← Back

Clustered Data Ontap

clustered_data_ontap

Vendor: Netapp • 187 CVEs

CVEs (187)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netapp
1Clustered Data Ontap
May 6, 2026
Jan 11, 2017
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Clustered Data ONTAP versions 8.0, 8.3.1, and 8.3.2 contain a default privileged account which under certain conditions can be used for unauthorized information disclosure.
2Netapp
Php
2Clustered Data Ontap
Php
May 6, 2026
Jan 11, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service...Show more
The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access) via crafted serialized data.Show less
2Netapp
Php
2Clustered Data Ontap
Php
May 6, 2026
Jan 11, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attackers to execute arbitrary code or cause a denial of service (integer ov...Show more
Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow, uninitialized memory access, and use of arbitrary destructor function pointers) via crafted serialized data.Show less
2Netapp
Ntp
6Clustered Data Ontap
Data Ontap Operating In 7 ModeNtp+3 more
May 23, 2025
Jan 6, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a specially crafted private mode packet. The crafted packet needs to have the correct message authenticati...Show more
An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a specially crafted private mode packet. The crafted packet needs to have the correct message authentication code and a valid timestamp. When processed by the NTP daemon, it leads to an immediate crash.Show less
1Netapp
1Clustered Data Ontap
May 6, 2026
Sep 1, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
NetApp Clustered Data ONTAP before 8.2.4P4 and 8.3.x before 8.3.2P2 allows remote authenticated users to obtain sensitive cluster and tenant information via unspecified vectors.
1Netapp
1Clustered Data Ontap
May 6, 2026
Apr 7, 2016
N/A· v4
6.8 MEDIUM· v3
5.8 MEDIUM· v2
NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
4Debian
NetappNtp+1 more
6Clustered Data Ontap
Debian LinuxNtp+3 more
May 6, 2026
Jan 26, 2016
N/A· v4
7.7 HIGH· v3
4.0 MEDIUM· v2
NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted k...Show more
NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."Show less