CVEs (100)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianNetapp5Active Iq Advanced Package ToolDebian Linux+2 moreJun 17, 2026 Jan 28, 2019 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machi...Show more |
2Isc Netapp4Bind Data Ontap EdgeElement Software+1 moreNov 21, 2024 Jan 16, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop while handling a query. Affects BIND 9.9.10, 9.10.5, 9.11.0->9.11.1, 9....Show more |
3Debian IscNetapp5Bind Data Ontap EdgeDebian Linux+2 moreNov 21, 2024 Jan 16, 2019 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a re...Show more |
4Debian IscNetapp+1 more11Bind Data Ontap EdgeDebian Linux+8 moreNov 21, 2024 Jan 16, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when process...Show more |
4Debian IscNetapp+1 more11Bind Data Ontap EdgeDebian Linux+8 moreNov 21, 2024 Jan 16, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and terminate. An attacker could deliberately construct a query, enabling denial-of-service against a serv...Show more |
4Canonical NetappRedhat+1 more5Active Iq Performance Analytics Services Element SoftwareEnterprise Linux+2 moreNov 21, 2024 Jan 14, 2019 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When a service is run from an unprivileged user (e.g. User field set in the service file), a local attack...Show more |
5Canonical DebianNetapp+2 more21Active Iq Performance Analytics Services Debian LinuxElement Software+18 moreNov 21, 2024 Jan 11, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 a...Show more |
9Canonical DebianFujitsu+6 more22Cloud Backup Debian LinuxElement Software+19 moreDec 17, 2025 Jan 10, 2019 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the...Show more |
6Canonical DebianNetapp+3 more22Api Gateway Application ServerCloud Backup+19 moreNov 21, 2024 Oct 29, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affect...Show more |
3Linux NetappOpensuse4Active Iq Performance Analytics Services Element SoftwareLeap+1 moreNov 21, 2024 Sep 21, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in the Linux kernel before 4.8. Incorrect access checking in overlayfs mounts could be used by local attackers to modify or truncate files in the underlying filesystem. |
4Canonical DebianLinux+1 more5Active Iq Performance Analytics Services Debian LinuxElement Software+2 moreNov 21, 2024 Sep 19, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An attacker can trigger a use-after-free (and possibly gain privileges) v...Show more |
5Debian EclipseHp+2 more17Debian Linux E Series Santricity ManagementE Series Santricity Os Controller+14 moreNov 21, 2024 Jun 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vul...Show more |
2Eclipse Netapp12E Series Santricity Management Plug Ins E Series Santricity Os ControllerE Series Santricity Web Services Proxy+9 moreNov 21, 2024 Jun 22, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSes...Show more |
4Canonical FreebsdNetapp+1 more4Element Software FreebsdNtp+1 moreJun 17, 2026 Mar 8, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted array. |
3Canonical NetappNtp3Element Software NtpUbuntu LinuxJun 17, 2026 Mar 6, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mode 6 packet with a ntpd instance from 4.2.8p6 through 4.2.8p10. |
4Gnu NetappOracle+1 more15Cloud Backup Communications Session Border ControllerData Ontap Edge+12 moreJun 17, 2026 Feb 1, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too...Show more |
4Debian NetappOracle+1 more29Active Iq Unified Manager Cloud BackupDebian Linux+26 moreMay 13, 2026 Oct 19, 2017 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Difficult to exp...Show more |
4Debian NetappOracle+1 more29Active Iq Unified Manager Cloud BackupDebian Linux+26 moreMay 13, 2026 Oct 19, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily explo...Show more |
4Debian NetappOracle+1 more29Active Iq Unified Manager Cloud BackupDebian Linux+26 moreMay 13, 2026 Oct 19, 2017 N/A· v4 6.2 MEDIUM· v3 2.1 LOW· v2 Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit:...Show more |
4Debian NetappOracle+1 more30Active Iq Unified Manager Cloud BackupDebian Linux+27 moreMay 13, 2026 Oct 19, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRocki...Show more |