CVEs (848)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Netapp Oracle4Active Iq Unified Manager Mysql ClientMysql Cluster+1 moreNov 3, 2025 Apr 15, 2025 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Difficult to exploit vulnerability allows lo...Show more |
2Apache Netapp2Active Iq Unified Manager PoiJul 15, 2025 Apr 9, 2025 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to ad...Show more |
2Netapp Xmlsoft11Active Iq Unified Manager H300s FirmwareH410c Firmware+8 moreNov 3, 2025 Feb 18, 2025 N/A· v4 7.7 HIGH· v3 N/A· v2 libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is si...Show more |
2Netapp Xmlsoft11Active Iq Unified Manager H300s FirmwareH410c Firmware+8 moreNov 3, 2025 Feb 18, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XM...Show more |
4Debian NetappOpenbsd+1 more6Active Iq Unified Manager Debian LinuxEnterprise Linux+3 moreMay 12, 2026 Feb 18, 2025 N/A· v4 6.8 MEDIUM· v3 N/A· v2 A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH...Show more |
2Gnu Netapp3Active Iq Unified Manager BinutilsOntap Select Deploy Administration UtilityMay 21, 2025 Feb 11, 2025 2.3 LOW· v4 5.0 MEDIUM· v3 5.1 MEDIUM· v2 A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corrupt...Show more |
2Gnu Netapp3Active Iq Unified Manager BinutilsOntap Select Deploy Administration UtilityMay 21, 2025 Feb 11, 2025 6.3 MEDIUM· v4 5.6 MEDIUM· v3 5.1 MEDIUM· v2 A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory co...Show more |
2Netapp Netty3Active Iq Unified Manager NettyOncommand InsightSep 5, 2025 Feb 10, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doe...Show more |
27 Zip Netapp27 Zip Active Iq Unified ManagerOct 27, 2025 Jan 25, 2025 N/A· v4 7.0 HIGH· v3 N/A· v2 7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this v...Show more |
3Debian NetappOracle11Active Iq Unified Manager Bootstrap OsBrocade San Navigator+8 moreJun 18, 2025 Jan 21, 2025 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.25...Show more |
2Netapp Oracle4Active Iq Unified Manager Mysql ServerOncommand Insight+1 moreApr 9, 2025 Jan 21, 2025 N/A· v4 4.9 MEDIUM· v3 N/A· v2 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 and prior and 8.4.0. Easily exploitable vulnerability allows high privileged att...Show more |
3Debian GnomeNetapp4Active Iq Unified Manager Debian LinuxGlib+1 moreJun 17, 2025 Nov 11, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character. |
3Debian Libexpat ProjectNetapp12Active Iq Unified Manager Debian LinuxH300s Firmware+9 moreOct 15, 2025 Oct 27, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser. |
2Eclipse Netapp3Active Iq Unified Manager Bootstrap OsJettyNov 3, 2025 Oct 14, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted requests...Show more |
2Apache Netapp8Active Iq Unified Manager BluexpCommons Io+5 moreJul 10, 2025 Oct 3, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue a...Show more |
2Apache Netapp3Active Iq Unified Manager AvroBrocade San NavigatorJul 10, 2025 Oct 3, 2024 9.2 CRITICAL· v4 7.3 HIGH· v3 N/A· v2 Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code.
Users are recommended to upgrade to version 1.11.4 or 1.12.0, which fix this issue. |
2Google Netapp8Active Iq Unified Manager BluexpOntap Tools+5 moreSep 26, 2025 Sep 19, 2024 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unkn...Show more |
3Debian HaxxNetapp10Active Iq Unified Manager Bootstrap OsCurl+7 moreJul 30, 2025 Sep 11, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly co...Show more |
2Angularjs Netapp2Active Iq Unified Manager AngularjsNov 20, 2025 Sep 9, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://...Show more |
2Angularjs Netapp2Active Iq Unified Manager AngularjsNov 20, 2025 Sep 9, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/at...Show more |