Vagrant vmware fusion
This hub aggregates every CVE we track for Vagrant vmware fusion, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
7
CVEs tracked
0
Critical
7
High
0
In CISA KEV
Severity distribution
HIGH7
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 7 most recently published vulnerabilities affecting Vagrant vmware fusion.
- CVE-2017-16873It is possible to exploit an unsanitized PATH in the suid binary that ships with vagrant-vmware-fusion 4.0.25 through 5.0.4 in order to escalate to root privileges.7.8
- CVE-2017-16839Hashicorp vagrant-vmware-fusion 5.0.4 allows local users to steal root privileges if VMware Fusion is not installed.7.0
- CVE-2017-16512The vagrant update process in Hashicorp vagrant-vmware-fusion 5.0.2 through 5.0.4 allows local users to steal root privileges via a crafted update request when no updates are available.7.8
- CVE-2017-15884In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.0, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges.7.0
- CVE-2017-12579An insecure suid wrapper binary in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 4.0.24 and earlier allows a non-root user to obtain a root shell.7.8
- CVE-2017-11741HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.24 uses weak permissions for the sudo helper scripts, allows local users to execute arbitrary code with root privileges...8.8
- CVE-2017-7642The sudo helper in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.21 allows local users to gain root privileges by leveraging failure to verify the path to the en...7.8
Product normalization is registry-driven with AI assist and human review. How it works