%)
None3 (3.4%)
Unknown84 (94.4%)
Top CVEs
Signals from CVEs in this product scope (89 CVEs).
89 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-3569HIGH Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.5, and other products, allows user-assis | Nov 14, 2012 | 9.3 | 74 | NO | YES |
CVE-2010-1205CRITICAL Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG | Jun 30, 2010 | 9.8 | 67 | NO | YES |
CVE-2009-3732HIGH Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary code via unspecified vectors. | Apr 12, 2010 | 10.0 | 48 | NO | YES |
CVE-2008-3892HIGH Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player | Sep 3, 2008 | 10.0 | 48 | NO | YES |
CVE-2013-1662MEDIUM vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host OS privileges via a crafted ls | Aug 24, 2013 | 6.9 | 44 | NO | YES |
CVE-2010-4297HIGH The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548; VMware Player 2.5.x before 2.5.5 build 328052 and 3.1 | Dec 6, 2010 | 7.2 | 36 | NO | YES |
CVE-2005-4459HIGH Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticate | Dec 21, 2005 | 10.0 | 35 | NO | NO |
CVE-2007-0063HIGH Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 | Sep 21, 2007 | 10.0 | 34 | NO | NO |
CVE-2009-2267MEDIUM VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware Server 1.x before 1.0.10 build | Nov 2, 2009 | 6.9 | 32 | NO | YES |
CVE-2016-2077CRITICAL VMware Workstation 11.x before 11.1.3 and VMware Player 7.x before 7.1.3 on Windows incorrectly access an executable file, which allows host OS users to gain host OS privileges via | May 18, 2016 | 9.8 | 31 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (89 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
2.2% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
9 CVEs
10.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (89 CVEs).
Media Mentions
Signals from CVEs in this product scope (89 CVEs).
Top CNAs Publishing CVEs For Player
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.1.2 | 1 | 9.8 | 1.8% | 0 | 0 |
| 7.1.1 | 2 | 8.1 | 1.7% | 0 | 0 |
| 7.1 | 8 | 6.7 | 0.9% | 0 | 0 |
| 7.0 | 8 | 6.7 | 0.9% | 0 | 0 |
| 6.0.6 | 1 | 7.2 | 0.5% | 0 | 0 |
| 6.0.5 | 7 | 6.4 | 0.8% | 0 | 0 |
| 6.0.4 | 10 | 5.8 | 1.2% | 0 | 0 |
| 6.0.3 | 10 | 5.8 | 1.2% | 0 | 0 |
| 6.0.2 | 10 | 5.8 | 1.2% | 0 | 0 |
| 6.0.1_build_1379776 | 1 | 4.9 | 0.3% | 0 | 0 |
| 6.0.1 | 11 | 5.8 | 1.2% | 0 | 0 |
| 6.0 | 11 | 5.8 | 1.2% | 0 | 0 |
| 5.0.4 | 1 | 7.2 | 0.5% | 0 | 0 |
| 5.0.3 | 1 | 7.2 | 0.5% | 0 | 0 |
| 5.0.2 | 4 | 7.3 | 1.5% | 0 | 1 |
| 5.0.1 | 4 | 7.3 | 1.5% | 0 | 1 |
| 5.0 | 5 | 6.5 | 1.3% | 0 | 1 |
| 4.0.6 | 1 | 6.9 | 4.6% | 0 | 1 |
| 4.0.5 | 1 | 6.9 | 4.6% | 0 | 1 |
| 4.0.4 | 4 | 8.1 | 13.4% | 0 | 2 |