Esx Server
Vendor:
First CVE: Apr 6, 2007 · Active for 19 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Esx Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 6, 2007
19 years ago
Most Recent CVE
Apr 1, 2010
5,958 days ago
CVE Severity & Scoring
Esx Server8 CVEs
75%
25%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown8 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown8 (100.0%)
User Interaction
None0 (0.0%)
Unknown8 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (100.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-0686HIGH WebAccess in VMware VirtualCenter 2.0.2 and 2.5, VMware Server 2.0, and VMware ESX 3.0.3 and 3.5 allows remote attackers to leverage proxy-server functionality to spoof the origin | Apr 1, 2010 | 7.5 | 21 | NO | NO |
CVE-2008-0967MEDIUM Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware Player 1.x before 1.0.7 build 91707 | Jun 5, 2008 | 6.9 | 19 | NO | NO |
CVE-2008-2100HIGH Multiple buffer overflows in VIX API 1.1.x before 1.1.4 build 93057 on VMware Workstation 5.x and 6.x, VMware Player 1.x and 2.x, VMware ACE 2.x, VMware Server 1.x, VMware Fusion 1 | Jun 5, 2008 | 7.2 | 19 | NO | NO |
CVE-2010-1137MEDIUM Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5, and the Server Console in VMware Server 1.0, allows remote | Apr 1, 2010 | 4.3 | 15 | NO | NO |
CVE-2009-2277MEDIUM Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5 allows remote attackers to inject arbitrary web script or H | Apr 1, 2010 | 4.3 | 15 | NO | NO |
CVE-2009-3731MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware | Dec 16, 2009 | 4.3 | 15 | NO | NO |
CVE-2007-1270MEDIUM Double free vulnerability in VMware ESX Server 3.0.0 and 3.0.1 allows attackers to cause a denial of service (crash), obtain sensitive information, or possibly execute arbitrary co | Apr 6, 2007 | 5.0 | 15 | NO | NO |
CVE-2007-5671MEDIUM HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Player before 1.0.6 build 80404, VMware ACE before 1.0.5 build 79846, VMware Server | Jun 5, 2008 | 4.4 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Esx Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.0 | 1 | 4.3 | 2.8% | 0 | 0 |
| 3.5 | 5 | 6.0 | 1.4% | 0 | 0 |
| 3.3 | 1 | 6.9 | 0.4% | 0 | 0 |
| 3.2 | 1 | 6.9 | 0.4% | 0 | 0 |
| 3.1 | 1 | 6.9 | 0.4% | 0 | 0 |
| 3.0.3 | 3 | 5.4 | 2.1% | 0 | 0 |
| 3.0 | 2 | 6.1 | 1.6% | 0 | 0 |
| 2.5.5 | 2 | 5.7 | 0.4% | 0 | 0 |