Solidfire

Vendor:

First CVE: May 21, 2007 · Active for 19 years

194
Total CVEs
More Total CVEs than 99% of tracked products
19.4
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
2.6%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Solidfire over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 21, 2007
19 years ago
Most Recent CVE
Apr 13, 2024
832 days ago

CVE Severity & Scoring

Solidfire194 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local81 (41.8%)
Network107 (55.2%)
Unknown1 (0.5%)
Physical0 (0.0%)
Adjacent Network5 (2.6%)
Attack Complexity
Low145 (74.7%)
High48 (24.7%)
Unknown1 (0.5%)
User Interaction
None161 (83.0%)
Unknown1 (0.5%)
Required32 (16.5%)
Privileges Required
Low65 (33.5%)
High6 (3.1%)
None122 (62.9%)
Unknown1 (0.5%)

Top CVEs

Signals from CVEs in this product scope (194 CVEs).

194 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg
Jan 26, 20217.899YESYES
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory
Jul 7, 20217.896YESYES
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploi
Oct 11, 20197.896YESYES
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature
Nov 10, 20167.095YESYES
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows
Jul 17, 20197.893YESYES
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or byp
Jul 15, 20215.391NOYES
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveragi
Feb 11, 20198.691NOYES
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side
Jan 4, 20185.683NOYES
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first tim
Aug 24, 20219.879NONO
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to
Jun 21, 20227.376NONO

Exploit Exposure

Signals from CVEs in this product scope (194 CVEs).

CISA KEV
5 CVEs
2.6% of CVEs· 96th percentile
Metasploit
6 CVEs
3.1% of CVEs· 96th percentile
Nuclei
2 CVEs
1.0% of CVEs· 96th percentile
ExploitDB
12 CVEs
6.2% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (194 CVEs).

Media Mentions

Signals from CVEs in this product scope (194 CVEs).

Top CNAs Publishing CVEs For Solidfire

Top CWEs

Versions

No cataloged versions.