Esx

Vendor:

First CVE: Dec 31, 2003 · Active for 22 years

86
Total CVEs
More Total CVEs than 99% of tracked products
7.8
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
2.3%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Esx over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2003
22 years ago
Most Recent CVE
Sep 25, 2014
4,320 days ago

CVE Severity & Scoring

Esx86 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local12 (14.0%)
Network7 (8.1%)
Unknown67 (77.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (20.9%)
High1 (1.2%)
Unknown67 (77.9%)
User Interaction
None17 (19.8%)
Unknown67 (77.9%)
Required2 (2.3%)
Privileges Required
Low14 (16.3%)
High0 (0.0%)
None5 (5.8%)
Unknown67 (77.9%)

Top CVEs

Signals from CVEs in this product scope (86 CVEs).

86 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra
Sep 24, 20149.899YESYES
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri
Sep 25, 20149.898YESYES
Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5 allows r
Nov 2, 20095.080NOYES
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unli
Sep 30, 20108.145NOYES
The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory req
Sep 24, 20107.839NOYES
The extension parser in slp_v2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Service Location Protocol daemon (SLPD) in VMware ESX 4.0 and 4.1
Mar 11, 20115.036NOYES
The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548; VMware Player 2.5.x before 2.5.5 build 328052 and 3.1
Dec 6, 20107.236NOYES
Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privi
Nov 4, 20097.036NOYES
The Virtual Machine Communication Interface (VMCI) implementation in vmci.sys in VMware Workstation 8.x before 8.0.5 and 9.x before 9.0.1 on Windows, VMware Fusion 4.1 before 4.1.4
Feb 11, 20137.235NOYES
Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1
Sep 21, 200710.034NONO

Exploit Exposure

Signals from CVEs in this product scope (86 CVEs).

CISA KEV
2 CVEs
2.3% of CVEs· 96th percentile
Metasploit
2 CVEs
2.3% of CVEs· 96th percentile
Nuclei
1 CVE
1.2% of CVEs· 96th percentile
ExploitDB
13 CVEs
15.1% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (86 CVEs).

Media Mentions

Signals from CVEs in this product scope (86 CVEs).

Top CNAs Publishing CVEs For Esx

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.016.90.8%01
4.1477.16.6%28
4.0547.06.0%210
3.5297.83.8%03
3.0.3165.96.7%02
3.0.295.92.8%00
3.0.1106.85.0%00
3.0.087.34.3%00
2.5.577.02.2%01
2.5.457.66.1%00
2.5.3210.013.5%00
2.5.244.93.1%01
2.554.92.6%01
2.1.3210.013.5%00
2.1.254.92.6%01
2.1.154.92.6%01
2.124.33.8%01
2.0.2210.013.5%00
2.0.154.92.6%01
2.054.92.6%01