Skip to main content

Vendor/product archive

netapp / h500s_firmware CVEs

Beta · best-effort

277 CVEs tagged to netapp / h500s_firmware17 Critical, 166 High, 87 Medium, 7 Low, 0 Unrated.

CVE-2022-25265

Published Feb 16, 2022

In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20).…

CVSS 7.8 · High

CVE-2022-25258

Published Feb 16, 2022

An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests…

CVSS 4.6 · Medium

CVE-2022-0185

Published Feb 11, 2022

A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters…

CVSS 8.4 · High
evidence mentions
3
Buzz score
50.4
KEV listed

CVE-2022-24122

Published Jan 29, 2022

kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object c…

CVSS 7.8 · High

CVE-2021-22600

Published Jan 26, 2022

A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upg…

CVSS 6.6 · Medium
evidence mentions
4
Buzz score
52.6
KEV listed

CVE-2021-34866

Published Jan 25, 2022

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.14-rc3. An attacker must first obtain the ability to execute low-privi…

CVSS 7.8 · High

CVE-2022-23222

Published Jan 14, 2022

kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer typ…

CVSS 7.8 · High

CVE-2021-44733

Published Dec 22, 2021

A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an…

CVSS 7.0 · High
evidence mentions
7
Buzz score
41.3
Public PoC observed

CVE-2021-45100

Published Dec 16, 2021

The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabled. This occurs because it set…

CVSS 7.5 · High

CVE-2018-25020

Published Dec 8, 2021

The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into…

CVSS 7.8 · High

CVE-2021-43975

Published Nov 17, 2021

In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allows an attacker (who can introduce a crafted device…

CVSS 6.7 · Medium

CVE-2021-42377

Published Nov 15, 2021

An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell misha…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2021-42376

Published Nov 15, 2021

A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character.…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2021-42375

Published Nov 15, 2021

An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characte…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2021-42374

Published Nov 15, 2021

An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
21.9

CVE-2021-43618

Published Nov 15, 2021

GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation faul…

CVSS 7.5 · High
Showing 176-200 of 277 CVEsPage 8 of 12