Player

Vendor:

First CVE: Dec 21, 2005 · Active for 20 years

89
Total CVEs
More Total CVEs than 99% of tracked products
7.4
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Player over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 21, 2005
20 years ago
Most Recent CVE
May 18, 2016
3,719 days ago

CVE Severity & Scoring

Player89 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local1 (1.1%)
Network4 (4.5%)
Unknown84 (94.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (5.6%)
High0 (0.0%)
Unknown84 (94.4%)
User Interaction
None4 (4.5%)
Unknown84 (94.4%)
Required1 (1.1%)
Privileges Required
Low2 (2.2%)
High0 (0.0%)
None3 (3.4%)
Unknown84 (94.4%)

Top CVEs

Signals from CVEs in this product scope (89 CVEs).

89 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.5, and other products, allows user-assis
Nov 14, 20129.374NOYES
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG
Jun 30, 20109.867NOYES
Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary code via unspecified vectors.
Apr 12, 201010.048NOYES
Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player
Sep 3, 200810.048NOYES
vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host OS privileges via a crafted ls
Aug 24, 20136.944NOYES
The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548; VMware Player 2.5.x before 2.5.5 build 328052 and 3.1
Dec 6, 20107.236NOYES
Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticate
Dec 21, 200510.035NONO
Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1
Sep 21, 200710.034NONO
VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware Server 1.x before 1.0.10 build
Nov 2, 20096.932NOYES
VMware Workstation 11.x before 11.1.3 and VMware Player 7.x before 7.1.3 on Windows incorrectly access an executable file, which allows host OS users to gain host OS privileges via
May 18, 20169.831NONO

Exploit Exposure

Signals from CVEs in this product scope (89 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
2.2% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
9 CVEs
10.1% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (89 CVEs).

Media Mentions

Signals from CVEs in this product scope (89 CVEs).

Top CNAs Publishing CVEs For Player

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.1.219.81.8%00
7.1.128.11.7%00
7.186.70.9%00
7.086.70.9%00
6.0.617.20.5%00
6.0.576.40.8%00
6.0.4105.81.2%00
6.0.3105.81.2%00
6.0.2105.81.2%00
6.0.1_build_137977614.90.3%00
6.0.1115.81.2%00
6.0115.81.2%00
5.0.417.20.5%00
5.0.317.20.5%00
5.0.247.31.5%01
5.0.147.31.5%01
5.056.51.3%01
4.0.616.94.6%01
4.0.516.94.6%01
4.0.448.113.4%02