📦 H500s Firmware

by Netapp

🔍 What is H500s Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-54085

CRITICAL CVSS 9.8 Mar 11, 2025

CVE-2024-54085 is a critical authentication bypass vulnerability in AMI's SPx BMC firmware that allows remote attackers to gain unauthorized access through the Redfish Host Interface without credentia...

CVE-2025-0665

CRITICAL CVSS 9.8 Feb 5, 2025

libcurl incorrectly closes the same eventfd file descriptor twice during threaded name resolution cleanup, causing a use-after-free condition. This vulnerability affects applications using libcurl wit...

CVE-2024-40896

CRITICAL CVSS 9.1 Dec 23, 2024

This vulnerability in libxml2 allows attackers to bypass custom SAX handler protections against external entity processing, enabling classic XML External Entity (XXE) attacks. Any application using af...

CVE-2023-23914

CRITICAL CVSS 9.1 Feb 23, 2023

A vulnerability in curl versions before 7.88.0 causes HSTS (HTTP Strict Transport Security) to fail when processing multiple URLs sequentially on the same command line. This allows sensitive informati...

CVE-2022-32221

CRITICAL CVSS 9.8 Dec 5, 2022

This vulnerability in libcurl allows an attacker to cause memory corruption or data leakage when reusing a handle from a PUT to a POST request. Applications using libcurl for HTTP(S) transfers with re...

CVE-2022-32207

CRITICAL CVSS 9.8 Jul 7, 2022

CVE-2022-32207 is a privilege escalation vulnerability in curl versions before 7.84.0 where file permission widening occurs during atomic file operations. When curl saves cookies, alt-svc, or hsts dat...

CVE-2022-1587

CRITICAL CVSS 9.1 May 16, 2022

An out-of-bounds read vulnerability in PCRE2 library's JIT compiler allows reading memory beyond allocated buffers during recursive regular expression processing. This affects any software using PCRE2...

CVE-2022-29155

CRITICAL CVSS 9.8 May 4, 2022

This CVE describes a SQL injection vulnerability in OpenLDAP's experimental back-sql backend. Attackers can execute arbitrary SQL commands via specially crafted LDAP search filters, potentially compro...

CVE-2022-0742

CRITICAL CVSS 9.1 Mar 18, 2022

A memory leak vulnerability in the Linux kernel's ICMPv6 implementation allows remote attackers to cause denial-of-service by sending crafted ICMPv6 packets (types 130 or 131), leading to system memor...

CVE-2021-42377

CRITICAL CVSS 9.8 Nov 15, 2021

CVE-2021-42377 is a critical vulnerability in BusyBox's hush shell applet where an attacker-controlled pointer free leads to denial of service and potential remote code execution when processing a cra...

CVE-2021-33574

CRITICAL CVSS 9.8 May 25, 2021

This CVE describes a use-after-free vulnerability in the GNU C Library (glibc) mq_notify function affecting versions 2.32 and 2.33. Attackers could exploit this to cause denial of service (application...

CVE-2025-24928

HIGH CVSS 7.8 Feb 18, 2025

This CVE describes a stack-based buffer overflow vulnerability in libxml2's xmlSnprintfElements function. Attackers can exploit this by providing malicious XML documents with DTD validation enabled, p...

CVE-2024-33599

HIGH CVSS 8.1 May 6, 2024

A stack-based buffer overflow vulnerability in nscd (Name Service Cache Daemon) allows attackers to execute arbitrary code or crash the service when netgroup cache is exhausted. This affects systems r...

CVE-2024-33601

HIGH CVSS 7.3 May 6, 2024

A memory allocation failure in nscd's netgroup cache can cause the daemon to terminate, resulting in denial of service for clients relying on name service caching. This affects systems running glibc 2...

CVE-2024-2398

HIGH CVSS 8.6 Mar 27, 2024

CVE-2024-2398 is a memory leak vulnerability in libcurl that occurs when HTTP/2 server push headers exceed the 1000-header limit. This allows attackers to cause denial of service through resource exha...

CVE-2024-28757

HIGH CVSS 7.5 Mar 10, 2024

CVE-2024-28757 is an XML Entity Expansion vulnerability in libexpat that allows attackers to cause denial of service through resource exhaustion when external parsers are created via XML_ExternalEntit...

CVE-2023-4911

HIGH CVSS 7.8 Oct 3, 2023

CVE-2023-4911 is a buffer overflow vulnerability in the GNU C Library's dynamic loader (ld.so) that allows local attackers to exploit SUID binaries. By crafting malicious GLIBC_TUNABLES environment va...

