CVEs (848)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
27 Zip Netapp37 Zip Active Iq Unified ManagerOncommand Workflow AutomationNov 21, 2024 Nov 3, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive. |
3Linux NetappRedhat5Active Iq Unified Manager Enterprise LinuxLinux Kernel+2 moreMar 24, 2026 Nov 1, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-a...Show more |
4Fedoraproject HaxxMicrosoft+1 more13Active Iq Unified Manager FedoraLibcurl+10 moreMay 12, 2026 Oct 18, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl...Show more |
2Linux Netapp3Active Iq Unified Manager H410c FirmwareLinux KernelNov 21, 2024 Oct 14, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue was discovered in drivers/usb/storage/ene_ub6250.c for the ENE UB6250 reader driver in the Linux kernel before 6.2.5. An object could potentially extend beyond the end of an allocation. |
4Fedoraproject LibtiffNetapp+1 more4Active Iq Unified Manager Enterprise LinuxFedora+1 moreNov 21, 2024 Oct 5, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based...Show more |
6Apple DebianFedoraproject+3 more14Active Iq Unified Manager Cloud Insights Acquisition UnitCloud Insights Storage Workload Security Agent+11 moreNov 5, 2025 Sep 21, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploit...Show more |
4Fedoraproject GnuNetapp+1 more16Active Iq Unified Manager Enterprise LinuxEnterprise Linux Eus+13 moreSep 26, 2025 Sep 12, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is...Show more |
9Bandisoft BentleyDebian+6 more12Active Iq Unified Manager ChromeDebian Linux+9 moreOct 24, 2025 Sep 12, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical...Show more |
2Netapp Python2Active Iq Unified Manager PythonNov 21, 2024 Aug 23, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which a...Show more |
3Debian NetappPython4Active Iq Unified Manager Converged Systems Advisor AgentDebian Linux+1 moreNov 21, 2024 Aug 22, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest. |
2Netapp Python2Active Iq Unified Manager PythonNov 21, 2024 Aug 22, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format. |
2Json C Netapp2Active Iq Unified Manager Json CJun 25, 2025 Aug 22, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit. |
2Gnu Netapp2Active Iq Unified Manager NcursesNov 21, 2024 Aug 22, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command. |
3Debian GnuNetapp3Active Iq Unified Manager Debian LinuxNcursesNov 21, 2024 Aug 22, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command. |
2Gnu Netapp2Active Iq Unified Manager NcursesNov 21, 2024 Aug 22, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command. |
2Gnu Netapp2Active Iq Unified Manager NcursesNov 21, 2024 Aug 22, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command. |
2Gnu Netapp2Active Iq Unified Manager NcursesNov 21, 2024 Aug 22, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Buffer Overflow vulnerability in _nc_find_entry function in tinfo/comp_hash.c:66 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command. |
2Gnu Netapp2Active Iq Unified Manager NcursesNov 21, 2024 Aug 22, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command. |
3Debian MitNetapp7Active Iq Unified Manager Clustered Data OntapDebian Linux+4 moreNov 21, 2024 Aug 7, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_princip...Show more |
3Certifi FedoraprojectNetapp8Active Iq Unified Manager CertifiFedora+5 moreFeb 13, 2025 Jul 25, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certifi...Show more |