Netapp
Management Services FOR Netapp HCI: vulnerabilidades y CVE
Management Services FOR Netapp HCI tiene 17 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-37920 | Crítica (9.8) | 0.57% | — | 25 jul 2023 | Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root… |
| CVE-2023-24329 | Alta (7.5) | 20% | — | 17 feb 2023 | An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters. |
| CVE-2022-23491 | Alta (7.5) | 0.51% | — | 7 dic 2022 | Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from… |
| CVE-2022-38023 | Alta (8.1) | 2.4% | — | 9 nov 2022 | Netlogon RPC Elevation of Privilege Vulnerability |
| CVE-2022-37967 | Alta (7.2) | 4.1% | — | 9 nov 2022 | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2022-37966 | Alta (8.1) | 2.5% | — | 9 nov 2022 | Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability |
| CVE-2022-36033 | Media (6.1) | 1.5% | — | 29 ago 2022 | jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks… |
| CVE-2022-24736 | Media (5.5) | 1.5% | — | 27 abr 2022 | Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of… |
| CVE-2022-24735 | Alta (7.8) | 2.3% | — | 27 abr 2022 | Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Redis prior to version 7.0.0 or 6.2.7 can inject Lua code that will… |
| CVE-2021-3671 | Media (6.5) | 2.1% | — | 12 oct 2021 | A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server. |
| CVE-2021-32762 | Alta (8.8) | 2.6% | — | 4 oct 2021 | Redis is an open source, in-memory database that persists on disk. The redis-cli command line tool and redis-sentinel service may be vulnerable to integer overflow when parsing specially crafted large multi-bulk network… |
| CVE-2021-32687 | Alta (7.5) | 4.1% | — | 4 oct 2021 | Redis is an open source, in-memory database that persists on disk. An integer overflow bug affecting all versions of Redis can be exploited to corrupt the heap and potentially be used to leak arbitrary contents of the… |
| CVE-2021-32675 | Alta (7.5) | 16% | — | 4 oct 2021 | Redis is an open source, in-memory database that persists on disk. When parsing an incoming Redis Standard Protocol (RESP) request, Redis allocates memory according to user-specified values which determine the number of… |
| CVE-2021-32672 | Media (4.3) | 1.8% | — | 4 oct 2021 | Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer.… |
| CVE-2021-32628 | Alta (7.5) | 14% | — | 4 oct 2021 | Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the ziplist data structure used by all versions of Redis can be exploited to corrupt the heap and potentially result with… |
| CVE-2021-32627 | Alta (7.5) | 3.9% | — | 4 oct 2021 | Redis is an open source, in-memory database that persists on disk. In affected versions an integer overflow bug in Redis can be exploited to corrupt the heap and potentially result with remote code execution. The… |
| CVE-2021-32626 | Alta (8.8) | 16% | — | 4 oct 2021 | Redis is an open source, in-memory database that persists on disk. In affected versions specially crafted Lua scripts executing in Redis can cause the heap-based Lua stack to be overflowed, due to incomplete checks for… |
Otros productos de Netapp
Oncommand Insight · 971Active IQ Unified Manager · 848Oncommand Workflow Automation · 743Snapcenter · 575Cloud Backup · 349H700s Firmware · 294H300s Firmware · 293H500s Firmware · 293H410s Firmware · 293E-series Santricity OS Controller · 242H410c Firmware · 241Steelstore Cloud Integrated Storage · 211