CVE-2023-4236

HIGH CVSS 7.5 Sep 20, 2023

A denial-of-service vulnerability in BIND 9's DNS-over-TLS implementation causes the named service to crash when handling high volumes of DNS-over-TLS queries due to assertion failures from incorrect ...

CVE-2023-32252

HIGH CVSS 7.5 Jul 24, 2023

This vulnerability in the Linux kernel's ksmbd SMB server allows attackers to cause a denial-of-service by sending specially crafted SMB2_LOGOFF commands. The flaw exists due to improper pointer valid...

CVE-2023-2829

HIGH CVSS 7.5 Jun 21, 2023

A vulnerability in BIND 9 DNS servers configured with DNSSEC validation and aggressive cache usage allows remote attackers to cause denial of service by sending specially crafted NSEC records. This af...

CVE-2023-35788

HIGH CVSS 7.8 Jun 16, 2023

This vulnerability allows attackers to perform out-of-bounds writes in the Linux kernel's flower classifier code via specially crafted GENEVE packets. It affects Linux systems running kernel versions ...

CVE-2023-3111

HIGH CVSS 7.8 Jun 5, 2023

A use-after-free vulnerability in the Linux kernel's Btrfs filesystem allows local attackers to potentially crash the system or execute arbitrary code with kernel privileges. This affects Linux system...

CVE-2023-2953

HIGH CVSS 7.5 May 30, 2023

This vulnerability in OpenLDAP causes a null pointer dereference in the ber_memalloc_x() function, which can lead to denial of service (DoS) by crashing the LDAP service. Any system running vulnerable...

CVE-2023-28319

HIGH CVSS 7.5 May 26, 2023

CVE-2023-28319 is a use-after-free vulnerability in curl/libcurl versions before 8.1.0 that occurs during SSH server public key verification. When verification fails, curl frees memory containing the ...

CVE-2023-2124

HIGH CVSS 7.8 May 15, 2023

A local privilege escalation vulnerability exists in the Linux kernel's XFS filesystem when restoring from a dirty log journal after failure. This allows a local attacker to trigger out-of-bounds memo...

CVE-2023-28464

HIGH CVSS 7.8 Mar 31, 2023

This vulnerability is a use-after-free and double-free flaw in the Linux kernel's Bluetooth subsystem that can lead to privilege escalation. Attackers with local access can exploit memory corruption t...

CVE-2023-27533

HIGH CVSS 8.8 Mar 30, 2023

A vulnerability in curl versions before 8.0 allows attackers to inject malicious content during TELNET protocol negotiation when user input is accepted. This could lead to arbitrary code execution on ...

CVE-2023-27534

HIGH CVSS 8.8 Mar 30, 2023

A path traversal vulnerability in curl's SFTP implementation allows attackers to bypass path filtering by using specially crafted paths containing tilde characters. This affects curl versions before 8...

CVE-2023-1077

HIGH CVSS 7.0 Mar 27, 2023

CVE-2023-1077 is a type confusion vulnerability in the Linux kernel's real-time scheduler that can lead to memory corruption. This allows local attackers to potentially escalate privileges or cause de...

CVE-2023-1380

HIGH CVSS 7.1 Mar 27, 2023

This CVE describes an out-of-bounds read vulnerability in the Broadcom brcmfmac WiFi driver in the Linux kernel. When processing association request data, the driver can read beyond allocated memory b...

CVE-2023-0386

HIGH CVSS 7.8 Mar 22, 2023

This Linux kernel vulnerability allows local users to escalate privileges by exploiting a uid mapping bug in OverlayFS when copying capable files between mounts. Attackers can gain root access on affe...

CVE-2022-1998

HIGH CVSS 7.8 Jun 9, 2022

CVE-2022-1998 is a use-after-free vulnerability in the Linux kernel's fanotify file system notification subsystem. A local attacker could trigger this flaw to crash the system or potentially escalate ...

CVE-2022-32250

HIGH CVSS 7.8 Jun 2, 2022

This vulnerability in the Linux kernel's netfilter component allows a local user with namespace creation privileges to escalate to root via a use-after-free condition. It affects Linux kernel versions...

CVE-2022-27780

HIGH CVSS 7.5 Jun 2, 2022

The curl URL parser incorrectly accepts percent-encoded URL separators like '/' in hostnames, allowing attackers to bypass filters and checks by making malicious URLs appear legitimate. This affects a...

