CVEs (103)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Netapp Xmlsoft11Active Iq Unified Manager H300s FirmwareH410c Firmware+8 moreJun 17, 2026 Feb 18, 2025 N/A· v4 7.7 HIGH· v3 N/A· v2 libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is si...Show more |
2Netapp Xmlsoft11Active Iq Unified Manager H300s FirmwareH410c Firmware+8 moreJun 17, 2026 Feb 18, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XM...Show more |
2Haxx Netapp8Curl Hci Baseboard Management ControllerHci H610c Firmware+5 moreJun 17, 2026 Feb 5, 2025 N/A· v4 7.3 HIGH· v3 N/A· v2 When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would ma...Show more |
2Haxx Netapp16Bootstrap Os CurlElement Software+13 moreJun 17, 2026 Feb 5, 2025 N/A· v4 3.4 LOW· v3 N/A· v2 When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itse...Show more |
2Netapp Xmlsoft9H300s Firmware H410c FirmwareH410s Firmware+6 moreJun 17, 2026 Dec 23, 2024 N/A· v4 9.1 CRITICAL· v3 N/A· v2 In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This m...Show more |
3Debian Libexpat ProjectNetapp12Active Iq Unified Manager Debian LinuxH300s Firmware+9 moreJun 17, 2026 Oct 27, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser. |
2Linux Netapp10Converged Systems Advisor Agent H300s FirmwareH410c Firmware+7 moreJun 17, 2026 May 30, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix nfsd4_encode_fattr4() crasher Ensure that args.acl is initialized early. It is used in an unconditional call to kfree() on the way out of nf...Show more |
3Debian GnuNetapp11Debian Linux Element SoftwareGlibc+8 moreJun 17, 2026 May 6, 2024 N/A· v4 7.4 HIGH· v3 N/A· v2 nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw...Show more |
3Linux NetappRedhat5Active Iq Unified Manager Enterprise LinuxLinux Kernel+2 moreJun 17, 2026 Nov 1, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-a...Show more |
2Linux Netapp6H300s H410sH500s+3 moreJun 17, 2026 Jul 18, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/connection.c in ksmbd does not validate the relationship between the NetBIOS header's length field and the SMB header sizes, via pdu_size in ksmbd_c...Show more |
2Linux Netapp7H300s H410sH500s+4 moreJun 17, 2026 Jul 18, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ksmbd does not properly check the UserName value because it does not consider the address of security buffer, leading to an out-of-bounds re...Show more |
2Linux Netapp7H300s H410sH500s+4 moreJun 17, 2026 Jul 18, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An issue was discovered in the Linux kernel before 6.3.4. ksmbd has an out-of-bounds read in smb2_find_context_vals when create_context's name_len is larger than the tag length. |
3Debian LinuxNetapp8Debian Linux H300s FirmwareH410c Firmware+5 moreJun 17, 2026 Apr 24, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabil...Show more |
4Debian FedoraprojectLibexpat Project+1 more12Active Iq Unified Manager Debian LinuxFedora+9 moreJun 17, 2026 Oct 24, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations. |
3Gnu NetappRedhat5Active Iq Unified Manager Enterprise LinuxGnutls+2 moreJun 17, 2026 Aug 24, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authen...Show more |
3Debian LinuxNetapp7Active Iq Unified Manager Debian LinuxHci Compute Node+4 moreJun 17, 2026 Jul 27, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 nfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a denial of service (panic) because, in the case of an nf_queue verdict with a one-byte nfta_payload at...Show more |
3Haxx NetappSplunk10Clustered Data Ontap CurlH300s Firmware+7 moreJun 17, 2026 Jun 2, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given U...Show more |
4Debian HaxxNetapp+1 more12Clustered Data Ontap CurlDebian Linux+9 moreJun 17, 2026 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS g...Show more |
3Haxx NetappSplunk10Clustered Data Ontap CurlH300s Firmware+7 moreJun 17, 2026 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it is later retrieved.For example, a URL lik...Show more |
3Haxx NetappSplunk11Clustered Data Ontap CurlH300s Firmware+8 moreJun 17, 2026 Jun 2, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.curl can be told to receive and send cookies. curl's "cookie engine" can bebuilt with or without [Publ...Show more |