Hci Compute Node Firmware

Vendor:

First CVE: Nov 18, 2019 · Active for 6 years

34
Total CVEs
More Total CVEs than 96% of tracked products
6.8
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Hci Compute Node Firmware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 18, 2019
6 years ago
Most Recent CVE
Jan 20, 2025
550 days ago

CVE Severity & Scoring

Hci Compute Node Firmware34 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local17 (50.0%)
Network16 (47.1%)
Unknown0 (0.0%)
Physical1 (2.9%)
Adjacent Network0 (0.0%)
Attack Complexity
Low25 (73.5%)
High9 (26.5%)
Unknown0 (0.0%)
User Interaction
None26 (76.5%)
Unknown0 (0.0%)
Required8 (23.5%)
Privileges Required
Low13 (38.2%)
High1 (2.9%)
None20 (58.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (34 CVEs).

34 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malic
Jun 11, 20218.160NONO
A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.
Jun 2, 20228.128NONO
A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP
Feb 18, 20227.428NONO
The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state.
Apr 11, 20227.826NONO
In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't pro
Dec 25, 20217.526NONO
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for
Jun 4, 20207.426NONO
A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by
Nov 18, 20197.526NONO
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
Oct 24, 20227.525NONO
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
Apr 8, 20227.025NONO
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a R
Mar 10, 20226.525NONO

Exploit Exposure

Signals from CVEs in this product scope (34 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (34 CVEs).

Media Mentions

Signals from CVEs in this product scope (34 CVEs).

Top CNAs Publishing CVEs For Hci Compute Node Firmware

Top CWEs

Versions

No cataloged versions.