Vma
Vendor:
First CVE: Mar 12, 2009 · Active for 17 years
7
Total CVEs
More Total CVEs than 83% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Vma over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 12, 2009
17 years ago
Most Recent CVE
Jun 1, 2012
5,166 days ago
CVE Severity & Scoring
Vma7 CVEs
57%
43%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (28.6%)
Network1 (14.3%)
Unknown4 (57.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (28.6%)
High1 (14.3%)
Unknown4 (57.1%)
User Interaction
None2 (28.6%)
Unknown4 (57.1%)
Required1 (14.3%)
Privileges Required
Low2 (28.6%)
High0 (0.0%)
None1 (14.3%)
Unknown4 (57.1%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-3547HIGH Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privi | Nov 4, 2009 | 7.0 | 36 | NO | YES |
CVE-2009-3621MEDIUM net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket | Oct 22, 2009 | 5.5 | 27 | NO | YES |
CVE-2009-2416MEDIUM Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (ap | Aug 11, 2009 | 6.5 | 23 | NO | NO |
CVE-2009-0778HIGH The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Dest | Mar 12, 2009 | 7.1 | 22 | NO | NO |
CVE-2012-2752HIGH Untrusted search path vulnerability in VMware vMA 4.x and 5.x before 5.0.0.2 allows local users to gain privileges via a Trojan horse DLL in the current working directory. | Jun 1, 2012 | 7.2 | 21 | NO | NO |
CVE-2009-2848MEDIUM The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial o | Aug 18, 2009 | 5.9 | 18 | NO | NO |
CVE-2009-1072MEDIUM nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demo | Mar 25, 2009 | 4.9 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
28.6% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Vma
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.0.0.1 | 1 | 7.2 | 0.4% | 0 | 0 |
| 4.1 | 1 | 7.2 | 0.4% | 0 | 0 |
| 4.0 | 7 | 6.3 | 1.9% | 0 | 2 |