Windows Xp

Vendor:

First CVE: Apr 14, 2000 · Active for 26 years

1,352
Total CVEs
More Total CVEs than 100% of tracked products
67.6
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 59% of tracked products
1.8%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Windows Xp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 14, 2000
26 years ago
Most Recent CVE
Apr 29, 2020
2,277 days ago

CVE Severity & Scoring

Windows Xp1,352 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local55 (4.1%)
Network79 (5.8%)
Unknown1,218 (90.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low102 (7.5%)
High32 (2.4%)
Unknown1,218 (90.1%)
User Interaction
None80 (5.9%)
Unknown1,218 (90.1%)
Required54 (4.0%)
Privileges Required
Low29 (2.1%)
High0 (0.0%)
None105 (7.8%)
Unknown1,218 (90.1%)

Top CVEs

Signals from CVEs in this product scope (1352 CVEs).

1,352 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token
Nov 5, 20108.198YESYES
Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP
Jan 15, 20108.898YESYES
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitr
Oct 23, 20089.898YESYES
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object t
Dec 30, 20128.897YESYES
Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafte
Sep 18, 20128.197YESYES
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (me
Jun 13, 20128.897YESYES
Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary cod
Jul 22, 20107.897YESYES
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via ve
Mar 10, 20108.897YESYES
Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in Dir
Jul 7, 20098.897YESYES
The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2
Nov 12, 20138.896YESYES

Exploit Exposure

Signals from CVEs in this product scope (1352 CVEs).

CISA KEV
24 CVEs
1.8% of CVEs· 96th percentile
Metasploit
81 CVEs
6.0% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
300 CVEs
22.2% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (1352 CVEs).

Media Mentions

Signals from CVEs in this product scope (1352 CVEs).

Top CNAs Publishing CVEs For Windows Xp

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
sp3106.517.6%05
ibm_oem_version27.711.6%00
200538.937.7%01