Skip to main content

Vendor/product archive

netapp / h410s_firmware CVEs

Beta · best-effort

258 CVEs tagged to netapp / h410s_firmware15 Critical, 154 High, 82 Medium, 7 Low, 0 Unrated.

CVE-2021-34866

Published Jan 25, 2022

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.14-rc3. An attacker must first obtain the ability to execute low-privi…

CVSS 7.8 · High

CVE-2022-23222

Published Jan 14, 2022

kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer typ…

CVSS 7.8 · High

CVE-2021-45100

Published Dec 16, 2021

The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabled. This occurs because it set…

CVSS 7.5 · High

CVE-2018-25020

Published Dec 8, 2021

The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into…

CVSS 7.8 · High

CVE-2021-43975

Published Nov 17, 2021

In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allows an attacker (who can introduce a crafted device…

CVSS 6.7 · Medium

CVE-2021-42377

Published Nov 15, 2021

An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell misha…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2021-42376

Published Nov 15, 2021

A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character.…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2021-42375

Published Nov 15, 2021

An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characte…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2021-42374

Published Nov 15, 2021

An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
21.9

CVE-2021-43618

Published Nov 15, 2021

GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation faul…

CVSS 7.5 · High

CVE-2021-43267

Published Nov 2, 2021

An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploi…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2021-43057

Published Oct 28, 2021

An issue was discovered in the Linux kernel before 5.14.8. A use-after-free in selinux_ptrace_traceme (aka the SELinux handler for PTRACE_TRACEME) could be used by local attackers…

CVSS 7.8 · High

CVE-2021-42327

Published Oct 21, 2021

dp_link_settings_write in drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c in the Linux kernel through 5.14.14 allows a heap-based buffer overflow by an attacker who can…

CVSS 6.7 · Medium
Showing 176-200 of 258 CVEsPage 8 of 11