CVEs (289)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Busybox FedoraprojectNetapp12Busybox Cloud BackupFedora+9 moreNov 21, 2024 Nov 15, 2021 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare...Show more |
3Busybox FedoraprojectNetapp12Busybox Cloud BackupFedora+9 moreApr 23, 2025 Nov 15, 2021 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be u...Show more |
3Busybox FedoraprojectNetapp12Busybox Cloud BackupFedora+9 moreNov 3, 2025 Nov 15, 2021 N/A· v4 5.3 MEDIUM· v3 3.3 LOW· v2 An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that |
3Busybox FedoraprojectNetapp12Busybox Cloud BackupFedora+9 moreNov 21, 2024 Nov 15, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given |
3Debian GmplibNetapp8Active Iq Unified Manager Debian LinuxGmp+5 moreNov 21, 2024 Nov 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms. |
3Fedoraproject LinuxNetapp9Fedora H300e FirmwareH300s Firmware+6 moreNov 21, 2024 Nov 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplie...Show more |
2Linux Netapp9Cloud Backup H300e FirmwareH300s Firmware+6 moreNov 21, 2024 Nov 2, 2021 N/A· v4 8.8 HIGH· v3 4.6 MEDIUM· v2 Insufficient data validation in waitid allowed an user to escape sandboxes on Linux. |
2Linux Netapp9H300e Firmware H300s FirmwareH410c Firmware+6 moreNov 21, 2024 Oct 28, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered in the Linux kernel before 5.14.8. A use-after-free in selinux_ptrace_traceme (aka the SELinux handler for PTRACE_TRACEME) could be used by local attackers to cause memory corruption and escalate...Show more |
6Debian FedoraprojectIsc+3 more15Bind Cloud BackupDebian Linux+12 moreNov 21, 2024 Oct 27, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development b...Show more |
6Drupal FedoraprojectJqueryui+3 more27Agile Plm Application ExpressBanking Platform+24 moreNov 4, 2025 Oct 26, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in...Show more |
7Debian DrupalFedoraproject+4 more28Agile Plm Application ExpressBanking Platform+25 moreNov 21, 2024 Oct 26, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fi...Show more |
7Debian DrupalFedoraproject+4 more29Agile Plm Application ExpressBanking Platform+26 moreNov 21, 2024 Oct 26, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixe...Show more |
3Fedoraproject LinuxNetapp10Fedora H300e FirmwareH300s Firmware+7 moreNov 21, 2024 Oct 21, 2021 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 dp_link_settings_write in drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c in the Linux kernel through 5.14.14 allows a heap-based buffer overflow by an attacker who can write a string to the AMD GPU display dri...Show more |
2Linux Netapp10H300e Firmware H300s FirmwareH410c Firmware+7 moreNov 21, 2024 Oct 11, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the ker...Show more |
3Debian LinuxNetapp11Debian Linux H300e FirmwareH300s Firmware+8 moreNov 21, 2024 Oct 5, 2021 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input from a process that has the CAP_NET_ADMIN capability can lead to root access. |
4Debian FedoraprojectLinux+1 more15Cloud Backup Debian LinuxFedora+12 moreNov 21, 2024 Oct 2, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write. |
8Apple DebianFedoraproject+5 more26Cloud Backup Clustered Data OntapCommerce Guided Search+23 moreApr 16, 2026 Sep 29, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl woul...Show more |
8Apple DebianFedoraproject+5 more29Cloud Backup Clustered Data OntapCommerce Guided Search+26 moreApr 16, 2026 Sep 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLU...Show more |
8Apple DebianFedoraproject+5 more17Cloud Backup Clustered Data OntapDebian Linux+14 moreJun 9, 2025 Sep 23, 2021 N/A· v4 9.1 CRITICAL· v3 5.8 MEDIUM· v2 When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also...Show more |
3Debian LinuxNetapp11Cloud Backup Debian LinuxH300e Firmware+8 moreNov 21, 2024 Sep 20, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 arch/mips/net/bpf_jit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when transforming unprivileged cBPF programs, allowing execution of arbitrary code within the kernel context. This occurs be...Show more |