Gsx Server
Vendor:
First CVE: Aug 12, 2002 · Active for 23 years
6
Total CVEs
More Total CVEs than 80% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Gsx Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 12, 2002
23 years ago
Most Recent CVE
Dec 21, 2005
7,519 days ago
CVE Severity & Scoring
Gsx Server6 CVEs
33%
67%
All CVEs352,101 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (16.7%)
Unknown5 (83.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (16.7%)
High0 (0.0%)
Unknown5 (83.3%)
User Interaction
None1 (16.7%)
Unknown5 (83.3%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (16.7%)
Unknown5 (83.3%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-4459HIGH Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticate | Dec 21, 2005 | 10.0 | 35 | NO | NO |
CVE-2002-0814HIGH Buffer overflow in VMware Authorization Service for VMware GSX Server 2.0.0 build-2050 allows remote authenticated users to execute arbitrary code via a long GLOBAL argument. | Aug 12, 2002 | 7.5 | 34 | NO | YES |
CVE-2004-0079HIGH The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake t | Nov 23, 2004 | 7.5 | 29 | NO | NO |
CVE-2004-0112MEDIUM The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, whi | Nov 23, 2004 | 5.0 | 23 | NO | NO |
CVE-2003-0631HIGH VMware GSX Server 2.5.1 build 4968 and earlier, and Workstation 4.0 and earlier, allows local users to gain root privileges via certain enivronment variables that are used when lau | Aug 27, 2003 | 7.2 | 23 | NO | NO |
CVE-2004-0081MEDIUM OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Co | Nov 23, 2004 | 5.0 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
16.7% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Gsx Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.2 | 1 | 10.0 | 14.1% | 0 | 0 |
| 3.1 | 1 | 10.0 | 14.1% | 0 | 0 |
| 3.0_build_7592 | 4 | 6.9 | 10.3% | 0 | 0 |
| 3.0 | 1 | 10.0 | 14.1% | 0 | 0 |
| 2.5.2 | 1 | 10.0 | 14.1% | 0 | 0 |
| 2.5.1_build_5336 | 4 | 6.9 | 10.3% | 0 | 0 |
| 2.5.1 | 5 | 6.9 | 8.3% | 0 | 0 |
| 2.0.1_build_2129 | 4 | 6.9 | 10.3% | 0 | 0 |
| 2.0.0_build_2050 | 1 | 7.5 | 13.7% | 0 | 1 |
| 2.0 | 4 | 6.9 | 10.3% | 0 | 0 |