CVEs (187)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Apache Netapp2Clustered Data Ontap Http ServerNov 3, 2025 Jul 1, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request.
Users are recommended to upgrade to version 2.4.60, which fixes this issue. |
2Apache Netapp2Clustered Data Ontap Http ServerNov 3, 2025 Jul 1, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users...Show more |
2Apache Netapp2Clustered Data Ontap Http ServerMar 25, 2025 Jul 1, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclos...Show more |
ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 and 9.13.1P4 are susceptible to a vulnerability which could allow an authenticated user with multiple remote accounts with differing roles to perform...Show more |
ONTAP versions 9.4 and higher are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information to unprivileged attackers when the object-store profiler command is...Show more |
ONTAP 9 versions prior to 9.8P19, 9.9.1P16, 9.10.1P12, 9.11.1P8,
9.12.1P2 and 9.13.1 are susceptible to a vulnerability which could allow
a remote unauthenticated attacker to cause a crash of the HTTP service. |
3Debian MitNetapp7Active Iq Unified Manager Clustered Data OntapDebian Linux+4 moreNov 21, 2024 Aug 7, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_princip...Show more |
2Freebsd Netapp2Clustered Data Ontap FreebsdJul 9, 2025 Aug 1, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a fragment reassembled packet's payload length field. This allows an attacker to trigger a kernel panic, resulting in a denial...Show more |
5Apple DebianEs+2 more6Clustered Data Ontap Debian LinuxFedora+3 moreNov 21, 2024 Jul 17, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field. |
4Apple NetappOpenldap+1 more11Active Iq Unified Manager Clustered Data OntapEnterprise Linux+8 moreJan 10, 2025 May 30, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function. |
4Apple FedoraprojectHaxx+1 more9Clustered Data Ontap CurlFedora+6 moreFeb 13, 2026 May 26, 2023 N/A· v4 3.7 LOW· v3 N/A· v2 An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFI...Show more |
5Apple DebianFedoraproject+2 more10Clustered Data Ontap CurlDebian Linux+7 moreJan 15, 2025 May 26, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use...Show more |
3Apple HaxxNetapp8Clustered Data Ontap CurlH300s Firmware+5 moreJan 15, 2025 May 26, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows...Show more |
3Apple HaxxNetapp8Clustered Data Ontap CurlH300s Firmware+5 moreJan 15, 2025 May 26, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprin...Show more |
6Broadcom DebianFedoraproject+3 more11Active Iq Unified Manager Brocade Fabric Operating System FirmwareClustered Data Ontap+8 moreJun 9, 2025 Mar 30, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcur...Show more |
4Broadcom HaxxNetapp+1 more9Active Iq Unified Manager Brocade Fabric Operating System FirmwareClustered Data Ontap+6 moreNov 21, 2024 Mar 30, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indi...Show more |
4Fedoraproject HaxxNetapp+1 more9Active Iq Unified Manager Clustered Data OntapCurl+6 moreFeb 13, 2026 Mar 30, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The la...Show more |
5Debian FedoraprojectHaxx+2 more9Clustered Data Ontap CurlDebian Linux+6 moreMar 12, 2025 Feb 23, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potent...Show more |
3Haxx NetappSplunk8Active Iq Unified Manager Clustered Data OntapCurl+5 moreFeb 13, 2026 Feb 23, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl...Show more |
3Haxx NetappSplunk8Active Iq Unified Manager Clustered Data OntapCurl+5 moreMar 12, 2025 Feb 23, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed t...Show more |