Skip to main content

Vendor/product archive

netapp / solidfire_&_hci_management_node CVEs

Beta · best-effort

102 CVEs tagged to netapp / solidfire_&_hci_management_node5 Critical, 45 High, 48 Medium, 4 Low, 0 Unrated.

CVE-2025-24928

Published Feb 18, 2025

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted do…

CVSS 7.8 · High

CVE-2024-56171

Published Feb 18, 2025

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML…

CVSS 7.8 · High

CVE-2025-0725

Published Feb 5, 2025

When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an atta…

CVSS 7.3 · High
evidence mentions
8
Buzz score
36.5

CVE-2024-40896

Published Dec 23, 2024

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override enti…

CVSS 9.1 · Critical

CVE-2024-36958

Published May 30, 2024

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix nfsd4_encode_fattr4() crasher Ensure that args.acl is initialized early. It is used in an unconditi…

CVSS 5.5 · Medium

CVE-2024-33602

Published May 6, 2024

nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all…

CVSS 7.4 · High

CVE-2023-2007

Published Apr 24, 2023

The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage…

CVSS 7.8 · High

CVE-2022-30115

Published Jun 2, 2022

Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2022-27780

Published Jun 2, 2022

The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2022-27779

Published Jun 2, 2022

libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.curl can be told to receive and send cookies. curl's "cookie…

CVSS 5.3 · Medium
Showing 1-25 of 102 CVEsPage 1 of 5