H500s

Vendor:

First CVE: Jul 30, 2019 · Active for 6 years

315
Total CVEs
More Total CVEs than 100% of tracked products
45.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 43% of tracked products
3.2%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact H500s over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 30, 2019
6 years ago
Most Recent CVE
Mar 11, 2025
503 days ago

CVE Severity & Scoring

H500s315 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local166 (52.7%)
Network141 (44.8%)
Unknown0 (0.0%)
Physical4 (1.3%)
Adjacent Network4 (1.3%)
Attack Complexity
Low246 (78.1%)
High69 (21.9%)
Unknown0 (0.0%)
User Interaction
None286 (90.8%)
Unknown0 (0.0%)
Required29 (9.2%)
Privileges Required
Low165 (52.4%)
High12 (3.8%)
None138 (43.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (315 CVEs).

315 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to us
Oct 3, 20237.898YESYES
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux ker
Mar 10, 20227.898YESYES
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory
Jul 7, 20217.896YESYES
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's
Apr 29, 20206.195YESYES
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploi
Oct 11, 20197.892YESYES
AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerabili
Mar 11, 20259.891YESNO
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append
Apr 29, 20206.183NOYES
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the
Mar 3, 20227.879YESYES
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a u
Mar 22, 20237.878YESYES
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters
Feb 11, 20228.477YESNO

Exploit Exposure

Signals from CVEs in this product scope (315 CVEs).

CISA KEV
10 CVEs
3.2% of CVEs· 97th percentile
Metasploit
8 CVEs
2.5% of CVEs· 96th percentile
Nuclei
1 CVE
0.3% of CVEs· 96th percentile
ExploitDB
7 CVEs
2.2% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (315 CVEs).

Media Mentions

Signals from CVEs in this product scope (315 CVEs).

Top CNAs Publishing CVEs For H500s

Top CWEs

Versions

No cataloged versions.