Xenserver

Vendor:

First CVE: Jul 22, 2008 · Active for 18 years

51
Total CVEs
More Total CVEs than 98% of tracked products
4.6
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 41% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Xenserver over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 22, 2008
18 years ago
Most Recent CVE
Jun 13, 2024
771 days ago

CVE Severity & Scoring

Xenserver51 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local25 (49.0%)
Network12 (23.5%)
Unknown13 (25.5%)
Physical0 (0.0%)
Adjacent Network1 (2.0%)
Attack Complexity
Low29 (56.9%)
High9 (17.6%)
Unknown13 (25.5%)
User Interaction
None38 (74.5%)
Unknown13 (25.5%)
Required0 (0.0%)
Privileges Required
Low22 (43.1%)
High9 (17.6%)
None7 (13.7%)
Unknown13 (25.5%)

Top CVEs

Signals from CVEs in this product scope (51 CVEs).

51 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos befor
Jun 12, 20127.265NOYES
Citrix XenServer 7.1 and newer allows Directory Traversal.
Aug 15, 20189.862NONO
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-sys
May 8, 20187.856NOYES
The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.
Aug 7, 20179.836NONO
A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update i
Jul 27, 20189.933NONO
Buffer overflow in the HVM graphics console support in Citrix XenServer 6.2 Service Pack 1 and earlier has unspecified impact and attack vectors.
Jul 22, 201410.032NONO
Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a h
Jun 13, 20169.830NONO
The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by cha
May 11, 20168.828NONO
arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.
Aug 24, 20178.827NONO
Citrix XenServer 4.1, 6.0, 5.6 SP2, 5.6 Feature Pack 1, 5.6 Common Criteria, 5.6, 5.5, 5.0, and 5.0 Update 3 contains a Local Privilege Escalation Vulnerability which could allow l
Jan 23, 20207.825NONO

Exploit Exposure

Signals from CVEs in this product scope (51 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
3.9% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
3.9% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (51 CVEs).

Media Mentions

Signals from CVEs in this product scope (51 CVEs).

Top CNAs Publishing CVEs For Xenserver

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.016.00.2%00
7.637.10.4%00
7.557.311.6%00
7.437.725.2%01
7.326.79.7%01
7.258.44.1%01
7.1138.36.9%01
7.0287.62.3%01
6.5.027.50.5%00
6.5237.72.7%01
6.2.0287.72.6%01
6.1.025.51.2%00
6.127.50.5%00
6.0.2267.62.5%01
6.087.05.5%01
5.627.10.4%00
5.536.20.4%00
5.027.20.4%00
4.1.024.21.8%00
4.117.80.4%00