← Back

H410s Firmware

h410s_firmware

Vendor: Netapp • 289 CVEs

CVEs (289)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
LinuxNetapp
15500f Firmware
A250 FirmwareCloud Backup+12 more
Nov 21, 2024
May 26, 2021
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.
4Debian
FedoraprojectLinux+1 more
13Cloud Backup
Debian LinuxFedora+10 more
Nov 21, 2024
May 26, 2021
8.7 HIGH· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with th...Show more
An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM to read/write random pages of memory and can result in local privilege escalation.Show less
3Fedoraproject
LinuxNetapp
13Active Iq Unified Manager
Cloud BackupFedora+10 more
Nov 21, 2024
May 26, 2021
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
A vulnerability was found in Linux kernel where non-blocking socket in llcp_sock_connect() leads to leak and eventually hanging-up the system.
4Debian
FedoraprojectLinux+1 more
14Active Iq Unified Manager
Cloud BackupDebian Linux+11 more
Nov 21, 2024
May 26, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability was found in Linux Kernel, where a refcount leak in llcp_sock_connect() causing use-after-free which might lead to privilege escalations.
4Debian
FedoraprojectLinux+1 more
14Active Iq Unified Manager
Cloud BackupDebian Linux+11 more
Nov 21, 2024
May 26, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability was found in Linux Kernel where refcount leak in llcp_sock_bind() causing use-after-free which might lead to privilege escalations.
4Debian
FedoraprojectGnu+1 more
13Cloud Backup
Debian LinuxE Series Santricity Os Controller+10 more
Nov 21, 2024
May 25, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been f...Show more
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.Show less
4Debian
FedoraprojectLinux+1 more
14Active Iq Unified Manager
Cloud BackupDebian Linux+11 more
Nov 21, 2024
May 25, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A memory leak vulnerability was found in Linux kernel in llcp_sock_connect
2Linux
Netapp
10Cloud Backup
H300e FirmwareH300s Firmware+7 more
Nov 21, 2024
May 21, 2021
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order t...Show more
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of eBPF programs. The issue results from the lack of proper validation of user-supplied eBPF programs prior to executing them. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel. Was ZDI-CAN-13661.Show less
3Debian
LinuxNetapp
11Cloud Backup
Debian LinuxH300e Firmware+8 more
Nov 21, 2024
May 17, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list, leading to a use-after-free when one of these devices is removed. The highest threat fro...Show more
A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list, leading to a use-after-free when one of these devices is removed. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. Versions before kernel 5.12-rc6 are affectedShow less
2Linux
Netapp
12Cloud Backup
H300e FirmwareH300s Firmware+9 more
Nov 21, 2024
May 14, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the kernel context and privilege escalation, aka CID-c3e2219216c9. This is related to blk_mq_free_rqs a...Show more
The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the kernel context and privilege escalation, aka CID-c3e2219216c9. This is related to blk_mq_free_rqs and blk_cleanup_queue.Show less
3Debian
LinuxNetapp
11Cloud Backup
Debian LinuxH300e Firmware+8 more
Nov 21, 2024
May 10, 2021
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
net/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condition for removal of the HCI controller.
2Linux
Netapp
11Cloud Backup
H300e FirmwareH300s Firmware+8 more
Nov 21, 2024
May 6, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc5. A bounds check failure allows a local attacker with a user account on the system to gain access t...Show more
An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc5. A bounds check failure allows a local attacker with a user account on the system to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.Show less
4Fedoraproject
LinuxNetapp+1 more
19Cloud Backup
Enterprise LinuxEnterprise Linux For Real Time+16 more
Nov 21, 2024
May 6, 2021
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-boun...Show more
A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.Show less
4Debian
IscNetapp+1 more
14Active Iq Unified Manager
Aff 500f FirmwareAff A250 Firmware+11 more
Nov 21, 2024
Apr 29, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.1 of the BIND 9.17 developm...Show more
In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.1 of the BIND 9.17 development branch, BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server can be rendered vulnerable by explicitly setting values for the tkey-gssapi-keytab or tkey-gssapi-credential configuration options. Although the default configuration is not vulnerable, GSS-TSIG is frequently used in networks where BIND is integrated with Samba, as well as in mixed-server environments that combine BIND servers with Active Directory domain controllers. For servers that meet these conditions, the ISC SPNEGO implementation is vulnerable to various attacks, depending on the CPU architecture for which BIND was built: For named binaries compiled for 64-bit platforms, this flaw can be used to trigger a buffer over-read, leading to a server crash. For named binaries compiled for 32-bit platforms, this flaw can be used to trigger a server crash due to a buffer overflow and possibly also to achieve remote code execution. We have determined that standard SPNEGO implementations are available in the MIT and Heimdal Kerberos libraries, which support a broad range of operating systems, rendering the ISC implementation unnecessary and obsolete. Therefore, to reduce the attack surface for BIND users, we will be removing the ISC SPNEGO implementation in the April releases of BIND 9.11 and 9.16 (it had already been dropped from BIND 9.17). We would not normally remove something from a stable ESV (Extended Support Version) of BIND, but since system libraries can replace the ISC SPNEGO implementation, we have made an exception in this case for reasons of stability and security.Show less
6Debian
FedoraprojectIsc+3 more
16500f Firmware
A250 FirmwareActive Iq Unified Manager+13 more
Nov 21, 2024
Apr 29, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 developm...Show more
In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a query for a record triggering the flaw described above, the named process will terminate due to a failed assertion check. The vulnerability affects all currently maintained BIND 9 branches (9.11, 9.11-S, 9.16, 9.16-S, 9.17) as well as all other versions of BIND 9.Show less
5Debian
FedoraprojectIsc+2 more
15Active Iq Unified Manager
Aff 500f FirmwareAff A250 Firmware+12 more
Nov 21, 2024
Apr 29, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the...Show more
In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a malformed IXFR triggering the flaw described above, the named process will terminate due to a failed assertion the next time the transferred secondary zone is refreshed.Show less
5Broadcom
DebianFedoraproject+2 more
15Brocade Fabric Operating System
Cloud BackupDebian Linux+12 more
Nov 21, 2024
Apr 22, 2021
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called w...Show more
A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket.Show less
3Debian
LinuxNetapp
12Cloud Backup
Debian LinuxH300e Firmware+9 more
Nov 21, 2024
Apr 19, 2021
N/A· v4
7.1 HIGH· v3
5.6 MEDIUM· v2
An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds m...Show more
An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability.Show less
4Debian
FedoraprojectLinux+1 more
13Cloud Backup
Debian LinuxFedora+10 more
Nov 21, 2024
Apr 8, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute arbitrary code within the kernel context. This affects arch/x86/net/bpf_jit_comp.c and ar...Show more
BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute arbitrary code within the kernel context. This affects arch/x86/net/bpf_jit_comp.c and arch/x86/net/bpf_jit_comp32.c.Show less
3Linux
NetappRedhat
18A700s Firmware
Aff A400 FirmwareBrocade Fabric Operating System Firmware+15 more
Nov 21, 2024
Mar 26, 2021
N/A· v4
4.5 MEDIUM· v3
4.4 MEDIUM· v2
A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to...Show more
A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to bypass checks to send any signal to a privileged process.Show less