Hci Management Node

Vendor:

First CVE: May 21, 2007 · Active for 19 years

182
Total CVEs
More Total CVEs than 99% of tracked products
22.8
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
2.2%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Hci Management Node over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 21, 2007
19 years ago
Most Recent CVE
Jul 18, 2023
1,102 days ago

CVE Severity & Scoring

Hci Management Node182 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local74 (40.7%)
Network102 (56.0%)
Unknown1 (0.5%)
Physical0 (0.0%)
Adjacent Network5 (2.7%)
Attack Complexity
Low135 (74.2%)
High46 (25.3%)
Unknown1 (0.5%)
User Interaction
None151 (83.0%)
Unknown1 (0.5%)
Required30 (16.5%)
Privileges Required
Low59 (32.4%)
High5 (2.7%)
None117 (64.3%)
Unknown1 (0.5%)

Top CVEs

Signals from CVEs in this product scope (182 CVEs).

182 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg
Jan 26, 20217.899YESYES
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory
Jul 7, 20217.896YESYES
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploi
Oct 11, 20197.896YESYES
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows
Jul 17, 20197.893YESYES
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or byp
Jul 15, 20215.391NOYES
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveragi
Feb 11, 20198.691NOYES
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first tim
Aug 24, 20219.879NONO
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to
Jun 21, 20227.376NONO
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access v
Jan 4, 20185.674NOYES
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality
Feb 26, 20215.361NONO

Exploit Exposure

Signals from CVEs in this product scope (182 CVEs).

CISA KEV
4 CVEs
2.2% of CVEs· 96th percentile
Metasploit
6 CVEs
3.3% of CVEs· 96th percentile
Nuclei
2 CVEs
1.1% of CVEs· 96th percentile
ExploitDB
10 CVEs
5.5% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (182 CVEs).

Media Mentions

Signals from CVEs in this product scope (182 CVEs).

Top CNAs Publishing CVEs For Hci Management Node

Top CWEs

Versions

No cataloged versions.