Netapp
Netapp HCI Compute Node: vulnerabilidades y CVE
Netapp HCI Compute Node tiene 51 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE51
Últimos 12 meses0
Críticas5
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-13272 | Alta (7.8) | 52% | ⚠ Explotación activa | 17 jul 2019 | In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-27423 | Alta (7.1) | 22% | — | 3 mar 2025 | Vim is an open source, command line text editor. Vim is distributed with the tar.vim plugin, that allows easy editing and viewing of (compressed or uncompressed) tar files. Starting with 9.1.0858, the tar.vim plugin… |
| CVE-2025-24928 | Alta (7.7) | 0.39% | — | 18 feb 2025 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is… |
| CVE-2024-56171 | Crítica (9.8) | 1.2% | — | 18 feb 2025 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an… |
| CVE-2025-26603 | Media (4.2) | 0.24% | — | 18 feb 2025 | Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages using the `:redir` ex command to register, variables and files. It also allows to show the contents of registers… |
| CVE-2025-0509 | Media (6.8) | 0.90% | — | 4 feb 2025 | A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks. |
| CVE-2024-40896 | Crítica (9.1) | 1.2% | — | 23 dic 2024 | In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This… |
| CVE-2024-53580 | Alta (7.5) | 0.92% | — | 18 dic 2024 | iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function. |
| CVE-2024-3447 | Media (6) | 0.55% | — | 14 nov 2024 | A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_count` and the size of `s->fifo_buffer` are set to 0x200, leading to an out-of-bound access. A… |
| CVE-2024-50602 | Media (5.9) | 1.0% | — | 27 oct 2024 | An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser. |
| CVE-2024-41965 | Media (4.2) | 0.33% | — | 1 ago 2024 | Vim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a buffer, Vim may ask the user what to do with the modified buffer. If the user wants the changed… |
| CVE-2024-36958 | Media (5.5) | 0.50% | — | 30 may 2024 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix nfsd4_encode_fattr4() crasher Ensure that args.acl is initialized early. It is used in an unconditional call to kfree() on the way out of… |
| CVE-2024-2961 | Alta (7.3) | 88% | — | 17 abr 2024 | The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an… |
| CVE-2023-48706 | Media (4.7) | 0.54% | — | 22 nov 2023 | Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` command for the very first time and using a sub-replace-special atom inside the substitution part, it… |
| CVE-2023-0049 | Alta (7.8) | 0.57% | — | 4 ene 2023 | Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143. |
| CVE-2022-37434 | Crítica (9.8) | 19% | — | 5 ago 2022 | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common… |
| CVE-2022-36946 | Alta (7.5) | 7.6% | — | 27 jul 2022 | nfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a denial of service (panic) because, in the case of an nf_queue verdict with a one-byte nfta_payload… |
| CVE-2022-21549 | Media (5.3) | 2.4% | — | 19 jul 2022 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.3.1; Oracle GraalVM Enterprise… |
| CVE-2022-21541 | Media (5.9) | 2.7% | — | 19 jul 2022 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1,… |
| CVE-2022-21540 | Media (5.3) | 3.9% | — | 19 jul 2022 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1,… |
| CVE-2022-34169 | Alta (7.5) | 81% | — | 19 jul 2022 | The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and… |
| CVE-2022-2048 | Alta (7.5) | 2.6% | — | 7 jul 2022 | In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This… |
| CVE-2022-2047 | Baja (2.7) | 1.3% | — | 7 jul 2022 | In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid… |
| CVE-2022-27781 | Alta (7.5) | 2.7% | — | 2 jun 2022 | libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS… |
| CVE-2022-27779 | Media (5.3) | 2.7% | — | 2 jun 2022 | libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.curl can be told to receive and send cookies. curl's "cookie engine" can bebuilt with or without… |
| CVE-2022-30594 | Alta (7.8) | 0.80% | — | 12 may 2022 | The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag. |
| CVE-2022-21449 | Alta (7.5) | 77% | — | 19 abr 2022 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.2 and 18; Oracle GraalVM Enterprise… |
| CVE-2018-25032 | Alta (7.5) | 52% | — | 25 mar 2022 | zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. |
| CVE-2021-3772 | Media (6.5) | 1.2% | — | 2 mar 2022 | A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can… |
| CVE-2022-0391 | Alta (7.5) | 8.3% | — | 9 feb 2022 | A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input… |
| CVE-2021-2163 | Media (5.3) | 3.6% | — | 22 abr 2021 | Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u291, 8u281, 11.0.10, 16; Java SE… |
Otros productos de Netapp
Oncommand Insight · 971Active IQ Unified Manager · 848Oncommand Workflow Automation · 743Snapcenter · 575Cloud Backup · 349H700s Firmware · 293H300s Firmware · 292H500s Firmware · 292H410s Firmware · 292E-series Santricity OS Controller · 242H410c Firmware · 240Steelstore Cloud Integrated Storage · 211