CVEs (21)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Intel Netapp72Aff A200 Firmware Aff A220 FirmwareAff A250 Firmware+69 moreMay 5, 2025 Aug 18, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access. |
3Debian LinuxNetapp24A700s Firmware Active Iq Unified ManagerAff 500f Firmware+21 moreMay 5, 2025 Jul 27, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice. |
6Broadcom DebianFedoraproject+3 more28Aff 8300 Firmware Aff 8700 FirmwareAff A400 Firmware+25 moreNov 3, 2025 Jun 21, 2022 N/A· v4 7.3 HIGH· v3 10.0 HIGH· v2 In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by...Show more |
2Netapp Openssl26A250 Firmware A700s FirmwareActive Iq Unified Manager+23 moreMay 5, 2025 May 3, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long...Show more |
2Netapp Openssl26A250 Firmware A700s FirmwareActive Iq Unified Manager+23 moreNov 21, 2024 May 3, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The OpenSSL 3.0 implementation of the RC4-MD5 ciphersuite incorrectly uses the AAD data as the MAC key. This makes the MAC key trivially predictable. An attacker could exploit this issue by performing a man-in-the-middle...Show more |
2Netapp Openssl26A250 Firmware A700s FirmwareActive Iq Unified Manager+23 moreMay 5, 2025 May 3, 2022 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification)...Show more |
6Debian FedoraprojectNetapp+3 more35A250 Firmware A700s FirmwareActive Iq Unified Manager+32 moreAug 13, 2025 May 3, 2022 N/A· v4 7.3 HIGH· v3 10.0 HIGH· v2 The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating sys...Show more |
3Linux NetappOracle26Aff A400 Firmware All Flash Fabric Attached Storage 8300 FirmwareAll Flash Fabric Attached Storage 8700 Firmware+23 moreNov 21, 2024 Dec 25, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers...Show more |
3Brocade LinuxNetapp21Aff 500f Firmware Aff A250 FirmwareAff A400 Firmware+18 moreOct 27, 2025 Jul 7, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space |
2Linux Netapp22Aff 8300 Firmware Aff 8700 FirmwareAff A400 Firmware+19 moreNov 21, 2024 Jun 7, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_state_fini panic, aka CID-dbb2483b2a46. |
3Linux NetappRedhat18A700s Firmware Aff A400 FirmwareBrocade Fabric Operating System Firmware+15 moreNov 21, 2024 Mar 26, 2021 N/A· v4 4.5 MEDIUM· v3 4.4 MEDIUM· v2 A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to...Show more |
3Broadcom LinuxNetapp19A250 Firmware A700s FirmwareAff 500f Firmware+16 moreNov 21, 2024 Nov 23, 2020 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field. |
4Canonical LinuxNetapp+1 more19Active Iq Unified Manager Aff 8300 FirmwareAff 8700 Firmware+16 moreNov 21, 2024 Jun 12, 2020 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and exfiltrate private kernel data. |
2Canonical Netapp32Aff 8300 Firmware Aff 8700 FirmwareAff A220 Firmware+29 moreNov 21, 2024 Apr 10, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete,...Show more |
4Canonical DebianLinux+1 more13Active Iq Unified Manager Aff A400 FirmwareAff A700s Firmware+10 moreNov 21, 2024 Dec 17, 2019 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-of-bounds write access in __btrfs_map_block in fs/btrfs/volumes.c, because a value of 1 for the numb...Show more |
4Canonical DebianLinux+1 more13Active Iq Unified Manager Aff A400 FirmwareAff A700s Firmware+10 moreNov 21, 2024 Dec 17, 2019 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutex.c. This is rela...Show more |
4Canonical DebianLinux+1 more18A700s Firmware Active Iq Unified ManagerAff 8300 Firmware+15 moreNov 21, 2024 Dec 8, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-spa...Show more |
5Canonical DebianLinux+2 more14Active Iq Unified Manager Aff A400 FirmwareAff A700s Firmware+11 moreNov 21, 2024 Nov 28, 2019 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 In the Linux kernel 5.3.11, mounting a crafted btrfs image twice can cause an rwsem_down_write_slowpath use-after-free because (in rwsem_can_spin_on_owner in kernel/locking/rwsem.c) rwsem_owner_flags returns an already f...Show more |
4Broadcom CanonicalLinux+1 more16Active Iq Unified Manager Aff A400 FirmwareAff A700s Firmware+13 moreNov 21, 2024 Nov 18, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A memory leak in the fastrpc_dma_buf_attach() function in drivers/misc/fastrpc.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering dma_get_sgtable() failure...Show more |
5Broadcom CanonicalFedoraproject+2 more17Active Iq Unified Manager Aff A400 FirmwareAff A700s Firmware+14 moreNov 21, 2024 Nov 18, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A memory leak in the crypto_reportstat() function in crypto/crypto_user_stat.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_reportstat_alg() f...Show more |