Vm Server
Vendor:
First CVE: Feb 8, 2013 · Active for 13 years
38
Total CVEs
More Total CVEs than 97% of tracked products
5.4
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Vm Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 8, 2013
13 years ago
Most Recent CVE
Sep 20, 2023
1,038 days ago
CVE Severity & Scoring
Vm Server38 CVEs
50%
37%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local18 (47.4%)
Network12 (31.6%)
Unknown8 (21.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low29 (76.3%)
High1 (2.6%)
Unknown8 (21.1%)
User Interaction
None23 (60.5%)
Unknown8 (21.1%)
Required7 (18.4%)
Privileges Required
Low12 (31.6%)
High2 (5.3%)
None16 (42.1%)
Unknown8 (21.1%)
Top CVEs
Signals from CVEs in this product scope (38 CVEs).
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-2776HIGH buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause | Sep 28, 2016 | 7.5 | 87 | NO | YES |
CVE-2016-3115MEDIUM Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command restrictions via crafted X11 | Mar 22, 2016 | 6.4 | 53 | NO | YES |
CVE-2015-8000MEDIUM db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a mal | Dec 16, 2015 | 5.0 | 41 | NO | NO |
CVE-2015-3195MEDIUM The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused | Dec 6, 2015 | 5.3 | 39 | NO | NO |
CVE-2016-4447HIGH The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application cr | Jun 9, 2016 | 7.5 | 35 | NO | NO |
CVE-2016-4448CRITICAL Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors. | Jun 9, 2016 | 9.8 | 34 | NO | NO |
CVE-2015-8668CRITICAL Heap-based buffer overflow in the PackBitsPreEncode function in tif_packbits.c in bmp2tiff in libtiff 4.0.6 and earlier allows remote attackers to execute arbitrary code or cause a | Jan 8, 2016 | 9.8 | 32 | NO | NO |
CVE-2014-1490HIGH Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, Se | Feb 6, 2014 | 9.3 | 31 | NO | NO |
CVE-2016-3627HIGH The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recu | May 17, 2016 | 7.5 | 30 | NO | NO |
CVE-2016-1950HIGH Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38 | Mar 13, 2016 | 8.8 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (38 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.6% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
5.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (38 CVEs).
Media Mentions
Signals from CVEs in this product scope (38 CVEs).
Top CNAs Publishing CVEs For Vm Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.6 | 1 | 3.3 | 0.4% | 0 | 0 |
| 3.4 | 25 | 6.9 | 7.3% | 0 | 1 |
| 3.3 | 19 | 7.2 | 9.0% | 0 | 1 |
| 3.2 | 16 | 6.3 | 15.8% | 0 | 2 |
| 3.1 | 1 | 4.3 | 1.7% | 0 | 0 |
| 3.0 | 1 | 5.5 | 0.2% | 0 | 0 |