CVEs (289)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Brocade DebianHaxx+2 more12Bootstrap Os Clustered Data OntapCurl+9 moreMay 27, 2026 May 26, 2022 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the...Show more |
2Linux Netapp9H300e Firmware H300s FirmwareH410c Firmware+6 moreNov 21, 2024 May 26, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A use-after-free flaw was found in the Linux kernel’s pipes functionality in how a user performs manipulations with the pipe post_one_notification() after free_pipe_info() that is already called. This flaw allows a local...Show more |
2Linux Netapp17Active Iq Unified Manager Bootstrap OsCloud Volumes Ontap Mediator+14 moreNov 21, 2024 May 25, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients. |
2Isc Netapp6Bind H300s FirmwareH410c Firmware+3 moreNov 21, 2024 May 19, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in thei...Show more |
3Debian LinuxNetapp10Debian Linux H300e FirmwareH300s Firmware+7 moreNov 21, 2024 May 18, 2022 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine. |
4Canonical DebianLinux+1 more11Debian Linux H300e FirmwareH300s Firmware+8 moreNov 21, 2024 May 17, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later v...Show more |
2Linux Netapp5H300s Firmware H410s FirmwareH500s Firmware+2 moreNov 21, 2024 May 17, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Integer Overflow or Wraparound vulnerability in io_uring of Linux Kernel allows local attacker to cause memory corruption and escalate privileges to root. This issue affects: Linux Kernel versions prior to 5.4.189; versi...Show more |
4Fedoraproject NetappPcre+1 more12Active Iq Unified Manager Enterprise LinuxFedora+9 moreNov 21, 2024 May 16, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused...Show more |
5Debian FedoraprojectNetapp+2 more13Active Iq Unified Manager Debian LinuxEnterprise Linux+10 moreMar 25, 2025 May 16, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regul...Show more |
3Debian LinuxNetapp10Debian Linux H300e FirmwareH300s Firmware+7 moreNov 21, 2024 May 16, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to cra...Show more |
3Debian LinuxNetapp138300 Firmware 8700 FirmwareA400 Firmware+10 moreNov 21, 2024 May 12, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag. |
3Debian NetappOpenldap8Debian Linux H300s FirmwareH410c Firmware+5 moreNov 21, 2024 May 4, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search ope...Show more |
2Netapp Openssl26A250 Firmware A700s FirmwareActive Iq Unified Manager+23 moreMay 5, 2025 May 3, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long...Show more |
2Netapp Openssl26A250 Firmware A700s FirmwareActive Iq Unified Manager+23 moreNov 21, 2024 May 3, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The OpenSSL 3.0 implementation of the RC4-MD5 ciphersuite incorrectly uses the AAD data as the MAC key. This makes the MAC key trivially predictable. An attacker could exploit this issue by performing a man-in-the-middle...Show more |
2Netapp Openssl26A250 Firmware A700s FirmwareActive Iq Unified Manager+23 moreMay 5, 2025 May 3, 2022 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification)...Show more |
6Debian FedoraprojectNetapp+3 more35A250 Firmware A700s FirmwareActive Iq Unified Manager+32 moreAug 13, 2025 May 3, 2022 N/A· v4 7.3 HIGH· v3 10.0 HIGH· v2 The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating sys...Show more |
5Debian FedoraprojectNetapp+2 more19Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+16 moreNov 21, 2024 May 3, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to...Show more |
3Fedoraproject LinuxNetapp8Fedora H300s FirmwareH410c Firmware+5 moreNov 21, 2024 May 2, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private. |
4Debian LinuxNetapp+1 more11Debian Linux Enterprise LinuxH300e Firmware+8 moreNov 21, 2024 Apr 29, 2022 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of intern...Show more |
4Debian LinuxNetapp+1 more11Debian Linux Enterprise LinuxH300e Firmware+8 moreNov 21, 2024 Apr 29, 2022 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. T...Show more |