CVEs (19)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Netapp Service Location Protocol ProjectSuse+1 more5Esxi Linux Enterprise ServerManager Server+2 moreJun 17, 2026 Apr 25, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with...Show more |
3Apple NetappXmlsoft17Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+14 moreJun 17, 2026 Nov 23, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked. |
6Broadcom DebianFedoraproject+3 more28Aff 8300 Firmware Aff 8700 FirmwareAff A400 Firmware+25 moreJun 17, 2026 Jun 21, 2022 N/A· v4 7.3 HIGH· v3 10.0 HIGH· v2 In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by...Show more |
2Netapp Openssl26A250 Firmware A700s FirmwareActive Iq Unified Manager+23 moreJun 17, 2026 May 3, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long...Show more |
2Netapp Openssl26A250 Firmware A700s FirmwareActive Iq Unified Manager+23 moreJun 17, 2026 May 3, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The OpenSSL 3.0 implementation of the RC4-MD5 ciphersuite incorrectly uses the AAD data as the MAC key. This makes the MAC key trivially predictable. An attacker could exploit this issue by performing a man-in-the-middle...Show more |
2Netapp Openssl26A250 Firmware A700s FirmwareActive Iq Unified Manager+23 moreJun 17, 2026 May 3, 2022 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification)...Show more |
6Debian FedoraprojectNetapp+3 more35A250 Firmware A700s FirmwareActive Iq Unified Manager+32 moreJun 17, 2026 May 3, 2022 N/A· v4 7.3 HIGH· v3 10.0 HIGH· v2 The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating sys...Show more |
5Debian FedoraprojectNetapp+2 more19Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+16 moreJun 17, 2026 May 3, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to...Show more |
6Apple DebianFedoraproject+3 more35Active Iq Unified Manager Bootstrap OsClustered Data Ontap+32 moreJun 17, 2026 Feb 26, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. |
4Netapp OracleRedhat+1 more19Active Iq Unified Manager Cloud BackupClustered Data Ontap+16 moreJun 17, 2026 Jul 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service. |
3Canonical Net SnmpNetapp6Cloud Backup Hci Management NodeNet Snmp+3 moreJun 17, 2026 Aug 20, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root. |
3Canonical Net SnmpNetapp5Cloud Backup Net SnmpSmi S Provider+2 moreJun 17, 2026 Aug 20, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following. |
10Broadcom DebianFedoraproject+7 more26Active Iq Unified Manager Application ServerDebian Linux+23 moreJun 17, 2026 Apr 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert"...Show more |
7Canonical DebianFedoraproject+4 more24Clustered Data Ontap Communications Cloud Native Core Network Function Cloud Native EnvironmentDebian Linux+21 moreJun 17, 2026 Jan 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation. |
6Debian FedoraprojectNetapp+3 more24Cloud Backup Clustered Data OntapCommunications Cloud Native Core Network Function Cloud Native Environment+21 moreJun 17, 2026 Jan 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak. |
13Canonical DebianF5+10 more82A220 Firmware A320 FirmwareA800 Firmware+79 moreJun 17, 2026 Feb 27, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte r...Show more |
6Canonical DebianNetapp+3 more22Api Gateway Application ServerCloud Backup+19 moreNov 21, 2024 Oct 29, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affect...Show more |
7Debian FujitsuNetapp+4 more45Adaptive Access Manager Application Testing SuiteClustered Data Ontap+42 moreMay 13, 2026 Nov 13, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use t...Show more |
2Ietf Netapp13Clustered Data Ontap Antivirus Connector Data Ontap EdgeHost Agent+10 moreMay 6, 2026 Sep 21, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in c...Show more |