VendorsNetAppmanagement_services_for_netapp_hciall versions
Vulnerabilities

NetApp Management Services for NetApp HCI

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2023-37920
Certifi's removal of e-Tugra root certificate
Published 2023-07-25 · Analyzed
9.8EPSS 0.006
CVE-2021-32762
Integer overflow that can lead to heap overflow in redis-cli, redis-sentinel on some platforms
Published 2021-10-04 · Modified
9.0EPSS 0.027
CVE-2021-32626
Lua scripts can overflow the heap-based Lua stack in Redis
Published 2021-10-04 · Modified
8.8EPSS 0.162
CVE-2022-37966
Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability
Published 2022-11-09 · Modified
8.1EPSS 0.025
CVE-2022-38023
Netlogon RPC Elevation of Privilege Vulnerability
Published 2022-11-09 · Modified
8.1EPSS 0.024
CVE-2022-24735
Lua scripts can be manipulated to overcome ACL rules in Redis
Published 2022-04-27 · Modified
7.8EPSS 0.023
CVE-2023-24329
An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
Published 2023-02-17 · Modified
7.5EPSS 0.205
CVE-2021-32675
DoS vulnerability in Redis
Published 2021-10-04 · Modified
7.5EPSS 0.169
CVE-2021-32628
Vulnerability in handling large ziplists
Published 2021-10-04 · Modified
7.5EPSS 0.135
CVE-2021-32687
Integer overflow issue with intsets in Redis
Published 2021-10-04 · Modified
7.5EPSS 0.041
CVE-2021-32627
Integer overflow issue with Streams in Redis
Published 2021-10-04 · Modified
7.5EPSS 0.039
CVE-2022-23491
Removal of TrustCor root certificate
Published 2022-12-07 · Analyzed
7.5EPSS 0.005
CVE-2022-37967
Windows Kerberos Elevation of Privilege Vulnerability
Published 2022-11-09 · Modified
7.2EPSS 0.041
CVE-2021-3671
A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.
Published 2021-10-12 · Modified
6.5EPSS 0.022
CVE-2022-36033
jsoup may not sanitize Cross-Site Scripting (XSS) attempts if SafeList.preserveRelativeLinks is enabled
Published 2022-08-29 · Modified
6.1EPSS 0.015
CVE-2022-24736
A Malformed Lua script can crash Redis
Published 2022-04-27 · Modified
5.5EPSS 0.015
CVE-2021-32672
Vulnerability in Lua Debugger in Redis
Published 2021-10-04 · Modified
5.3EPSS 0.019