CVEs (848)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject NetappPython9Active Iq Unified Manager Bootstrap OsE Series Performance Analyzer+6 moreNov 3, 2025 Nov 9, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being present...Show more |
2Linux Netapp7Active Iq Unified Manager H300s FirmwareH410c Firmware+4 moreMay 12, 2026 Nov 4, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow. NFSD tracks the number of pages held by each NFSD thread by combining the receive and send buffers of a remote p...Show more |
2Netapp Vmware2Active Iq Unified Manager Spring SecurityMay 6, 2025 Oct 31, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an application is vulnerable when all of the f...Show more |
2Netapp Vmware2Active Iq Unified Manager Spring SecurityMay 8, 2025 Oct 31, 2022 N/A· v4 8.1 HIGH· v3 N/A· v2 Spring Security, versions 5.7 prior to 5.7.5, and 5.6 prior to 5.6.9, and older unsupported versions could be susceptible to a privilege escalation under certain conditions. A malicious user or attacker can modify a requ...Show more |
4Debian FedoraprojectNetapp+1 more4Active Iq Unified Manager Debian LinuxFedora+1 moreNov 21, 2024 Oct 26, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in vim and classified as problematic. Affected by this issue is the function qf_update_buffer of the file quickfix.c of the component autocmd Handler. The manipulation leads to use after free. T...Show more |
4Debian FedoraprojectLibexpat Project+1 more12Active Iq Unified Manager Debian LinuxFedora+9 moreMay 30, 2025 Oct 24, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations. |
3Debian LinuxNetapp7Active Iq Unified Manager Debian LinuxH300s Firmware+4 moreNov 21, 2024 Oct 21, 2022 N/A· v4 7.0 HIGH· v3 N/A· v2 A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_new_inode of the file fs/nilfs2/inode.c of the component BPF. The manipulation leads to use after free. It...Show more |
3Debian LibtiffNetapp3Active Iq Unified Manager Debian LinuxLibtiffMay 7, 2025 Oct 21, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, tools/tiffcrop.c:6860, allowing attackers to cause a denial-of-service via a crafted tiff file. For...Show more |
3Debian LibtiffNetapp3Active Iq Unified Manager Debian LinuxLibtiffMay 7, 2025 Oct 21, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemset in libtiff/tif_unix.c:340 when called from processCropSelections, tools/tiffcrop.c:7619, allowing attackers to cause a denial-of-service via a crafted tiff file. Fo...Show more |
3Debian LibtiffNetapp3Active Iq Unified Manager Debian LinuxLibtiffMay 7, 2025 Oct 21, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 LibTIFF 4.4.0 has an out-of-bounds read in writeSingleSection in tools/tiffcrop.c:7345, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is ava...Show more |
3Debian LibtiffNetapp3Active Iq Unified Manager Debian LinuxLibtiffMay 7, 2025 Oct 21, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 LibTIFF 4.4.0 has an out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c:3604, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources...Show more |
3Debian LibtiffNetapp3Active Iq Unified Manager Debian LinuxLibtiffMay 7, 2025 Oct 21, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, tools/tiffcrop.c:6826, allowing attackers to cause a denial-of-service via a crafted tiff file. For...Show more |
4Debian FedoraprojectIsc+1 more4Active Iq Unified Manager BindDebian Linux+1 moreMay 28, 2025 Sep 21, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for l...Show more |
4Debian FedoraprojectIsc+1 more4Active Iq Unified Manager BindDebian Linux+1 moreMay 28, 2025 Sep 21, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for l...Show more |
2Netapp Systemd Project6Active Iq Unified Manager H300s FirmwareH410s Firmware+3 moreNov 21, 2024 Sep 9, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsS...Show more |
2Netapp Redhat9Active Iq Unified Manager Cloud Secure AgentIntegration Camel K+6 moreNov 21, 2024 Sep 1, 2022 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations. |
2Netapp Redhat7Active Iq Unified Manager Cloud Secure AgentOncommand Insight+4 moreNov 21, 2024 Aug 31, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the co...Show more |
2Netapp Redhat10Active Iq Unified Manager Build Of QuarkusCloud Secure Agent+7 moreNov 21, 2024 Aug 31, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-...Show more |
3Linux NetappRedhat8Active Iq Unified Manager Enterprise LinuxH300s Firmware+5 moreApr 23, 2025 Aug 29, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio from the user space, resulting in a null-ptr-deref vulnerability and a use-after-free vulnerability...Show more |
Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.10P1 are susceptible to a vulnerability which could allow an attacker to discover cluster, node and Active IQ Unified Manager...Show more |