Solidfire
Vendor:
First CVE: May 21, 2007 · Active for 19 years
194
Total CVEs
More Total CVEs than 99% of tracked products
19.4
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
2.6%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Solidfire over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 21, 2007
19 years ago
Most Recent CVE
Apr 13, 2024
832 days ago
CVE Severity & Scoring
Solidfire194 CVEs
47%
38%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local81 (41.8%)
Network107 (55.2%)
Unknown1 (0.5%)
Physical0 (0.0%)
Adjacent Network5 (2.6%)
Attack Complexity
Low145 (74.7%)
High48 (24.7%)
Unknown1 (0.5%)
User Interaction
None161 (83.0%)
Unknown1 (0.5%)
Required32 (16.5%)
Privileges Required
Low65 (33.5%)
High6 (3.1%)
None122 (62.9%)
Unknown1 (0.5%)
Top CVEs
Signals from CVEs in this product scope (194 CVEs).
194 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3156HIGH Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg | Jan 26, 2021 | 7.8 | 99 | YES | YES |
CVE-2021-22555HIGH A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory | Jul 7, 2021 | 7.8 | 96 | YES | YES |
CVE-2019-2215HIGH A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploi | Oct 11, 2019 | 7.8 | 96 | YES | YES |
CVE-2016-5195HIGH Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature | Nov 10, 2016 | 7.0 | 95 | YES | YES |
CVE-2019-13272HIGH In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows | Jul 17, 2019 | 7.8 | 93 | YES | YES |
CVE-2021-34429MEDIUM For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or byp | Jul 15, 2021 | 5.3 | 91 | NO | YES |
CVE-2019-5736HIGH runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveragi | Feb 11, 2019 | 8.6 | 91 | NO | YES |
CVE-2017-5753MEDIUM Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side | Jan 4, 2018 | 5.6 | 83 | NO | YES |
CVE-2021-3711CRITICAL In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first tim | Aug 24, 2021 | 9.8 | 79 | NO | NO |
CVE-2022-2068HIGH In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to | Jun 21, 2022 | 7.3 | 76 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (194 CVEs).
CISA KEV
5 CVEs
2.6% of CVEs· 96th percentile
Metasploit
6 CVEs
3.1% of CVEs· 96th percentile
Nuclei
2 CVEs
1.0% of CVEs· 96th percentile
ExploitDB
12 CVEs
6.2% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (194 CVEs).
Media Mentions
Signals from CVEs in this product scope (194 CVEs).
Top CNAs Publishing CVEs For Solidfire
Top CWEs
Versions
No cataloged versions.