CVEs (290)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Linux Netapp5H300s Firmware H410s FirmwareH500s Firmware+2 moreJun 17, 2026 May 21, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 The Linux kernel 6.3 has a use-after-free in iopt_unmap_iova_range in drivers/iommu/iommufd/io_pagetable.c. |
3Debian LinuxNetapp7Debian Linux H300s FirmwareH410c Firmware+4 moreJun 17, 2026 May 15, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image after failure (with a dirty log journal). This flaw allows a local user to crash or potentially esca...Show more |
3Debian LinuxNetapp8Active Iq Unified Manager Debian LinuxH300s Firmware+5 moreJun 17, 2026 Apr 25, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The current implementation of the prctl syscall does not issue an IBPB immediately during the syscall. The ib_prctl_set function updates the Thread Information Flags (TIFs) for the task and updates the SPEC_CTRL MSR on...Show more |
4Debian FedoraprojectLinux+1 more8Debian Linux FedoraH300s Firmware+5 moreJun 17, 2026 Apr 25, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A denial of service problem was found, due to a possible recursive locking scenario, resulting in a deadlock in table_clear in drivers/md/dm-ioctl.c in the Linux Kernel Device Mapper-Multipathing sub-component. |
3Debian LinuxNetapp8Debian Linux H300s FirmwareH410c Firmware+5 moreJun 17, 2026 Apr 24, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabil...Show more |
2Linux Netapp6H300s Firmware H410c FirmwareH410s Firmware+3 moreJun 17, 2026 Mar 31, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 hci_conn_cleanup in net/bluetooth/hci_conn.c in the Linux kernel through 6.2.9 has a use-after-free (observed in hci_conn_hash_flush) because of calls to hci_dev_put and hci_conn_put. There is a double free that may lead...Show more |
6Broadcom DebianFedoraproject+3 more11Active Iq Unified Manager Brocade Fabric Operating System FirmwareClustered Data Ontap+8 moreJun 17, 2026 Mar 30, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcur...Show more |
4Broadcom HaxxNetapp+1 more9Active Iq Unified Manager Brocade Fabric Operating System FirmwareClustered Data Ontap+6 moreJun 17, 2026 Mar 30, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indi...Show more |
5Debian FedoraprojectHaxx+2 more10Active Iq Unified Manager Debian LinuxFedora+7 moreJun 17, 2026 Mar 30, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the...Show more |
5Debian FedoraprojectHaxx+2 more10Active Iq Unified Manager Debian LinuxFedora+7 moreJun 17, 2026 Mar 30, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in...Show more |
5Broadcom FedoraprojectHaxx+2 more9Active Iq Unified Manager Brocade Fabric Operating System FirmwareCurl+6 moreJun 17, 2026 Mar 30, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first...Show more |
4Fedoraproject HaxxNetapp+1 more9Active Iq Unified Manager Clustered Data OntapCurl+6 moreJun 17, 2026 Mar 30, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The la...Show more |
5Canonical DebianLinux+2 more9Debian Linux Enterprise LinuxH300s Firmware+6 moreJun 17, 2026 Mar 27, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than th...Show more |
3Debian LinuxNetapp128300 Firmware 8700 FirmwareA400 Firmware+9 moreJun 17, 2026 Mar 27, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG_ON condition, as the confused entry will not be NULL, but list_head.The buggy error condition would lead to a type conf...Show more |
4Canonical DebianLinux+1 more8Debian Linux H300s FirmwareH410c Firmware+5 moreJun 17, 2026 Mar 22, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid...Show more |
3Debian LinuxNetapp7Debian Linux H300s FirmwareH410c Firmware+4 moreJun 17, 2026 Feb 25, 2023 N/A· v4 4.7 MEDIUM· v3 N/A· v2 In the Linux kernel before 6.1.13, there is a double free in net/mpls/af_mpls.c upon an allocation failure (for registering the sysctl table under a new location) during the renaming of a device. |
5Debian FedoraprojectHaxx+2 more9Clustered Data Ontap CurlDebian Linux+6 moreJun 17, 2026 Feb 23, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potent...Show more |
3Haxx NetappSplunk8Active Iq Unified Manager Clustered Data OntapCurl+5 moreJun 17, 2026 Feb 23, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl...Show more |
3Haxx NetappSplunk8Active Iq Unified Manager Clustered Data OntapCurl+5 moreJun 17, 2026 Feb 23, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed t...Show more |
3Debian LinuxNetapp7Debian Linux H300s FirmwareH410c Firmware+4 moreJun 17, 2026 Dec 18, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_CHANNEL_LIST in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-ba...Show more |