CVEs (848)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Broadcom DebianFedoraproject+3 more11Active Iq Unified Manager Brocade Fabric Operating System FirmwareClustered Data Ontap+8 moreJun 9, 2025 Mar 30, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcur...Show more |
4Broadcom HaxxNetapp+1 more9Active Iq Unified Manager Brocade Fabric Operating System FirmwareClustered Data Ontap+6 moreNov 21, 2024 Mar 30, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indi...Show more |
5Debian FedoraprojectHaxx+2 more10Active Iq Unified Manager Debian LinuxFedora+7 moreFeb 14, 2025 Mar 30, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the...Show more |
5Debian FedoraprojectHaxx+2 more10Active Iq Unified Manager Debian LinuxFedora+7 moreJun 9, 2025 Mar 30, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in...Show more |
5Broadcom FedoraprojectHaxx+2 more9Active Iq Unified Manager Brocade Fabric Operating System FirmwareCurl+6 moreApr 23, 2025 Mar 30, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first...Show more |
4Fedoraproject HaxxNetapp+1 more9Active Iq Unified Manager Clustered Data OntapCurl+6 moreFeb 13, 2026 Mar 30, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The la...Show more |
2Netapp Sudo Project2Active Iq Unified Manager SudoNov 21, 2024 Mar 16, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Sudo before 1.9.13 does not escape control characters in sudoreplay output. |
2Netapp Sudo Project2Active Iq Unified Manager SudoNov 21, 2024 Mar 16, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Sudo before 1.9.13 does not escape control characters in log messages. |
Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors. |
Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows administrative users to perform a Stored Cross-Site Scripting (XSS) atta...Show more |
3Haxx NetappSplunk8Active Iq Unified Manager Clustered Data OntapCurl+5 moreFeb 13, 2026 Feb 23, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl...Show more |
3Haxx NetappSplunk8Active Iq Unified Manager Clustered Data OntapCurl+5 moreMar 12, 2025 Feb 23, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed t...Show more |
2Netapp Redhat3Active Iq Unified Manager Oncommand Workflow AutomationResteasyMar 18, 2025 Feb 17, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user. |
3Fedoraproject NetappPython6Active Iq Unified Manager FedoraManagement Services For Element Software+3 moreNov 3, 2025 Feb 17, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters. |
5Debian FedoraprojectGnu+2 more7Active Iq Unified Manager Converged Systems Advisor AgentDebian Linux+4 moreMar 19, 2025 Feb 15, 2023 N/A· v4 7.4 HIGH· v3 N/A· v2 A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbache...Show more |
4Debian FasterxmlNetapp+1 more5Active Iq Unified Manager Debian LinuxJackson Databind+2 moreAug 19, 2025 Dec 26, 2022 N/A· v4 8.1 HIGH· v3 N/A· v2 A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLook...Show more |
4Fedoraproject HaxxNetapp+1 more7Active Iq Unified Manager CurlFedora+4 moreFeb 13, 2026 Dec 23, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even...Show more |
3Apple NetappXmlsoft17Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+14 moreApr 28, 2025 Nov 23, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked. |
3Apple NetappXmlsoft17Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+14 moreApr 29, 2025 Nov 23, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an a...Show more |
4Apple DebianLibtiff+1 more7Active Iq Unified Manager Debian LinuxIpados+4 moreNov 21, 2024 Nov 13, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to in...Show more |