← Back

Zfs Storage Appliance Kit

zfs_storage_appliance_kit

Vendor: Oracle • 117 CVEs

CVEs (117)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Apache
AppleDebian+2 more
8Debian Linux
Enterprise Manager Ops CenterFedora+5 more
Nov 21, 2024
Mar 14, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
5Apache
AppleDebian+2 more
7Debian Linux
FedoraHttp Server+4 more
Nov 21, 2024
Mar 14, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.
4Debian
FedoraprojectOracle+1 more
5Debian Linux
FedoraHttp Server+2 more
Nov 25, 2024
Mar 3, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version iden...Show more
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier. This ends up with a buffer using all the available memory. The attach is a simple as `nc -rv localhost 22 < /dev/zero`. A patch is available in version 22.2.0. There are currently no known workarounds.Show less
6Apple
DebianFedoraproject+3 more
35Active Iq Unified Manager
Bootstrap OsClustered Data Ontap+32 more
May 5, 2025
Feb 26, 2022
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
6Canonical
DebianFedoraproject+3 more
6Debian Linux
Enterprise LinuxFedora+3 more
Nov 21, 2024
Feb 21, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outa...Show more
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawnedShow less
5Debian
FedoraprojectLibexpat Project+2 more
6Debian Linux
FedoraHttp Server+3 more
May 5, 2025
Feb 18, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
5Debian
FedoraprojectLibexpat Project+2 more
6Debian Linux
FedoraHttp Server+3 more
May 5, 2025
Feb 18, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
5Debian
FedoraprojectLibexpat Project+2 more
6Debian Linux
FedoraHttp Server+3 more
May 30, 2025
Feb 18, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
4Debian
Libexpat ProjectOracle+1 more
5Debian Linux
Http ServerLibexpat+2 more
May 5, 2025
Feb 16, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
5Debian
FedoraprojectLibexpat Project+2 more
6Debian Linux
FedoraHttp Server+3 more
May 5, 2025
Feb 16, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
4Fedoraproject
NetappOracle+1 more
10Active Iq Unified Manager
FedoraHci+7 more
Dec 17, 2025
Feb 9, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input...Show more
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.Show less
7Canonical
OraclePolkit Project+4 more
30Command Center
Enterprise LinuxEnterprise Linux Desktop+27 more
Nov 6, 2025
Jan 28, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined polic...Show more
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.Show less
1Oracle
3Http Server
SolarisZfs Storage Appliance Kit
Nov 21, 2024
Jan 19, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastru...Show more
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).Show less
2Netapp
Oracle
197 Mode Transition Tool
Active Iq Unified ManagerCloud Insights Acquisition Unit+16 more
Nov 21, 2024
Jan 19, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13; Oracle GraalVM Ente...Show more
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).Show less
4Debian
FedoraprojectOracle+1 more
5Debian Linux
FedoraHttp Server+2 more
Nov 3, 2025
Dec 30, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
4Debian
FedoraprojectOracle+1 more
5Debian Linux
FedoraHttp Server+2 more
Nov 3, 2025
Dec 30, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
3Fedoraproject
OracleWireshark
4Fedora
Http ServerWireshark+1 more
Nov 21, 2024
Dec 30, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file
3Fedoraproject
OracleWireshark
4Fedora
Http ServerWireshark+1 more
Nov 3, 2025
Dec 30, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
4Debian
FedoraprojectOracle+1 more
5Debian Linux
FedoraHttp Server+2 more
Nov 3, 2025
Dec 30, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
7Apache
AppleDebian+4 more
14Cloud Backup
Communications Element ManagerCommunications Operations Monitor+11 more
May 1, 2025
Dec 20, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might...Show more
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.Show less