CVEs (83)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian NetappOracle+1 more25Active Iq Unified Manager Cloud BackupDebian Linux+22 moreMay 13, 2026 Aug 8, 2017 N/A· v4 8.3 HIGH· v3 5.1 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Difficult to exploit...Show more |
4Debian NetappOracle+1 more26Active Iq Unified Manager Cloud BackupDebian Linux+23 moreMay 13, 2026 Aug 8, 2017 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Difficult to exploit vulnerability allows unauthenticated attac...Show more |
5Debian NetappOracle+2 more28Active Iq Unified Manager Cloud BackupDebian Linux+25 moreMay 13, 2026 Aug 8, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14...Show more |
3Debian NetappNtp7Clustered Data Ontap Data OntapDebian Linux+4 moreMay 13, 2026 Aug 7, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication. |
4Debian NetappNtp+1 more9Clustered Data Ontap Data OntapDebian Linux+6 moreMay 13, 2026 Aug 7, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion failure) via a 6 or mode 7 packet containing a long data value. |
2Netapp Ntp6Clustered Data Ontap Data OntapNtp+3 moreMay 13, 2026 Aug 7, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Buffer overflow in the password management functionality in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary co...Show more |
2Netapp Ntp6Clustered Data Ontap Data OntapNtp+3 moreMay 13, 2026 Aug 7, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The datalen parameter in the refclock driver in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a negative input value. |
5Debian NetappNtp+2 more14Clustered Data Ontap Data OntapDebian Linux+11 moreMay 13, 2026 Aug 7, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 ntpq in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted mode 6 response packets. |
3Debian NetappNtp7Clustered Data Ontap Data OntapDebian Linux+4 moreMay 13, 2026 Aug 7, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (infinite loop or crash) by pointing the key file at the log file. |
2Netapp Ntp6Clustered Data Ontap Data OntapNtp+3 moreMay 13, 2026 Aug 7, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to possibly execute arbitrary code or cause a denial of service (crash) via crafted packets. |
9Apple CanonicalDebian+6 more39Active Iq Unified Manager Cloud BackupDatabase Server+36 moreJul 14, 2026 May 23, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. |
7Apache ArubanetworksHp+4 more9Clearpass Policy Manager Oncommand BalanceServer Automation+6 moreApr 21, 2026 Mar 11, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to ex...Show more |
6Canonical DebianLittlecms+3 more19Active Iq Unified Manager Debian LinuxE Series Santricity Management+16 moreMay 13, 2026 Feb 3, 2017 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bo...Show more |
7Debian FreebsdNetapp+4 more17Clustered Data Ontap Communications User Data RepositoryData Ontap+14 moreMay 13, 2026 Jan 30, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value. |
8Canonical DebianFedoraproject+5 more10Clustered Data Ontap Debian LinuxFedora+7 moreMay 13, 2026 Jan 30, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command. |
5Canonical FreebsdNetapp+2 more7Clustered Data Ontap FreebsdNtp+4 moreMay 13, 2026 Jan 30, 2017 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network. |
2Netapp Ntp6Clustered Data Ontap Data Ontap Operating In 7 ModeNtp+3 moreMay 23, 2025 Jan 6, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a specially crafted private mode packet. The crafted packet needs to have the correct message authenticati...Show more |
7Canonical DebianFedoraproject+4 more18Cloud Backup Debian LinuxEnterprise Linux+15 moreApr 21, 2026 Nov 10, 2016 N/A· v4 7.0 HIGH· v3 7.2 HIGH· v2 Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping,...Show more |
8Apache CanonicalDebian+5 more38Cassandra Debian LinuxE Series Santricity Management Plug Ins+35 moreApr 22, 2026 Apr 21, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. |
4Debian NetappNtp+1 more6Clustered Data Ontap Debian LinuxNtp+3 moreMay 6, 2026 Jan 26, 2016 N/A· v4 7.7 HIGH· v3 4.0 MEDIUM· v2 NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted k...Show more |