CVEs (848)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Fedoraproject NetappNodejs+2 more13Active Iq Unified Manager E Series Performance AnalyzerFedora+10 moreNov 21, 2024 Mar 3, 2021 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is r...Show more |
2Netapp Redhat3Active Iq Unified Manager Oncommand Workflow AutomationUndertowNov 21, 2024 Feb 23, 2021 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP...Show more |
5Broadcom DebianFedoraproject+2 more7Active Iq Unified Manager Brocade Fabric Operating System FirmwareCloud Backup+4 moreNov 21, 2024 Feb 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could poten...Show more |
5Broadcom DebianFedoraproject+2 more7Active Iq Unified Manager Brocade Fabric Operating System FirmwareCloud Backup+4 moreNov 21, 2024 Feb 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with a buffer of 4GB or more on a 64-bit platform, the length would be truncated modulo 2**32, causing u...Show more |
4Lodash NetappOracle+1 more23Active Iq Unified Manager Banking Corporate Lending Process ManagementBanking Credit Facilities Process Management+20 moreNov 21, 2024 Feb 15, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. |
5Debian NetappNetty+2 more13Active Iq Unified Manager Banking Corporate Lending Process ManagementBanking Credit Facilities Process Management+10 moreNov 21, 2024 Feb 8, 2021 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerab...Show more |
8Beyondtrust DebianFedoraproject+5 more24Active Iq Unified Manager Cloud BackupCommunications Performance Intelligence Center+21 moreNov 10, 2025 Jan 26, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash...Show more |
4Fedoraproject MariadbNetapp+1 more6Active Iq Unified Manager FedoraMariadb+3 moreNov 21, 2024 Jan 20, 2021 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.7.32 and prior and 8.0.22 and prior. Difficult to exploit vulnerability allows unauthenticated atta...Show more |
3Fedoraproject NetappOracle5Active Iq Unified Manager FedoraMysql+2 moreNov 21, 2024 Jan 20, 2021 N/A· v4 4.2 MEDIUM· v3 4.9 MEDIUM· v2 Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.50 and prior, 5.7.32 and prior and 8.0.22 and prior. Difficult to exploit vulnerability allows lo...Show more |
4Fedoraproject MariadbNetapp+1 more6Active Iq Unified Manager FedoraMariadb+3 moreNov 21, 2024 Jan 20, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.19 and prior. Difficult to exploit vulnerability allows un...Show more |
3Fedoraproject NetappOracle5Active Iq Unified Manager FedoraMysql+2 moreNov 21, 2024 Jan 20, 2021 N/A· v4 5.3 MEDIUM· v3 6.3 MEDIUM· v2 Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 8.0.19 and prior. Difficult to exploit vulnerability allows low privileged attacker with network acce...Show more |
3Fedoraproject NetappOracle6Active Iq Unified Manager FedoraMysql+3 moreNov 21, 2024 Jan 20, 2021 N/A· v4 3.8 LOW· v3 5.5 MEDIUM· v2 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with n...Show more |
5Apache DebianFasterxml+2 more8Active Iq Unified Manager Commerce Guided Search And Experience ManagerDebian Linux+5 moreAug 27, 2025 Jan 19, 2021 N/A· v4 8.1 HIGH· v3 8.3 HIGH· v2 A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as...Show more |
5Debian FedoraprojectNetapp+2 more10Active Iq Unified Manager Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Offline Mediation Controller+7 moreDec 18, 2025 Jan 19, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demons...Show more |
4Google NetappOracle+1 more13Active Iq Unified Manager Commerce Guided SearchCommunications Cloud Native Core Network Repository Function+10 moreFeb 23, 2026 Dec 10, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.F...Show more |
6Broadcom DebianFedoraproject+3 more128300 Firmware 8700 FirmwareA400 Firmware+9 moreNov 21, 2024 Dec 9, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b. |
5Broadcom DebianFedoraproject+2 more118300 Firmware 8700 FirmwareA400 Firmware+8 moreNov 21, 2024 Dec 9, 2020 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9...Show more |
8Debian FedoraprojectNetapp+5 more44Active Iq Unified Manager Aff A250 FirmwareApi Gateway+41 moreMay 29, 2026 Dec 8, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of...Show more |
3Infinispan NetappRedhat3Active Iq Unified Manager Data GridInfinispanNov 21, 2024 Dec 3, 2020 N/A· v4 6.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations l...Show more |
4Apache NetappOracle+1 more17Active Iq Unified Manager Commerce Guided SearchCommunications Cloud Native Core Service Communication Proxy+14 moreDec 1, 2025 Dec 2, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request executio...Show more |