H500e
Vendor:
First CVE: Jul 30, 2019 · Active for 6 years
149
Total CVEs
More Total CVEs than 99% of tracked products
37.3
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
2.0%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact H500e over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 30, 2019
6 years ago
Most Recent CVE
May 26, 2022
1,520 days ago
CVE Severity & Scoring
H500e149 CVEs
28%
68%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local95 (63.8%)
Network49 (32.9%)
Unknown0 (0.0%)
Physical2 (1.3%)
Adjacent Network3 (2.0%)
Attack Complexity
Low124 (83.2%)
High25 (16.8%)
Unknown0 (0.0%)
User Interaction
None138 (92.6%)
Unknown0 (0.0%)
Required11 (7.4%)
Privileges Required
Low95 (63.8%)
High7 (4.7%)
None47 (31.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (149 CVEs).
149 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0847HIGH A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux ker | Mar 10, 2022 | 7.8 | 98 | YES | YES |
CVE-2020-11023MEDIUM In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's | Apr 29, 2020 | 6.1 | 95 | YES | YES |
CVE-2020-11022MEDIUM In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append | Apr 29, 2020 | 6.1 | 83 | NO | YES |
CVE-2022-0185HIGH A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters | Feb 11, 2022 | 8.4 | 77 | YES | NO |
CVE-2021-25216CRITICAL In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9. | Apr 29, 2021 | 9.8 | 76 | NO | NO |
CVE-2022-1292HIGH The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is autom | May 3, 2022 | 7.3 | 68 | NO | NO |
CVE-2022-0435HIGH A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is | Mar 25, 2022 | 8.8 | 67 | NO | NO |
CVE-2021-43267CRITICAL An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit | Nov 2, 2021 | 9.8 | 64 | NO | NO |
CVE-2021-22901HIGH curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malic | Jun 11, 2021 | 8.1 | 60 | NO | NO |
CVE-2021-4044HIGH Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate | Dec 14, 2021 | 7.5 | 44 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (149 CVEs).
CISA KEV
3 CVEs
2.0% of CVEs· 96th percentile
Metasploit
2 CVEs
1.3% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
2.7% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (149 CVEs).
Media Mentions
Signals from CVEs in this product scope (149 CVEs).
Top CNAs Publishing CVEs For H500e
Top CWEs
Versions
No cataloged versions.