CVEs (27)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian GnuNetapp11Debian Linux Element SoftwareGlibc+8 moreMay 12, 2026 May 6, 2024 N/A· v4 7.4 HIGH· v3 N/A· v2 nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw...Show more |
3Debian GnuNetapp11Debian Linux GlibcH300s Firmware+8 moreMay 12, 2026 May 6, 2024 N/A· v4 7.3 HIGH· v3 N/A· v2 nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory allocat...Show more |
3Debian GnuNetapp12Active Iq Unified Manager Debian LinuxGlibc+9 moreMay 12, 2026 May 6, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache fails to add a not-found netgroup response to the cache, the client request can result in a null pointer dereference. T...Show more |
3Debian GnuNetapp8Debian Linux GlibcH300s Firmware+5 moreMay 12, 2026 May 6, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 nscd: Stack-based buffer overflow in netgroup cache If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted by client requests then a subsequent client request for netgroup data may result in a stack-bas...Show more |
2Intel Netapp3Hci Bootstrap Os Hci Compute Node BiosServer Platform ServicesJan 14, 2026 Feb 14, 2024 N/A· v4 4.9 MEDIUM· v3 N/A· v2 Uncontrolled resource consumption for some Intel(R) SPS firmware before version SPS_E5_06.01.04.002.0 may allow a privileged user to potentially enable denial of service via network access. |
2Netapp Openbsd4Brocade Fabric Operating System Hci Bootstrap OsOpenssh+1 moreMay 28, 2026 Mar 17, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9. |
3Gnu NetappRedhat5Active Iq Unified Manager Enterprise LinuxGnutls+2 moreNov 21, 2024 Aug 24, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authen...Show more |
3Debian LinuxNetapp24A700s Firmware Active Iq Unified ManagerAff 500f Firmware+21 moreMay 5, 2025 Jul 27, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice. |
3Haxx NetappSplunk10Clustered Data Ontap CurlH300s Firmware+7 moreNov 21, 2024 Jun 2, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given U...Show more |
4Debian HaxxNetapp+1 more12Clustered Data Ontap CurlDebian Linux+9 moreMay 27, 2026 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS g...Show more |
3Haxx NetappSplunk10Clustered Data Ontap CurlH300s Firmware+7 moreNov 21, 2024 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it is later retrieved.For example, a URL lik...Show more |
3Haxx NetappSplunk11Clustered Data Ontap CurlH300s Firmware+8 moreNov 21, 2024 Jun 2, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.curl can be told to receive and send cookies. curl's "cookie engine" can bebuilt with or without [Publ...Show more |
6Brocade DebianFedoraproject+3 more13Clustered Data Ontap CurlDebian Linux+10 moreNov 21, 2024 Jun 2, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number. |
5Brocade DebianHaxx+2 more12Clustered Data Ontap CurlDebian Linux+9 moreMay 27, 2026 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead. |
5Brocade DebianHaxx+2 more12Clustered Data Ontap CurlDebian Linux+9 moreMay 27, 2026 Jun 2, 2022 N/A· v4 5.7 MEDIUM· v3 3.5 LOW· v2 An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authenticat...Show more |
2Linux Netapp5Element Software Hci Bootstrap OsHci Management Node+2 moreNov 21, 2024 Aug 8, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the syste...Show more |
2Linux Netapp5Element Software Hci Bootstrap OsHci Management Node+2 moreMay 12, 2026 Aug 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is being used for nfsd. |
2Linux Netapp5Element Software Hci Bootstrap OsHci Management Node+2 moreNov 21, 2024 Aug 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdr_set_page_base slab-out-of-bounds access) by performing many NFS 4.2 READ_PLUS operations. |
3Debian LinuxNetapp6Debian Linux Element SoftwareHci Bootstrap Os+3 moreNov 21, 2024 Aug 8, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those server...Show more |
4Debian LinuxNetapp+1 more7Debian Linux Element SoftwareEnterprise Linux+4 moreMay 5, 2025 Aug 7, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates tha...Show more |