Virtualcenter
Vendor:
First CVE: Nov 21, 2006 · Active for 19 years
10
Total CVEs
More Total CVEs than 88% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
5.3
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Virtualcenter over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 21, 2006
19 years ago
Most Recent CVE
Feb 15, 2013
4,908 days ago
CVE Severity & Scoring
Virtualcenter10 CVEs
10%
60%
30%
All CVEs352,427 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown10 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown10 (100.0%)
User Interaction
None0 (0.0%)
Unknown10 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown10 (100.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-1405HIGH VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update 3a, VMware VI-Client | Feb 15, 2013 | 10.0 | 25 | NO | NO |
CVE-2009-0778HIGH The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Dest | Mar 12, 2009 | 7.1 | 22 | NO | NO |
CVE-2010-0686HIGH WebAccess in VMware VirtualCenter 2.0.2 and 2.5, VMware Server 2.0, and VMware ESX 3.0.3 and 3.5 allows remote attackers to leverage proxy-server functionality to spoof the origin | Apr 1, 2010 | 7.5 | 21 | NO | NO |
CVE-2009-1072MEDIUM nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demo | Mar 25, 2009 | 4.9 | 18 | NO | NO |
CVE-2011-0426MEDIUM Directory traversal vulnerability in vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, and VMware VirtualCenter 2.5 before Update 6a, allows remote atta | May 9, 2011 | 4.3 | 17 | NO | NO |
CVE-2010-1137MEDIUM Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5, and the Server Console in VMware Server 1.0, allows remote | Apr 1, 2010 | 4.3 | 15 | NO | NO |
CVE-2009-2277MEDIUM Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5 allows remote attackers to inject arbitrary web script or H | Apr 1, 2010 | 4.3 | 15 | NO | NO |
CVE-2008-3514MEDIUM VMware VirtualCenter 2.5 before Update 2 and 2.0.2 before Update 5 relies on client-side "enabled/disabled functionality" for access control, which allows remote attackers to deter | Aug 13, 2008 | 5.0 | 15 | NO | NO |
CVE-2006-5990MEDIUM VMWare VirtualCenter client 2.x before 2.0.1 Patch 1 (Build 33643) and 1.4.x before 1.4.1 Patch 1 (Build 33425), when server certificate verification is enabled, does not verify th | Nov 21, 2006 | 4.0 | 14 | NO | NO |
VMware VirtualCenter 2.5 before Update 3 build 119838 on Windows displays a user's password in cleartext when the password contains unspecified special characters, which allows phy | Oct 6, 2008 | 2.1 | 11 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Virtualcenter
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.5 | 9 | 4.9 | 2.0% | 0 | 0 |
| 2.0.2 | 7 | 4.3 | 1.5% | 0 | 0 |
| 2.0.1 | 2 | 3.0 | 0.6% | 0 | 0 |
| 1.4.1 | 2 | 3.0 | 0.6% | 0 | 0 |