Starwind Virtual San

Vendor:

First CVE: Apr 10, 2018 · Active for 8 years

23
Total CVEs
More Total CVEs than 95% of tracked products
5.8
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
4.3%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Starwind Virtual San over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 10, 2018
8 years ago
Most Recent CVE
Jan 28, 2022
1,637 days ago

CVE Severity & Scoring

Starwind Virtual San23 CVEs
All CVEs352,101 CVEs
LowMediumHighCritical
Attack Vector
Local13 (56.5%)
Network10 (43.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (73.9%)
High6 (26.1%)
Unknown0 (0.0%)
User Interaction
None15 (65.2%)
Unknown0 (0.0%)
Required8 (34.8%)
Privileges Required
Low8 (34.8%)
High3 (13.0%)
None12 (52.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as pri
Jan 28, 20227.898YESYES
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS f
Dec 8, 20219.841NONO
An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be
Nov 1, 20218.335NONO
An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an
Apr 10, 20188.829NONO
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expecte
Sep 26, 20217.027NONO
An issue was discovered in the Linux kernel before 5.10. drivers/infiniband/core/ucma.c has a use-after-free because the ctx is reached via the ctx_list in some ucma_migrate_id sit
Jun 7, 20217.825NONO
SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file.
Jan 19, 20217.825NONO
A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_p
Oct 6, 20207.225NONO
The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c, because av
Oct 20, 20216.724NONO
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable packag
Mar 26, 20217.024NONO

Exploit Exposure

Signals from CVEs in this product scope (23 CVEs).

CISA KEV
1 CVE
4.3% of CVEs· 97th percentile
Metasploit
1 CVE
4.3% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.3% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (23 CVEs).

Media Mentions

Signals from CVEs in this product scope (23 CVEs).

Top CNAs Publishing CVEs For Starwind Virtual San

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
v8r1357.77.0%00
v8156.23.0%11
815.50.4%00