📦 Solidfire \& Hci Storage Node

by Netapp

🔍 What is Solidfire \& Hci Storage Node?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-40896

CRITICAL CVSS 9.1 Dec 23, 2024

This vulnerability in libxml2 allows attackers to bypass custom SAX handler protections against external entity processing, enabling classic XML External Entity (XXE) attacks. Any application using af...

CVE-2023-38426

CRITICAL CVSS 9.1 Jul 18, 2023

This vulnerability in the Linux kernel's ksmbd SMB server allows attackers to read memory beyond allocated buffers when processing SMB2 create context requests. It affects Linux systems running kernel...

CVE-2023-38428

CRITICAL CVSS 9.1 Jul 18, 2023

This vulnerability in the Linux kernel's ksmbd SMB server allows attackers to read memory beyond intended boundaries by exploiting improper validation of UserName values. Systems running Linux kernels...

CVE-2023-38432

CRITICAL CVSS 9.1 Jul 18, 2023

This vulnerability in the Linux kernel's ksmbd SMB server allows attackers to trigger an out-of-bounds read by sending specially crafted SMB packets with mismatched payload size and RFC1002 length spe...

CVE-2021-44228

CRITICAL CVSS 10.0 Dec 10, 2021

CVE-2021-44228 (Log4Shell) is a critical remote code execution vulnerability in Apache Log4j2 that allows attackers to execute arbitrary code by exploiting JNDI lookups in log messages. This affects a...

CVE-2023-5178

HIGH CVSS 8.8 Nov 1, 2023

This CVE describes a use-after-free vulnerability in the NVMe/TCP subsystem of the Linux kernel that could allow attackers to execute arbitrary code or escalate privileges. It affects Linux systems wi...

CVE-2023-37920

HIGH CVSS 7.5 Jul 25, 2023

This vulnerability affects systems using certifi Python package versions before 2023.07.22, which included compromised e-Tugra root certificates. Attackers could perform man-in-the-middle attacks or s...

CVE-2022-2048

HIGH CVSS 7.5 Jul 7, 2022

This vulnerability in Eclipse Jetty's HTTP/2 server implementation allows attackers to cause denial of service by sending invalid HTTP/2 requests that trigger resource cleanup failures. The bug preven...

CVE-2022-27775

HIGH CVSS 7.5 Jun 2, 2022

This curl vulnerability allows information disclosure when an attacker can force curl to reuse an existing IPv6 connection from the pool with a different zone identifier, potentially exposing sensitiv...