Manageability Software Development Kit

Vendor:

First CVE: Dec 24, 2019 · Active for 6 years

15
Total CVEs
More Total CVEs than 92% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Manageability Software Development Kit over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 24, 2019
6 years ago
Most Recent CVE
Feb 18, 2025
521 days ago

CVE Severity & Scoring

Manageability Software Development Kit15 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local2 (13.3%)
Network13 (86.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (80.0%)
High3 (20.0%)
Unknown0 (0.0%)
User Interaction
None12 (80.0%)
Unknown0 (0.0%)
Required3 (20.0%)
Privileges Required
Low1 (6.7%)
High0 (0.0%)
None14 (93.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first tim
Aug 24, 20219.879NONO
ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This cont
Aug 24, 20217.453NONO
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept a
May 11, 20209.844NONO
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application li
May 19, 20218.631NONO
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML
Feb 18, 20259.830NONO
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
Feb 26, 20227.528NONO
There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-afte
May 18, 20218.828NONO
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case,
Nov 23, 20227.827NONO
xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.
Dec 24, 20197.527NONO
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted doc
Feb 18, 20257.725NONO

Exploit Exposure

Signals from CVEs in this product scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (15 CVEs).

Media Mentions

Signals from CVEs in this product scope (15 CVEs).

Top CNAs Publishing CVEs For Manageability Software Development Kit

Top CWEs

Versions

No cataloged versions.