CVEs (187)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Netapp 1Clustered Data Ontap Jun 17, 2026 Oct 12, 2021 N/A· v4 4.7 MEDIUM· v3 4.3 MEDIUM· v2 Clustered Data ONTAP versions prior to 9.5P18, 9.6P15, 9.7P14, 9.8P5 and 9.9.1 are missing an X-Frame-Options header which could allow a clickjacking attack. |
3Netapp OraclePhp3Clustered Data Ontap PhpSd Wan AwareJun 17, 2026 Oct 4, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can b...Show more |
2Netapp Php2Clustered Data Ontap PhpJun 17, 2026 Oct 4, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(...Show more |
8Apple DebianFedoraproject+5 more26Cloud Backup Clustered Data OntapCommerce Guided Search+23 moreJun 17, 2026 Sep 29, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl woul...Show more |
8Apple DebianFedoraproject+5 more29Cloud Backup Clustered Data OntapCommerce Guided Search+26 moreJun 17, 2026 Sep 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLU...Show more |
5Fedoraproject NetappOpenbsd+2 more12Active Iq Unified Manager Aff 500f FirmwareAff A250 Firmware+9 moreJul 14, 2026 Sep 26, 2021 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCom...Show more |
8Apple DebianFedoraproject+5 more17Cloud Backup Clustered Data OntapDebian Linux+14 moreJun 17, 2026 Sep 23, 2021 N/A· v4 9.1 CRITICAL· v3 5.8 MEDIUM· v2 When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also...Show more |
11Apache BroadcomDebian+8 more39Brocade Fabric Operating System Firmware Cloud BackupClustered Data Ontap+36 moreJun 17, 2026 Sep 16, 2021 N/A· v4 9.0 CRITICAL· v3 6.8 MEDIUM· v2 A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. |
6Apache DebianFedoraproject+3 more11Cloud Backup Clustered Data OntapDebian Linux+8 moreJun 17, 2026 Sep 16, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Serve...Show more |
6Apache BroadcomDebian+3 more13Brocade Fabric Operating System Firmware Cloud BackupClustered Data Ontap+10 moreJun 17, 2026 Sep 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive). |
8Apache BroadcomDebian+5 more18Brocade Fabric Operating System Firmware Cloud BackupClustered Data Ontap+15 moreJun 17, 2026 Sep 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. |
2Netapp Openbsd5Clustered Data Ontap Hci Management NodeOntap Select Deploy Administration Utility+2 moreMay 29, 2026 Sep 15, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challeng...Show more |
7Debian McafeeNetapp+4 more32Clustered Data Ontap Clustered Data Ontap Antivirus ConnectorCommunications Cloud Native Core Console+29 moreJun 17, 2026 Aug 24, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are re...Show more |
5Debian NetappOpenssl+2 more31Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+28 moreJun 17, 2026 Aug 24, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be...Show more |
5Haxx NetappOracle+2 more19Active Iq Unified Manager Clustered Data OntapCurl+16 moreJun 17, 2026 Aug 5, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is built to use the macOS n...Show more |
7Apple FedoraprojectHaxx+4 more20Cloud Backup Clustered Data OntapCurl+17 moreJun 17, 2026 Aug 5, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_EN...Show more |
7Debian FedoraprojectHaxx+4 more33Cloud Backup Clustered Data OntapDebian Linux+30 moreJun 17, 2026 Aug 5, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into ac...Show more |
6Fedoraproject HaxxNetapp+3 more16Cloud Backup Clustered Data OntapCurl+13 moreJun 17, 2026 Aug 5, 2021 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers fr...Show more |
6Fedoraproject HaxxNetapp+3 more16Cloud Backup Clustered Data OntapCurl+13 moreJun 17, 2026 Aug 5, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentf...Show more |
4Netapp OracleRedhat+1 more19Active Iq Unified Manager Cloud BackupClustered Data Ontap+16 moreJun 17, 2026 Jul 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service. |