Home/Product/netapp solidfire baseboard management controller firmware
Product

netapp solidfire baseboard management controller firmware

70 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2021-42252
all versions
An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local a
7.8HIGH
CVE-2021-42008
all versions
The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input
7.8HIGH
CVE-2021-41864
all versions
prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eB
7.8HIGH
CVE-2021-22947
all versions
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, t
5.9MEDIUM
CVE-2021-22946
all versions
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (
7.5HIGH
CVE-2021-22945
all versions
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an alr
9.1CRITICAL
CVE-2021-22924
all versions
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.
3.7LOW
CVE-2021-3612
all versions
An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the w
7.8HIGH
CVE-2021-22901
all versions
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3
8.1HIGH
CVE-2021-22897
all versions
curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIP
5.3MEDIUM
CVE-2019-25045
all versions
An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_state_fini
7.8HIGH
CVE-2020-25668
all versions
A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use af
7.0HIGH
CVE-2021-22543
all versions
An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead t
7.8HIGH
CVE-2020-25673
all versions
A vulnerability was found in Linux kernel where non-blocking socket in llcp_sock_connect() leads to leak and eventually hanging-up
5.5MEDIUM
CVE-2020-25671
all versions
A vulnerability was found in Linux Kernel, where a refcount leak in llcp_sock_connect() causing use-after-free which might lead to
7.8HIGH
CVE-2020-25670
all versions
A vulnerability was found in Linux Kernel where refcount leak in llcp_sock_bind() causing use-after-free which might lead to privi
7.8HIGH
CVE-2021-33574
all versions
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification t
9.8CRITICAL
CVE-2020-25672
all versions
A memory leak vulnerability was found in Linux kernel in llcp_sock_connect
7.5HIGH
CVE-2021-31440
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker mu
7.0HIGH
CVE-2019-25044
all versions
The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the kernel co
7.8HIGH
CVE-2021-32399
all versions
net/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condition for removal of the HCI controller.
7.0HIGH
CVE-2020-35519
all versions
An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc5. A bound
7.8HIGH
CVE-2021-3501
all versions
A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array i
7.1HIGH
CVE-2021-23133
all versions
A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the
6.7MEDIUM
CVE-2021-3506
all versions
An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.
7.1HIGH
CVE-2021-28972
all versions
In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer
6.7MEDIUM
CVE-2021-28971
all versions
In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, userspace appli
5.5MEDIUM
CVE-2021-28964
all versions
A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11.8. It allows attackers to cau
4.7MEDIUM
CVE-2021-28952
all versions
An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire device driver has a buffer overf
7.8HIGH
CVE-2021-28951
all versions
An issue was discovered in fs/io_uring.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (dea
5.5MEDIUM
CVE-2021-28660
all versions
rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end
8.8HIGH
CVE-2021-28375
all versions
An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent use
7.8HIGH
CVE-2021-27365
all versions
An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constrain
7.8HIGH
CVE-2021-27364
all versions
An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the abili
7.1HIGH
CVE-2021-27363
all versions
An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscs
4.4MEDIUM
CVE-2021-28039
all versions
An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV
6.5MEDIUM
CVE-2021-28038
all versions
An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necess
6.5MEDIUM
CVE-2020-36158
all versions
mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remo
8.8HIGH
CVE-2020-27825
all versions
A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race problem in trace
5.7MEDIUM
CVE-2020-27350
all versions
APT had several integer overflows and underflows while parsing .deb packages, aka GHSL-2020-168 GHSL-2020-169, in files apt-pkg/co
5.7MEDIUM
CVE-2020-29661
all versions
A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-aft
7.8HIGH
CVE-2020-29660
all versions
A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and dri
4.4MEDIUM
CVE-2020-25692
all versions
A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An u
7.5HIGH
CVE-2020-14305
all versions
An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality han
8.1HIGH
CVE-2020-29370
all versions
An issue was discovered in kmem_cache_alloc_bulk in mm/slub.c in the Linux kernel before 5.5.11. The slowpath lacks the required T
7.0HIGH
CVE-2020-15436
all versions
Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a den
6.7MEDIUM
CVE-2020-14356
all versions
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot
7.8HIGH
CVE-2020-13143
all versions
gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without consi
6.5MEDIUM
CVE-2020-12888
all versions
The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.
5.3MEDIUM
CVE-2020-8832
all versions
The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on c
5.5MEDIUM
CVE-2020-9383
all versions
An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of
7.1HIGH
CVE-2019-19448
all versions
In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a sy
7.8HIGH
CVE-2019-14815
all versions
A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marvell Wifi Dr
7.8HIGH
CVE-2019-19063
all versions
Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c in the Linux kernel through 5.3.11
4.6MEDIUM
CVE-2019-19061
all versions
A memory leak in the adis_update_scan_mode_burst() function in drivers/iio/imu/adis_buffer.c in the Linux kernel before 5.3.9 allo
7.5HIGH
CVE-2019-19060
all versions
A memory leak in the adis_update_scan_mode() function in drivers/iio/imu/adis_buffer.c in the Linux kernel before 5.3.9 allows att
7.5HIGH
CVE-2019-19057
all versions
Two memory leaks in the mwifiex_pcie_init_evt_ring() function in drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel t
3.3LOW
CVE-2019-19054
all versions
A memory leak in the cx23888_ir_probe() function in drivers/media/pci/cx23885/cx23888-ir.c in the Linux kernel through 5.3.11 allo
4.7MEDIUM
CVE-2019-19053
all versions
A memory leak in the rpmsg_eptdev_write_iter() function in drivers/rpmsg/rpmsg_char.c in the Linux kernel through 5.3.11 allows at
7.5HIGH
CVE-2019-19052
all versions
A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel before 5.3.11 allows attackers to
7.5HIGH
CVE-2019-19044
all versions
Two memory leaks in the v3d_submit_cl_ioctl() function in drivers/gpu/drm/v3d/v3d_gem.c in the Linux kernel before 5.3.11 allow at
7.5HIGH
CVE-2019-14591
all versions
Improper input validation in the API for Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user t
5.5MEDIUM
CVE-2019-14590
all versions
Improper access control in the API for the Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user
5.5MEDIUM
CVE-2019-14574
all versions
Out of bounds read in a subsystem for Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to p
5.5MEDIUM
CVE-2019-11113
all versions
Buffer overflow in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6618 (DCH) or 21.20.x.5077 (aka15.45.5
4.4MEDIUM
CVE-2019-11111
all versions
Pointer corruption in the Unified Shader Compiler in Intel(R) Graphics Drivers before 10.18.14.5074 (aka 15.36.x.5074) may allow a
7.8HIGH
CVE-2019-11089
all versions
Insufficient input validation in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6519 may allow an authen
5.5MEDIUM
CVE-2019-2215
all versions
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is requ
7.8HIGH
CVE-2019-5481
all versions
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
9.8CRITICAL
CVE-2019-15118
all versions
check_input_term in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles recursion, leading to kernel stack exhaustion.
5.5MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin