CVE-2008-1340
Last modified
CVE-2008-1340 is a vulnerability of currently unknown severity. Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.0.x before 6.0.3, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 allows attackers to cause a denial of service (host OS crash) via crafted VMCI calls that trigger "memory exhaustion and memory corruption.". EPSS estimates a 1.74% chance of exploitation in the next 30 days.
Description
Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.0.x before 6.0.3, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 allows attackers to cause a denial of service (host OS crash) via crafted VMCI calls that trigger "memory exhaustion and memory corruption."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Ace | 1.0 |
| Vmware | Ace | 2.0 |
| Vmware | Player | 1.0.2 |
| Vmware | Player | 1.0.3 |
| Vmware | Player | 1.0.4 |
| Vmware | Player | 1.0.5 |
| Vmware | Player | 2.0 |
| Vmware | Player | 2.0.1 |
| Vmware | Player | 2.0.2 |
| Vmware | Server | 1.0.3 |
| Vmware | Vmware Server | 1.0.2 |
| Vmware | Vmware Server | 1.0.4 |
| Vmware | Vmware Workstation | 5.5.5 |
| Vmware | Vmware Workstation | 6.0.1 |
| Vmware | Vmware Workstation | 6.0.2 |
| Vmware | Workstation | 5.5 |
| Vmware | Workstation | 5.5.3_build_34685 |
| Vmware | Workstation | 5.5.3_build_42958 |
| Vmware | Workstation | 5.5.4 |
| Vmware | Workstation | 5.5.4_build_44386 |
| Vmware | Workstation | 6.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-1340?
How severe is CVE-2008-1340?
How do I fix CVE-2008-1340?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-1333Format string vulnerability in Asterisk Open Source 1.6.x be…
- CVE-2008-1334cgi/b on the BT Home Hub router allows remote attackers to b…
- CVE-2008-1335The ipsec4_get_ulp function in the kernel in NetBSD 2.0 thro…
- CVE-2008-1336SQL injection vulnerability in Koobi CMS 4.2.3 through 4.3.0…
- CVE-2008-1337The instant message service in Timbuktu Pro 8.6.5 RC 229 and…
- CVE-2008-1338The Perforce service (p4s.exe) in Perforce Server 2007.3/143…
- CVE-2008-1341SQL injection vulnerability in SearchResults.aspx in LaGarde…
- CVE-2008-1342Multiple cross-site scripting (XSS) vulnerabilities in the s…
- CVE-2008-1343Directory traversal vulnerability in (1) pkgadd and (2) pkgr…
- CVE-2008-1344Multiple SQL injection vulnerabilities in MyioSoft EasyCalen…
- CVE-2008-1345Cross-site scripting (XSS) vulnerability in plugins/calendar…
- CVE-2008-1346SQL injection vulnerability in staticpages/easygallery/index…
Are you affected by CVE-2008-1340?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