CVE-2022-27775

HIGH CVSS 7.5 Jun 2, 2022

This curl vulnerability allows information disclosure when an attacker can force curl to reuse an existing IPv6 connection from the pool with a different zone identifier, potentially exposing sensitiv...

CVE-2022-1786

HIGH CVSS 7.8 Jun 2, 2022

A use-after-free vulnerability in the Linux kernel's io_uring subsystem allows local attackers to crash the system or potentially escalate privileges. This affects Linux systems with specific io_uring...

CVE-2022-1652

HIGH CVSS 7.8 Jun 2, 2022

CVE-2022-1652 is a use-after-free vulnerability in the Linux kernel's floppy disk driver that allows local attackers to execute arbitrary code or cause denial of service. This affects Linux systems wi...

CVE-2022-1882

HIGH CVSS 7.8 May 26, 2022

CVE-2022-1882 is a use-after-free vulnerability in the Linux kernel's pipes functionality that allows a local user to crash the system or potentially escalate privileges. This affects Linux systems wi...

CVE-2022-1183

HIGH CVSS 7.5 May 19, 2022

This vulnerability causes the BIND DNS server to crash with an assertion failure when configured with HTTP references in listen-on statements. It affects BIND servers using DNS over HTTPS (DoH) config...

CVE-2022-1734

HIGH CVSS 7.0 May 18, 2022

A use-after-free vulnerability in the Linux kernel's NFC Marvell driver allows attackers to potentially execute arbitrary code or cause denial of service. This affects Linux systems with the nfcmrvl d...

CVE-2022-29581

HIGH CVSS 7.8 May 17, 2022

A local privilege escalation vulnerability in the Linux kernel's net/sched subsystem allows attackers with local access to gain root privileges. This affects Linux kernel versions 4.14 through 5.17. T...

CVE-2022-1679

HIGH CVSS 7.8 May 16, 2022

CVE-2022-1679 is a use-after-free vulnerability in the Linux kernel's Atheros wireless adapter driver (ath9k_htc). It allows a local attacker to crash the system or potentially escalate privileges by ...

CVE-2022-1292

HIGH CVSS 7.3 May 3, 2022

CVE-2022-1292 is a command injection vulnerability in the c_rehash script distributed with OpenSSL. It allows attackers to execute arbitrary commands with script privileges when the script processes u...

CVE-2022-1473

HIGH CVSS 7.5 May 3, 2022

A memory leak vulnerability in OpenSSL's OPENSSL_LH_flush() function causes unbounded memory growth when processing certificates or keys. This affects long-lived processes like TLS clients/servers usi...

CVE-2022-1048

HIGH CVSS 7.0 Apr 29, 2022

A use-after-free vulnerability in the Linux kernel's sound subsystem allows local attackers to trigger race conditions in ALSA PCM ioctl operations. This can lead to system crashes or potential privil...

CVE-2022-1353

HIGH CVSS 7.1 Apr 29, 2022

A local privilege escalation vulnerability in the Linux kernel's pfkey_register function allows unprivileged local users to access kernel memory. This can lead to system crashes or information disclos...

CVE-2022-29156

HIGH CVSS 7.8 Apr 13, 2022

CVE-2022-29156 is a double-free vulnerability in the Linux kernel's RDMA Transport (RTRS) client driver that could allow local attackers to cause a kernel panic or potentially execute arbitrary code. ...

CVE-2022-28893

HIGH CVSS 7.8 Apr 11, 2022

This vulnerability in the Linux kernel's SUNRPC subsystem allows a use-after-free condition when freeing transport structures before sockets are properly closed. Attackers could potentially exploit th...

CVE-2022-28796

HIGH CVSS 7.0 Apr 8, 2022

CVE-2022-28796 is a use-after-free vulnerability in the Linux kernel's jbd2 journaling subsystem caused by a transaction_t race condition. This allows local attackers to potentially escalate privilege...

CVE-2022-1055

HIGH CVSS 7.8 Mar 29, 2022

CVE-2022-1055 is a use-after-free vulnerability in the Linux kernel's tc_new_tfilter function that allows local attackers to escalate privileges. The exploit requires unprivileged user namespaces to b...

CVE-2022-0330

HIGH CVSS 7.8 Mar 25, 2022

A memory access vulnerability in the Linux kernel's i915 GPU driver allows local attackers to execute malicious GPU code, potentially causing system crashes or privilege escalation. This affects Linux...

CVE-2023-28322

LOW CVSS 3.7 May 26, 2023

This vulnerability in curl versions before 8.1.0 causes information disclosure when reusing a handle between PUT and POST requests. It affects applications using libcurl for HTTP(S) transfers where th...