CVEs (289)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Ami Netapp10H300s Firmware H410c FirmwareH410s Firmware+7 moreNov 5, 2025 Mar 11, 2025 10.0 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality...Show more |
2Netapp Xmlsoft11Active Iq Unified Manager H300s FirmwareH410c Firmware+8 moreNov 3, 2025 Feb 18, 2025 N/A· v4 7.7 HIGH· v3 N/A· v2 libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is si...Show more |
2Netapp Xmlsoft11Active Iq Unified Manager H300s FirmwareH410c Firmware+8 moreNov 3, 2025 Feb 18, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XM...Show more |
2Haxx Netapp7Bootstrap Os CurlH300s Firmware+4 moreMar 17, 2026 Feb 5, 2025 N/A· v4 7.0 HIGH· v3 N/A· v2 libcurl would wrongly close the same eventfd file descriptor twice when taking
down a connection channel after having completed a threaded name resolve. |
2Haxx Netapp16Bootstrap Os CurlElement Software+13 moreJul 30, 2025 Feb 5, 2025 N/A· v4 3.4 LOW· v3 N/A· v2 When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itse...Show more |
2Netapp Xmlsoft9H300s Firmware H410c FirmwareH410s Firmware+6 moreNov 25, 2025 Dec 23, 2024 N/A· v4 9.1 CRITICAL· v3 N/A· v2 In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This m...Show more |
2Haxx Netapp11Bootstrap Os CurlH300s Firmware+8 moreNov 3, 2025 Dec 11, 2024 N/A· v4 3.4 LOW· v3 N/A· v2 When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests its...Show more |
3Debian Libexpat ProjectNetapp12Active Iq Unified Manager Debian LinuxH300s Firmware+9 moreOct 15, 2025 Oct 27, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser. |
3Debian HaxxNetapp10Active Iq Unified Manager Bootstrap OsCurl+7 moreJul 30, 2025 Sep 11, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly co...Show more |
2Netapp Openssl19500f Firmware A250 FirmwareActive Iq Unified Manager+16 moreMay 12, 2026 Sep 3, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process....Show more |
2Linux Netapp10Converged Systems Advisor Agent H300s FirmwareH410c Firmware+7 moreOct 1, 2025 May 30, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix nfsd4_encode_fattr4() crasher Ensure that args.acl is initialized early. It is used in an unconditional call to kfree() on the way out of nf...Show more |
3Debian GnuNetapp11Debian Linux Element SoftwareGlibc+8 moreMay 12, 2026 May 6, 2024 N/A· v4 7.4 HIGH· v3 N/A· v2 nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw...Show more |
3Debian GnuNetapp11Debian Linux GlibcH300s Firmware+8 moreMay 12, 2026 May 6, 2024 N/A· v4 7.3 HIGH· v3 N/A· v2 nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory allocat...Show more |
3Debian GnuNetapp12Active Iq Unified Manager Debian LinuxGlibc+9 moreMay 12, 2026 May 6, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache fails to add a not-found netgroup response to the cache, the client request can result in a null pointer dereference. T...Show more |
3Debian GnuNetapp8Debian Linux GlibcH300s Firmware+5 moreMay 12, 2026 May 6, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 nscd: Stack-based buffer overflow in netgroup cache If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted by client requests then a subsequent client request for netgroup data may result in a stack-bas...Show more |
3Apple HaxxNetapp7Bootstrap Os CurlH300s Firmware+4 moreJul 30, 2025 Mar 27, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostna...Show more |
4Apple FedoraprojectHaxx+1 more14Active Iq Unified Manager Bootstrap OsBrocade Fabric Operating System+11 moreJul 30, 2025 Mar 27, 2024 N/A· v4 8.6 HIGH· v3 N/A· v2 When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl i...Show more |
3Apple HaxxNetapp12Active Iq Unified Manager Bootstrap OsCurl+9 moreJul 30, 2025 Mar 27, 2024 N/A· v4 6.3 MEDIUM· v3 N/A· v2 libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and...Show more |
4Apple FedoraprojectHaxx+1 more10Bootstrap Os CurlFedora+7 moreJul 30, 2025 Mar 27, 2024 N/A· v4 3.5 LOW· v3 N/A· v2 When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below comman...Show more |
3Fedoraproject Libexpat ProjectNetapp14Active Iq Unified Manager FedoraH300s Firmware+11 moreNov 4, 2025 Mar 10, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate). |