H500e

Vendor:

First CVE: Jul 30, 2019 · Active for 6 years

149
Total CVEs
More Total CVEs than 99% of tracked products
37.3
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
2.0%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact H500e over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 30, 2019
6 years ago
Most Recent CVE
May 26, 2022
1,520 days ago

CVE Severity & Scoring

H500e149 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local95 (63.8%)
Network49 (32.9%)
Unknown0 (0.0%)
Physical2 (1.3%)
Adjacent Network3 (2.0%)
Attack Complexity
Low124 (83.2%)
High25 (16.8%)
Unknown0 (0.0%)
User Interaction
None138 (92.6%)
Unknown0 (0.0%)
Required11 (7.4%)
Privileges Required
Low95 (63.8%)
High7 (4.7%)
None47 (31.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (149 CVEs).

149 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux ker
Mar 10, 20227.898YESYES
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's
Apr 29, 20206.195YESYES
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append
Apr 29, 20206.183NOYES
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters
Feb 11, 20228.477YESNO
In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.
Apr 29, 20219.876NONO
The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is autom
May 3, 20227.368NONO
A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is
Mar 25, 20228.867NONO
An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit
Nov 2, 20219.864NONO
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malic
Jun 11, 20218.160NONO
Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate
Dec 14, 20217.544NONO

Exploit Exposure

Signals from CVEs in this product scope (149 CVEs).

CISA KEV
3 CVEs
2.0% of CVEs· 96th percentile
Metasploit
2 CVEs
1.3% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
2.7% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (149 CVEs).

Media Mentions

Signals from CVEs in this product scope (149 CVEs).

Top CNAs Publishing CVEs For H500e

Top CWEs

Versions

No cataloged versions.