Esx
Vendor:
First CVE: Dec 31, 2003 · Active for 22 years
86
Total CVEs
More Total CVEs than 99% of tracked products
7.8
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
2.3%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Esx over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2003
22 years ago
Most Recent CVE
Sep 25, 2014
4,320 days ago
CVE Severity & Scoring
Esx86 CVEs
42%
49%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local12 (14.0%)
Network7 (8.1%)
Unknown67 (77.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (20.9%)
High1 (1.2%)
Unknown67 (77.9%)
User Interaction
None17 (19.8%)
Unknown67 (77.9%)
Required2 (2.3%)
Privileges Required
Low14 (16.3%)
High0 (0.0%)
None5 (5.8%)
Unknown67 (77.9%)
Top CVEs
Signals from CVEs in this product scope (86 CVEs).
86 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-6271CRITICAL GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra | Sep 24, 2014 | 9.8 | 99 | YES | YES |
CVE-2014-7169CRITICAL GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri | Sep 25, 2014 | 9.8 | 98 | YES | YES |
CVE-2009-3733MEDIUM Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5 allows r | Nov 2, 2009 | 5.0 | 80 | NO | YES |
CVE-2010-2943HIGH The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unli | Sep 30, 2010 | 8.1 | 45 | NO | YES |
CVE-2010-3081HIGH The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory req | Sep 24, 2010 | 7.8 | 39 | NO | YES |
CVE-2010-3609MEDIUM The extension parser in slp_v2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Service Location Protocol daemon (SLPD) in VMware ESX 4.0 and 4.1 | Mar 11, 2011 | 5.0 | 36 | NO | YES |
CVE-2010-4297HIGH The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548; VMware Player 2.5.x before 2.5.5 build 328052 and 3.1 | Dec 6, 2010 | 7.2 | 36 | NO | YES |
CVE-2009-3547HIGH Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privi | Nov 4, 2009 | 7.0 | 36 | NO | YES |
CVE-2013-1406HIGH The Virtual Machine Communication Interface (VMCI) implementation in vmci.sys in VMware Workstation 8.x before 8.0.5 and 9.x before 9.0.1 on Windows, VMware Fusion 4.1 before 4.1.4 | Feb 11, 2013 | 7.2 | 35 | NO | YES |
CVE-2007-0063HIGH Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 | Sep 21, 2007 | 10.0 | 34 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (86 CVEs).
CISA KEV
2 CVEs
2.3% of CVEs· 96th percentile
Metasploit
2 CVEs
2.3% of CVEs· 96th percentile
Nuclei
1 CVE
1.2% of CVEs· 96th percentile
ExploitDB
13 CVEs
15.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (86 CVEs).
Media Mentions
Signals from CVEs in this product scope (86 CVEs).
Top CNAs Publishing CVEs For Esx
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.0 | 1 | 6.9 | 0.8% | 0 | 1 |
| 4.1 | 47 | 7.1 | 6.6% | 2 | 8 |
| 4.0 | 54 | 7.0 | 6.0% | 2 | 10 |
| 3.5 | 29 | 7.8 | 3.8% | 0 | 3 |
| 3.0.3 | 16 | 5.9 | 6.7% | 0 | 2 |
| 3.0.2 | 9 | 5.9 | 2.8% | 0 | 0 |
| 3.0.1 | 10 | 6.8 | 5.0% | 0 | 0 |
| 3.0.0 | 8 | 7.3 | 4.3% | 0 | 0 |
| 2.5.5 | 7 | 7.0 | 2.2% | 0 | 1 |
| 2.5.4 | 5 | 7.6 | 6.1% | 0 | 0 |
| 2.5.3 | 2 | 10.0 | 13.5% | 0 | 0 |
| 2.5.2 | 4 | 4.9 | 3.1% | 0 | 1 |
| 2.5 | 5 | 4.9 | 2.6% | 0 | 1 |
| 2.1.3 | 2 | 10.0 | 13.5% | 0 | 0 |
| 2.1.2 | 5 | 4.9 | 2.6% | 0 | 1 |
| 2.1.1 | 5 | 4.9 | 2.6% | 0 | 1 |
| 2.1 | 2 | 4.3 | 3.8% | 0 | 1 |
| 2.0.2 | 2 | 10.0 | 13.5% | 0 | 0 |
| 2.0.1 | 5 | 4.9 | 2.6% | 0 | 1 |
| 2.0 | 5 | 4.9 | 2.6% | 0 | 1 |