Netapp

H300s Firmware

293 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.35%
  • Veröffentlicht 23.03.2022 12:15:07
  • Zuletzt bearbeitet 21.11.2024 06:39:04

Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate due to a failed assertion check.

  • EPSS 2.7%
  • Veröffentlicht 23.03.2022 11:15:08
  • Zuletzt bearbeitet 21.11.2024 06:38:32

BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition. Specifically crafted TCP streams can cause connections to BIND to remain in CLOSE_WAIT status for an indefinite period of time, eve...

Medienbericht
  • EPSS 5.52%
  • Veröffentlicht 23.03.2022 06:15:06
  • Zuletzt bearbeitet 01.09.2026 18:05:14

A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation ...

  • EPSS 1.35%
  • Veröffentlicht 22.03.2022 12:15:08
  • Zuletzt bearbeitet 21.11.2024 06:39:08

When the vulnerability is triggered the BIND process will exit. BIND 9.18.0

  • EPSS 1.17%
  • Veröffentlicht 18.03.2022 18:15:12
  • Zuletzt bearbeitet 26.08.2026 18:13:43

A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation.

  • EPSS 5.04%
  • Veröffentlicht 18.03.2022 12:15:07
  • Zuletzt bearbeitet 21.11.2024 06:39:18

Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-memory via icmp6 packets of type 130 or 131. We recommend upgrading past commit 2d3916f3189172d5c69d33065c3c21119fe539fc.

Exploit
  • EPSS 1.34%
  • Veröffentlicht 18.03.2022 07:15:06
  • Zuletzt bearbeitet 21.11.2024 06:33:10

In the Linux kernel before 5.15.3, fs/quota/quota_tree.c does not validate the block number in the quota tree (on disk). This can, for example, lead to a kernel/locking/rwsem.c use-after-free if there is a corrupted quota file.

  • EPSS 2.15%
  • Veröffentlicht 16.03.2022 00:15:09
  • Zuletzt bearbeitet 21.11.2024 06:55:26

In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might be manipulated by the host for out-of-array access.

  • EPSS 0.35%
  • Veröffentlicht 12.03.2022 22:15:08
  • Zuletzt bearbeitet 21.11.2024 06:54:52

An issue was discovered in the Linux kernel before 5.16.12. drivers/net/usb/sr9700.c allows attackers to obtain sensitive information from heap memory via crafted frame lengths from a device.

Warnung Medienbericht Exploit
  • EPSS 88.61%
  • Veröffentlicht 10.03.2022 17:44:57
  • Zuletzt bearbeitet 06.11.2025 14:50:37

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user co...