Skip to main content

Vendor/product archive

netapp / cloud_backup CVEs

Beta · best-effort

322 CVEs tagged to netapp / cloud_backup35 Critical, 139 High, 131 Medium, 17 Low, 0 Unrated.

CVE-2021-44790

Published Dec 20, 2021

A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an expl…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2018-25020

Published Dec 8, 2021

The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into…

CVSS 7.8 · High

CVE-2021-43975

Published Nov 17, 2021

In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allows an attacker (who can introduce a crafted device…

CVSS 6.7 · Medium

CVE-2021-42377

Published Nov 15, 2021

An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell misha…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2021-42376

Published Nov 15, 2021

A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character.…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2021-42375

Published Nov 15, 2021

An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characte…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2021-42374

Published Nov 15, 2021

An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
21.9

CVE-2021-42013

Published Oct 7, 2021

It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the director…

CVSS 9.8 · Critical
evidence mentions
19
Buzz score
79.0
KEV listedPublic PoC observed
Showing 1-25 of 322 CVEsPage 1 of 13