Xenserver
Vendor:
First CVE: Jul 22, 2008 · Active for 18 years
51
Total CVEs
More Total CVEs than 98% of tracked products
4.6
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 41% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Xenserver over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 22, 2008
18 years ago
Most Recent CVE
Jun 13, 2024
771 days ago
CVE Severity & Scoring
Xenserver51 CVEs
41%
41%
12%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local25 (49.0%)
Network12 (23.5%)
Unknown13 (25.5%)
Physical0 (0.0%)
Adjacent Network1 (2.0%)
Attack Complexity
Low29 (56.9%)
High9 (17.6%)
Unknown13 (25.5%)
User Interaction
None38 (74.5%)
Unknown13 (25.5%)
Required0 (0.0%)
Privileges Required
Low22 (43.1%)
High9 (17.6%)
None7 (13.7%)
Unknown13 (25.5%)
Top CVEs
Signals from CVEs in this product scope (51 CVEs).
51 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-0217HIGH The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos befor | Jun 12, 2012 | 7.2 | 65 | NO | YES |
CVE-2018-14007CRITICAL Citrix XenServer 7.1 and newer allows Directory Traversal. | Aug 15, 2018 | 9.8 | 62 | NO | NO |
CVE-2018-8897HIGH A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-sys | May 8, 2018 | 7.8 | 56 | NO | YES |
CVE-2015-7705CRITICAL The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests. | Aug 7, 2017 | 9.8 | 36 | NO | NO |
CVE-2016-9603CRITICAL A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update i | Jul 27, 2018 | 9.9 | 33 | NO | NO |
CVE-2014-4947HIGH Buffer overflow in the HVM graphics console support in Citrix XenServer 6.2 Service Pack 1 and earlier has unspecified impact and attack vectors. | Jul 22, 2014 | 10.0 | 32 | NO | NO |
CVE-2016-5302CRITICAL Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a h | Jun 13, 2016 | 9.8 | 30 | NO | NO |
CVE-2016-3710HIGH The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by cha | May 11, 2016 | 8.8 | 28 | NO | NO |
CVE-2017-12137HIGH arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref. | Aug 24, 2017 | 8.8 | 27 | NO | NO |
CVE-2012-4606HIGH Citrix XenServer 4.1, 6.0, 5.6 SP2, 5.6 Feature Pack 1, 5.6 Common Criteria, 5.6, 5.5, 5.0, and 5.0 Update 3 contains a Local Privilege Escalation Vulnerability which could allow l | Jan 23, 2020 | 7.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (51 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
3.9% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
3.9% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (51 CVEs).
Media Mentions
Signals from CVEs in this product scope (51 CVEs).
Top CNAs Publishing CVEs For Xenserver
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.0 | 1 | 6.0 | 0.2% | 0 | 0 |
| 7.6 | 3 | 7.1 | 0.4% | 0 | 0 |
| 7.5 | 5 | 7.3 | 11.6% | 0 | 0 |
| 7.4 | 3 | 7.7 | 25.2% | 0 | 1 |
| 7.3 | 2 | 6.7 | 9.7% | 0 | 1 |
| 7.2 | 5 | 8.4 | 4.1% | 0 | 1 |
| 7.1 | 13 | 8.3 | 6.9% | 0 | 1 |
| 7.0 | 28 | 7.6 | 2.3% | 0 | 1 |
| 6.5.0 | 2 | 7.5 | 0.5% | 0 | 0 |
| 6.5 | 23 | 7.7 | 2.7% | 0 | 1 |
| 6.2.0 | 28 | 7.7 | 2.6% | 0 | 1 |
| 6.1.0 | 2 | 5.5 | 1.2% | 0 | 0 |
| 6.1 | 2 | 7.5 | 0.5% | 0 | 0 |
| 6.0.2 | 26 | 7.6 | 2.5% | 0 | 1 |
| 6.0 | 8 | 7.0 | 5.5% | 0 | 1 |
| 5.6 | 2 | 7.1 | 0.4% | 0 | 0 |
| 5.5 | 3 | 6.2 | 0.4% | 0 | 0 |
| 5.0 | 2 | 7.2 | 0.4% | 0 | 0 |
| 4.1.0 | 2 | 4.2 | 1.8% | 0 | 0 |
| 4.1 | 1 | 7.8 | 0.4% | 0 | 0 |