CVEs (187)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Clustered Data ONTAP versions 8.0, 8.3.1, and 8.3.2 contain a default privileged account which under certain conditions can be used for unauthorized information disclosure. |
2Netapp Php2Clustered Data Ontap PhpMay 6, 2026 Jan 11, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service...Show more |
2Netapp Php2Clustered Data Ontap PhpMay 6, 2026 Jan 11, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attackers to execute arbitrary code or cause a denial of service (integer ov...Show more |
2Netapp Ntp6Clustered Data Ontap Data Ontap Operating In 7 ModeNtp+3 moreMay 23, 2025 Jan 6, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a specially crafted private mode packet. The crafted packet needs to have the correct message authenticati...Show more |
NetApp Clustered Data ONTAP before 8.2.4P4 and 8.3.x before 8.3.2P2 allows remote authenticated users to obtain sensitive cluster and tenant information via unspecified vectors. |
NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |
4Debian NetappNtp+1 more6Clustered Data Ontap Debian LinuxNtp+3 moreMay 6, 2026 Jan 26, 2016 N/A· v4 7.7 HIGH· v3 4.0 MEDIUM· v2 NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted k...Show more |