CVEs (289)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian NetappOpenssl7Debian Linux H300s FirmwareH410c Firmware+4 moreJun 17, 2026 Oct 25, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Issue summary: A bug has been identified in the processing of key and initialisation vector (IV) lengths. This can lead to potential truncation or overruns during the initialisation of some symmetric ciphers. Impact su...Show more |
2Linux Netapp5H300s Firmware H410s FirmwareH500s Firmware+2 moreJun 17, 2026 Oct 16, 2023 N/A· v4 6.3 MEDIUM· v3 N/A· v2 extract_user_to_sg in lib/scatterlist.c in the Linux kernel before 6.4.12 fails to unpin pages in a certain situation, as demonstrated by a WARNING for try_grab_page. |
7Canonical DebianFedoraproject+4 more39Bootstrap Os Codeready Linux BuilderCodeready Linux Builder Eus+36 moreJun 17, 2026 Oct 3, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES env...Show more |
4Debian FedoraprojectIsc+1 more8Bind Debian LinuxFedora+5 moreJun 17, 2026 Sep 20, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS...Show more |
4Fedoraproject GnuNetapp+1 more27Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little EndianCodeready Linux Builder Eus For Power Little Endian Eus+24 moreJun 17, 2026 Sep 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can...Show more |
4Fedoraproject GnuNetapp+1 more16Active Iq Unified Manager Enterprise LinuxEnterprise Linux Eus+13 moreJun 17, 2026 Sep 12, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is...Show more |
5Debian FedoraprojectLinux+2 more8Debian Linux Enterprise LinuxFedora+5 moreJun 17, 2026 Aug 9, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementation of the file name reconstruction function, which is responsible for reading file name entries from a directory index...Show more |
2Linux Netapp6H300s Firmware H410c FirmwareH410s Firmware+3 moreJun 17, 2026 Jul 24, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_LOGOFF commands. The issue results from the lack of proper validation of a point...Show more |
5Debian FedoraprojectLinux+2 more9Debian Linux Enterprise LinuxFedora+6 moreJun 17, 2026 Jun 23, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evict code tries to reference the journal descriptor structure after it has been fre...Show more |
4Debian FedoraprojectIsc+1 more9Active Iq Unified Manager BindDebian Linux+6 moreJun 17, 2026 Jun 21, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-related lookups could cause `named` to loop...Show more |
2Isc Netapp7Active Iq Unified Manager BindH300s Firmware+4 moreJun 17, 2026 Jun 21, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A `named` instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cache (RFC 8198) option (`synth-from-dnssec`) enabled can be remotely terminated using a zone wit...Show more |
4Debian FedoraprojectIsc+1 more9Active Iq Unified Manager BindDebian Linux+6 moreJun 17, 2026 Jun 21, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can b...Show more |
4Canonical DebianLinux+1 more8Debian Linux H300s FirmwareH410c Firmware+5 moreJun 17, 2026 Jun 16, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may...Show more |
3Debian LinuxNetapp7Debian Linux H300s FirmwareH410c Firmware+4 moreJun 17, 2026 Jun 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defra...Show more |
4Apple NetappOpenldap+1 more11Active Iq Unified Manager Clustered Data OntapEnterprise Linux+8 moreJun 17, 2026 May 30, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function. |
3Debian LinuxNetapp7Debian Linux H300s FirmwareH410c Firmware+4 moreJun 17, 2026 May 26, 2023 N/A· v4 4.7 MEDIUM· v3 N/A· v2 There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw allows a local privileged user to cause a denial of service problem. |
4Apple FedoraprojectHaxx+1 more9Clustered Data Ontap CurlFedora+6 moreJun 17, 2026 May 26, 2023 N/A· v4 3.7 LOW· v3 N/A· v2 An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFI...Show more |
5Apple DebianFedoraproject+2 more10Clustered Data Ontap CurlDebian Linux+7 moreJun 17, 2026 May 26, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use...Show more |
3Apple HaxxNetapp8Clustered Data Ontap CurlH300s Firmware+5 moreJun 17, 2026 May 26, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows...Show more |
3Apple HaxxNetapp8Clustered Data Ontap CurlH300s Firmware+5 moreJun 17, 2026 May 26, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprin...Show more |