Oracle Zfs Storage Appliance Kit vulnerabilities
117 known vulnerabilities affecting oracle/zfs_storage_appliance_kit.
Total CVEs
117
CISA KEV
3
actively exploited
Public exploits
6
Exploited in wild
4
Severity breakdown
CRITICAL18HIGH47MEDIUM47LOW5
Vulnerabilities
Page 5 of 6
CVE-2019-14822P4HIGHCVSS 7.1v8.82019-11-25
CVE-2019-14822 [HIGH] CWE-862 CVE-2019-14822: A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor
A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engi
nvd
CVE-2021-3426P4MEDIUMCVSS 5.7v8.82021-05-20
CVE-2021-3426 [MEDIUM] CWE-200 CVE-2021-3426: There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convinc
There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidenti
nvd
CVE-2020-27783P4MEDIUMCVSS 6.1v8.82020-12-03
CVE-2020-27783 [MEDIUM] CWE-79 CVE-2020-27783: A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properl
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
nvd
CVE-2020-13630P4HIGHCVSS 7.0v8.82020-05-27
CVE-2020-13630 [HIGH] CWE-416 CVE-2020-13630: ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snip
ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
nvd
CVE-2020-13596P4MEDIUMCVSS 6.1v8.82020-06-03
CVE-2020-13596 [MEDIUM] CWE-79 CVE-2020-13596: An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.
nvd
CVE-2019-11135P4MEDIUMCVSS 6.5v8.82019-11-14
CVE-2019-11135 [MEDIUM] CWE-385 CVE-2019-11135: TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authentic
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
nvd
CVE-2019-12387P4MEDIUMCVSS 6.1v8.82019-06-10
CVE-2019-12387 [MEDIUM] CWE-74 CVE-2019-12387: In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1v8.82019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2022-21271P4MEDIUMCVSS 5.3v8.82022-01-19
CVE-2022-21271 [MEDIUM] CVE-2022-21271: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protoc
nvd
CVE-2020-17498P4MEDIUMCVSS 6.5v8.82020-08-13
CVE-2020-17498 [MEDIUM] CWE-415 CVE-2020-17498: In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/di
In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression.
nvd
CVE-2024-21104P4MEDIUMCVSS 6.5v8.82024-04-16
CVE-2024-21104 [MEDIUM] CVE-2024-21104: Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core).
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS Storage Appliance Kit. Successful attacks re
nvd
CVE-2020-26421P4MEDIUMCVSS 5.3v8.82020-12-11
CVE-2020-26421 [MEDIUM] CWE-125 CVE-2020-26421: Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.
Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
nvd
CVE-2020-26418P4MEDIUMCVSS 5.3v8.82020-12-11
CVE-2020-26418 [MEDIUM] CWE-401 CVE-2020-26418: Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of servi
Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
nvd
CVE-2020-15025P4MEDIUMCVSS 4.9v8.82020-06-24
CVE-2020-15025 [MEDIUM] CWE-401 CVE-2020-15025: ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial
ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.
nvd
CVE-2020-26419P4MEDIUMCVSS 5.3v8.82020-12-11
CVE-2020-26419 [MEDIUM] CWE-401 CVE-2020-26419: Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injectio
Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file.
nvd
CVE-2020-26420P4MEDIUMCVSS 5.3v8.82020-12-11
CVE-2020-26420 [MEDIUM] CWE-401 CVE-2020-26420: Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of servic
Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
nvd
CVE-2021-20227P4MEDIUMCVSS 5.5v8.82021-03-23
CVE-2021-20227 [MEDIUM] CWE-416 CVE-2021-20227: A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker
A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.
nvd
CVE-2020-13631P4MEDIUMCVSS 5.5v8.82020-05-27
CVE-2020-13631 [MEDIUM] CVE-2020-13631: SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, r
SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.
nvd
CVE-2025-62476P4MEDIUMCVSS 4.9v8.82025-10-21
CVE-2025-62476 [MEDIUM] CWE-400 CVE-2025-62476: Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Remote R
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Remote Replication). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can resu
nvd
CVE-2025-62475P4MEDIUMCVSS 4.9v8.82025-10-21
CVE-2025-62475 [MEDIUM] CWE-400 CVE-2025-62475: Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core).
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in unauthoriz
nvd