« Volver al listado

Netapp

Netapp Management Services FOR Element Software: vulnerabilidades y CVE

Netapp Management Services FOR Element Software tiene 27 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE27
Últimos 12 meses0
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-36054Media (6.5)2.8%—7 ago 2023
lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because…
CVE-2023-37920Crítica (9.8)0.57%—25 jul 2023
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root…
CVE-2023-24329Alta (7.5)20%—17 feb 2023
An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
CVE-2022-23491Alta (7.5)0.51%—7 dic 2022
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from…
CVE-2022-38023Alta (8.1)2.4%—9 nov 2022
Netlogon RPC Elevation of Privilege Vulnerability
CVE-2022-37967Alta (7.2)4.1%—9 nov 2022
Windows Kerberos Elevation of Privilege Vulnerability
CVE-2022-37966Alta (8.1)2.5%—9 nov 2022
Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability
CVE-2022-45061Alta (7.5)2.7%—9 nov 2022
An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being…
CVE-2022-36033Media (6.1)1.5%—29 ago 2022
jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks…
CVE-2022-37434Crítica (9.8)19%—5 ago 2022
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common…
CVE-2022-24736Media (5.5)1.5%—27 abr 2022
Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of…
CVE-2022-24735Alta (7.8)2.3%—27 abr 2022
Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Redis prior to version 7.0.0 or 6.2.7 can inject Lua code that will…
CVE-2018-25032Alta (7.5)52%—25 mar 2022
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
CVE-2021-3737Alta (7.5)12%—4 mar 2022
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming…
CVE-2022-0391Alta (7.5)8.3%—9 feb 2022
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input…
CVE-2021-42340Alta (7.5)12%—14 oct 2021
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade…
CVE-2021-3671Media (6.5)2.2%—12 oct 2021
A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.
CVE-2021-32762Alta (8.8)2.6%—4 oct 2021
Redis is an open source, in-memory database that persists on disk. The redis-cli command line tool and redis-sentinel service may be vulnerable to integer overflow when parsing specially crafted large multi-bulk network…
CVE-2021-32687Alta (7.5)4.1%—4 oct 2021
Redis is an open source, in-memory database that persists on disk. An integer overflow bug affecting all versions of Redis can be exploited to corrupt the heap and potentially be used to leak arbitrary contents of the…
CVE-2021-32675Alta (7.5)16%—4 oct 2021
Redis is an open source, in-memory database that persists on disk. When parsing an incoming Redis Standard Protocol (RESP) request, Redis allocates memory according to user-specified values which determine the number of…
CVE-2021-32672Media (4.3)1.8%—4 oct 2021
Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer.…
CVE-2021-32628Alta (7.5)14%—4 oct 2021
Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the ziplist data structure used by all versions of Redis can be exploited to corrupt the heap and potentially result with…
CVE-2021-32627Alta (7.5)3.9%—4 oct 2021
Redis is an open source, in-memory database that persists on disk. In affected versions an integer overflow bug in Redis can be exploited to corrupt the heap and potentially result with remote code execution. The…
CVE-2021-32626Alta (8.8)16%—4 oct 2021
Redis is an open source, in-memory database that persists on disk. In affected versions specially crafted Lua scripts executing in Redis can cause the heap-based Lua stack to be overflowed, due to incomplete checks for…
CVE-2021-28169Media (5.3)78%—9 jun 2021
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request…
CVE-2021-22118Alta (7.8)0.40%—27 may 2021
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally…
CVE-2020-27223Media (5.3)78%—26 feb 2021
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may…

Otros productos de Netapp