CVEs (100)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Haxx Netapp16Bootstrap Os CurlElement Software+13 moreJun 17, 2026 Feb 5, 2025 N/A· v4 3.4 LOW· v3 N/A· v2 When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itse...Show more |
3Debian GnuNetapp11Debian Linux Element SoftwareGlibc+8 moreJun 17, 2026 May 6, 2024 N/A· v4 7.4 HIGH· v3 N/A· v2 nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw...Show more |
3Fedoraproject NetappPython9Active Iq Unified Manager Bootstrap OsE Series Performance Analyzer+6 moreJun 17, 2026 Nov 9, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being present...Show more |
5Apple DebianHaxx+2 more13Bootstrap Os Clustered Data OntapCurl+10 moreJun 17, 2026 Sep 23, 2022 N/A· v4 3.7 LOW· v3 N/A· v2 When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing...Show more |
6Apple DebianFedoraproject+3 more14Bootstrap Os Clustered Data OntapCurl+11 moreJun 17, 2026 Jul 7, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the...Show more |
6Apple DebianFedoraproject+3 more14Bootstrap Os Clustered Data OntapCurl+11 moreJun 17, 2026 Jul 7, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation...Show more |
6Debian FedoraprojectHaxx+3 more19Bootstrap Os Clustered Data OntapCurl+16 moreJun 17, 2026 Jul 7, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompress...Show more |
7Apple DebianFedoraproject+4 more19Clustered Data Ontap CurlDebian Linux+16 moreJun 17, 2026 Jul 7, 2022 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this,...Show more |
6Broadcom DebianFedoraproject+3 more28Aff 8300 Firmware Aff 8700 FirmwareAff A400 Firmware+25 moreJun 17, 2026 Jun 21, 2022 N/A· v4 7.3 HIGH· v3 10.0 HIGH· v2 In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by...Show more |
2Linux Netapp17Active Iq Unified Manager Bootstrap OsCloud Volumes Ontap Mediator+14 moreJun 17, 2026 May 25, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients. |
4Azul DebianNetapp+1 more16Active Iq Unified Manager Bootstrap OsCloud Insights Acquisition Unit+13 moreJun 17, 2026 Apr 19, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle Graal...Show more |
4Azul DebianNetapp+1 more17Active Iq Unified Manager Bootstrap OsCloud Insights Acquisition Unit+14 moreJun 17, 2026 Apr 19, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle...Show more |
4Azul DebianNetapp+1 more16Active Iq Unified Manager Bootstrap OsCloud Insights Acquisition Unit+13 moreJun 17, 2026 Apr 19, 2022 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle...Show more |
3Linux NetappOracle16A700s Firmware Active Iq Unified ManagerBootstrap Os+13 moreJun 17, 2026 Mar 25, 2022 N/A· v4 6.8 MEDIUM· v3 4.9 MEDIUM· v2 A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw, an attacker with a user privileges m...Show more |
3Linux NetappRedhat12Active Iq Unified Manager Bootstrap OsElement Software+9 moreJun 17, 2026 Feb 16, 2022 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bounds read in vt as the write access to vc_mode is not protected by lock-in vt_ioctl (KDSETMDE). The...Show more |
2Linux Netapp5Element Software Hci Bootstrap OsHci Management Node+2 moreJun 17, 2026 Aug 8, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the syste...Show more |
2Linux Netapp5Element Software Hci Bootstrap OsHci Management Node+2 moreJun 17, 2026 Aug 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is being used for nfsd. |
2Linux Netapp5Element Software Hci Bootstrap OsHci Management Node+2 moreJun 17, 2026 Aug 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdr_set_page_base slab-out-of-bounds access) by performing many NFS 4.2 READ_PLUS operations. |
3Debian LinuxNetapp6Debian Linux Element SoftwareHci Bootstrap Os+3 moreJun 17, 2026 Aug 8, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those server...Show more |
4Debian LinuxNetapp+1 more7Debian Linux Element SoftwareEnterprise Linux+4 moreJun 17, 2026 Aug 7, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates tha...Show more |