CVEs (148)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Apple DebianFedoraproject+3 more35Active Iq Unified Manager Bootstrap OsClustered Data Ontap+32 moreJun 17, 2026 Feb 26, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. |
2Linux Netapp17Bootstrap Os Cloud Volumes Ontap MediatorE Series Santricity Os Controller+14 moreJun 17, 2026 Feb 26, 2022 N/A· v4 5.9 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID assignment policy allows an off-path attacker to inject data into a victim's TCP session or terminate...Show more |
2Linux Netapp9H300e Firmware H300s FirmwareH410c Firmware+6 moreJun 17, 2026 Feb 18, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw use after free in the Linux kernel Management Component Transport Protocol (MCTP) subsystem was found in the way user triggers cancel_work_sync after the unregister_netdev during removing device. A local user coul...Show more |
2Linux Netapp9H300e Firmware H300s FirmwareH410c Firmware+6 moreJun 17, 2026 Feb 18, 2022 N/A· v4 7.1 HIGH· v3 6.6 MEDIUM· v2 An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write beyond bmval[bmlen-1] in nfsd4_decode_bitmap4 in fs/nfsd/nfs4xdr.c. In this flaw, a local attacker wi...Show more |
5Debian FedoraprojectLinux+2 more21Active Iq Unified Manager Aff A700s FirmwareAff Baseboard Management Controller Firmware+18 moreJun 17, 2026 Feb 18, 2022 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remo...Show more |
2Linux Netapp9Baseboard Management Controller Firmware H300e FirmwareH300s Firmware+6 moreJun 17, 2026 Feb 16, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20). This can cause execution of bytes located...Show more |
4Debian FedoraprojectLinux+1 more11Debian Linux FedoraH300e Firmware+8 moreJun 17, 2026 Feb 16, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in the Linux kernel. A use-after-free vulnerability in the NFC stack can lead to a threat to confidentiality, integrity, and system availability. |
6Debian FedoraprojectLinux+3 more193scale Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Exposure Function+16 moreJun 17, 2026 Feb 16, 2022 N/A· v4 7.1 HIGH· v3 7.9 HIGH· v2 A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or...Show more |
2Linux Netapp9H300e Firmware H300s FirmwareH410c Firmware+6 moreJun 17, 2026 Feb 11, 2022 N/A· v4 8.4 HIGH· v3 7.2 HIGH· v2 A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unpr...Show more |
4Debian FedoraprojectLinux+1 more11Debian Linux FedoraH300e Firmware+8 moreJun 17, 2026 Feb 11, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release. |
3Fedoraproject LinuxNetapp10Fedora H300e FirmwareH300s Firmware+7 moreJun 17, 2026 Jan 29, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace. |
2Linux Netapp9H300e Firmware H300s FirmwareH410c Firmware+6 moreJun 17, 2026 Jan 25, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.14-rc3. An attacker must first obtain the ability to execute low-privileged code on the target system in order...Show more |
4Debian LinuxNetapp+1 more15Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+12 moreJun 17, 2026 Jan 18, 2022 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in the way users call close() and fget() simultaneously and can potentially trigger a race condition....Show more |
4Debian FedoraprojectLinux+1 more11Debian Linux FedoraH300e Firmware+8 moreJun 17, 2026 Jan 14, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types. |
3Linux NetappOracle26Aff A400 Firmware All Flash Fabric Attached Storage 8300 FirmwareAll Flash Fabric Attached Storage 8700 Firmware+23 moreJun 17, 2026 Dec 25, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers...Show more |
4Debian FedoraprojectLinux+1 more11Debian Linux FedoraH300e Firmware+8 moreJun 17, 2026 Dec 23, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry. |
5Debian FedoraprojectLinux+2 more12Debian Linux Enterprise LinuxFedora+9 moreJun 17, 2026 Dec 22, 2021 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object. |
2Ksmbd Project Netapp9H300e Firmware H300s FirmwareH410c Firmware+6 moreJun 17, 2026 Dec 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabled. This occurs because it sets the SMB2_GLOBAL_CAP_ENCRYPTION flag whe...Show more |
3Netapp NodejsOpenssl16500f Firmware A250 FirmwareCloud Backup+13 moreJun 17, 2026 Dec 14, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of me...Show more |
2Linux Netapp10Cloud Backup H300e FirmwareH300s Firmware+7 moreNov 21, 2024 Dec 8, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an...Show more |