Netapp
Netapp Management Services FOR Element Software: vulnerabilidades y CVE
Netapp Management Services FOR Element Software tiene 27 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE27
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-36054 | Media (6.5) | 2.8% | — | 7 ago 2023 | lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because… |
| CVE-2023-37920 | Crítica (9.8) | 0.57% | — | 25 jul 2023 | Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root… |
| CVE-2023-24329 | Alta (7.5) | 20% | — | 17 feb 2023 | An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters. |
| CVE-2022-23491 | Alta (7.5) | 0.51% | — | 7 dic 2022 | Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from… |
| CVE-2022-38023 | Alta (8.1) | 2.4% | — | 9 nov 2022 | Netlogon RPC Elevation of Privilege Vulnerability |
| CVE-2022-37967 | Alta (7.2) | 4.1% | — | 9 nov 2022 | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2022-37966 | Alta (8.1) | 2.5% | — | 9 nov 2022 | Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability |
| CVE-2022-45061 | Alta (7.5) | 2.7% | — | 9 nov 2022 | An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being… |
| CVE-2022-36033 | Media (6.1) | 1.5% | — | 29 ago 2022 | jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks… |
| CVE-2022-37434 | Crítica (9.8) | 19% | — | 5 ago 2022 | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common… |
| CVE-2022-24736 | Media (5.5) | 1.5% | — | 27 abr 2022 | Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of… |
| CVE-2022-24735 | Alta (7.8) | 2.3% | — | 27 abr 2022 | Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Redis prior to version 7.0.0 or 6.2.7 can inject Lua code that will… |
| CVE-2018-25032 | Alta (7.5) | 52% | — | 25 mar 2022 | zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. |
| CVE-2021-3737 | Alta (7.5) | 12% | — | 4 mar 2022 | A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming… |
| CVE-2022-0391 | Alta (7.5) | 8.3% | — | 9 feb 2022 | A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input… |
| CVE-2021-42340 | Alta (7.5) | 12% | — | 14 oct 2021 | The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade… |
| CVE-2021-3671 | Media (6.5) | 2.2% | — | 12 oct 2021 | A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server. |
| CVE-2021-32762 | Alta (8.8) | 2.6% | — | 4 oct 2021 | Redis is an open source, in-memory database that persists on disk. The redis-cli command line tool and redis-sentinel service may be vulnerable to integer overflow when parsing specially crafted large multi-bulk network… |
| CVE-2021-32687 | Alta (7.5) | 4.1% | — | 4 oct 2021 | Redis is an open source, in-memory database that persists on disk. An integer overflow bug affecting all versions of Redis can be exploited to corrupt the heap and potentially be used to leak arbitrary contents of the… |
| CVE-2021-32675 | Alta (7.5) | 16% | — | 4 oct 2021 | Redis is an open source, in-memory database that persists on disk. When parsing an incoming Redis Standard Protocol (RESP) request, Redis allocates memory according to user-specified values which determine the number of… |
| CVE-2021-32672 | Media (4.3) | 1.8% | — | 4 oct 2021 | Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer.… |
| CVE-2021-32628 | Alta (7.5) | 14% | — | 4 oct 2021 | Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the ziplist data structure used by all versions of Redis can be exploited to corrupt the heap and potentially result with… |
| CVE-2021-32627 | Alta (7.5) | 3.9% | — | 4 oct 2021 | Redis is an open source, in-memory database that persists on disk. In affected versions an integer overflow bug in Redis can be exploited to corrupt the heap and potentially result with remote code execution. The… |
| CVE-2021-32626 | Alta (8.8) | 16% | — | 4 oct 2021 | Redis is an open source, in-memory database that persists on disk. In affected versions specially crafted Lua scripts executing in Redis can cause the heap-based Lua stack to be overflowed, due to incomplete checks for… |
| CVE-2021-28169 | Media (5.3) | 78% | — | 9 jun 2021 | For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request… |
| CVE-2021-22118 | Alta (7.8) | 0.40% | — | 27 may 2021 | In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally… |
| CVE-2020-27223 | Media (5.3) | 78% | — | 26 feb 2021 | In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may… |
Otros productos de Netapp
Oncommand Insight · 971Active IQ Unified Manager · 848Oncommand Workflow Automation · 743Snapcenter · 575Cloud Backup · 349H700s Firmware · 294H300s Firmware · 293H500s Firmware · 293H410s Firmware · 293E-series Santricity OS Controller · 242H410c Firmware · 241Steelstore Cloud Integrated Storage · 211