📦 Solidfire \& Hci Management Node

by Netapp

🔍 What is Solidfire \& Hci Management Node?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-40896

CRITICAL CVSS 9.1 Dec 23, 2024

This vulnerability in libxml2 allows attackers to bypass custom SAX handler protections against external entity processing, enabling classic XML External Entity (XXE) attacks. Any application using af...

CVE-2023-38426

CRITICAL CVSS 9.1 Jul 18, 2023

This vulnerability in the Linux kernel's ksmbd SMB server allows attackers to read memory beyond allocated buffers when processing SMB2 create context requests. It affects Linux systems running kernel...

CVE-2023-38428

CRITICAL CVSS 9.1 Jul 18, 2023

This vulnerability in the Linux kernel's ksmbd SMB server allows attackers to read memory beyond intended boundaries by exploiting improper validation of UserName values. Systems running Linux kernels...

CVE-2021-26987

CRITICAL CVSS 9.8 Mar 15, 2021

This vulnerability allows remote code execution on systems running vulnerable versions of the Element Plug-in for vCenter Server. Attackers can exploit a flaw in the SpringBoot Framework to execute ar...

CVE-2025-24928

HIGH CVSS 7.8 Feb 18, 2025

This CVE describes a stack-based buffer overflow vulnerability in libxml2's xmlSnprintfElements function. Attackers can exploit this by providing malicious XML documents with DTD validation enabled, p...

CVE-2023-5178

HIGH CVSS 8.8 Nov 1, 2023

This CVE describes a use-after-free vulnerability in the NVMe/TCP subsystem of the Linux kernel that could allow attackers to execute arbitrary code or escalate privileges. It affects Linux systems wi...

CVE-2022-27780

HIGH CVSS 7.5 Jun 2, 2022

The curl URL parser incorrectly accepts percent-encoded URL separators like '/' in hostnames, allowing attackers to bypass filters and checks by making malicious URLs appear legitimate. This affects a...

CVE-2022-27775

HIGH CVSS 7.5 Jun 2, 2022

This curl vulnerability allows information disclosure when an attacker can force curl to reuse an existing IPv6 connection from the pool with a different zone identifier, potentially exposing sensitiv...

CVE-2022-27778

HIGH CVSS 8.1 Jun 2, 2022

This vulnerability in curl versions before 7.83.1 could cause the wrong file to be deleted when using the --no-clobber option with --remove-on-error. It affects systems using curl with these specific ...

CVE-2022-1292

HIGH CVSS 7.3 May 3, 2022

CVE-2022-1292 is a command injection vulnerability in the c_rehash script distributed with OpenSSL. It allows attackers to execute arbitrary commands with script privileges when the script processes u...

CVE-2022-1473

HIGH CVSS 7.5 May 3, 2022

A memory leak vulnerability in OpenSSL's OPENSSL_LH_flush() function causes unbounded memory growth when processing certificates or keys. This affects long-lived processes like TLS clients/servers usi...

CVE-2022-21449

HIGH CVSS 7.5 Apr 19, 2022

This vulnerability in Oracle Java SE and GraalVM Enterprise Edition allows unauthenticated attackers with network access to modify critical data without authorization. It affects Java deployments runn...

CVE-2022-28893

HIGH CVSS 7.8 Apr 11, 2022

This vulnerability in the Linux kernel's SUNRPC subsystem allows a use-after-free condition when freeing transport structures before sockets are properly closed. Attackers could potentially exploit th...

CVE-2022-28796

HIGH CVSS 7.0 Apr 8, 2022

CVE-2022-28796 is a use-after-free vulnerability in the Linux kernel's jbd2 journaling subsystem caused by a transaction_t race condition. This allows local attackers to potentially escalate privilege...

CVE-2022-0492

HIGH CVSS 7.8 Mar 3, 2022

CVE-2022-0492 is a Linux kernel vulnerability in the cgroups v1 release_agent feature that allows local attackers to escalate privileges and escape container namespaces. This affects Linux systems usi...

CVE-2022-23308

HIGH CVSS 7.5 Feb 26, 2022

CVE-2022-23308 is a use-after-free vulnerability in libxml2's validation component that allows attackers to potentially execute arbitrary code or cause denial of service. It affects applications that ...

CVE-2021-20322

HIGH CVSS 7.4 Feb 18, 2022

This Linux kernel vulnerability allows remote attackers to bypass UDP source port randomization by exploiting flaws in ICMP error processing. Attackers can scan open UDP ports more effectively, compro...

CVE-2021-46143

HIGH CVSS 8.1 Jan 6, 2022

CVE-2021-46143 is an integer overflow vulnerability in Expat's XML parser that can lead to heap memory corruption. Attackers can exploit this by providing specially crafted XML input, potentially caus...

CVE-2021-22901

HIGH CVSS 8.1 Jun 11, 2021

CVE-2021-22901 is a use-after-free vulnerability in curl/libcurl that allows a malicious TLS 1.3 server to potentially execute arbitrary code on the client. This affects curl clients using OpenSSL wit...

CVE-2021-33200

HIGH CVSS 7.8 May 27, 2021

This vulnerability in the Linux kernel's BPF verifier allows incorrect pointer arithmetic limits, enabling out-of-bounds memory access. Attackers can exploit this to read/write kernel memory and escal...

CVE-2021-25217

HIGH CVSS 7.4 May 26, 2021

A memory corruption vulnerability in ISC DHCP allows attackers to cause denial of service by crashing dhclient or dhcpd processes when they parse malicious lease files. The vulnerability affects DHCP ...

CVE-2020-25669

HIGH CVSS 7.8 May 26, 2021

This CVE describes a use-after-free vulnerability in the Linux kernel's Sun keyboard driver (sunkbd). An attacker with local access can potentially exploit this to cause a kernel crash (denial of serv...