7.3

CVE-2024-2961

The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GnuGlibc Version >= 2.1.93 < 2.40
NetappActive Iq Unified Manager Version- SwPlatformvmware_vsphere
DebianDebian Linux Version10.0
NetappHci H300s Firmware Version-
   NetappHci H300s Version-
NetappHci H500s Firmware Version-
   NetappHci H500s Version-
NetappHci H700s Firmware Version-
   NetappHci H700s Version-
NetappHci H410s Firmware Version-
   NetappHci H410s Version-
NetappHci H410c Firmware Version-
   NetappHci H410c Version-
NetappHci H610c Firmware Version-
   NetappHci H610c Version-
NetappHci H610s Firmware Version-
   NetappHci H610s Version-
NetappHci H615c Firmware Version-
   NetappHci H615c Version-
NetappHci Compute Node Version-
   NetappHci Compute Node Version-
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 91.92% 0.997
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.3 2.5 4.7
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.