CVEs (103)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Linux Netapp17Bootstrap Os Cloud Volumes Ontap MediatorE Series Santricity Os Controller+14 moreJun 17, 2026 Feb 26, 2022 N/A· v4 5.9 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID assignment policy allows an off-path attacker to inject data into a victim's TCP session or terminate...Show more |
5Debian FedoraprojectLinux+2 more21Active Iq Unified Manager Aff A700s FirmwareAff Baseboard Management Controller Firmware+18 moreJun 17, 2026 Feb 18, 2022 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remo...Show more |
4Libexpat Project NetappSiemens+1 more8Active Iq Unified Manager Clustered Data OntapHci Baseboard Management Controller+5 moreJun 17, 2026 Jan 6, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize. |
5Debian Libexpat ProjectNetapp+2 more8Active Iq Unified Manager Debian LinuxHci Baseboard Management Controller+5 moreJun 17, 2026 Jan 1, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory). |
3Linux NetappOracle26Aff A400 Firmware All Flash Fabric Attached Storage 8300 FirmwareAll Flash Fabric Attached Storage 8700 Firmware+23 moreJun 17, 2026 Dec 25, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers...Show more |
7Debian FedoraprojectHaxx+4 more33Cloud Backup Clustered Data OntapDebian Linux+30 moreJun 17, 2026 Aug 5, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into ac...Show more |
5Haxx NetappOracle+2 more26Active Iq Unified Manager Cloud BackupCommunications Cloud Native Core Binding Support Function+23 moreJun 17, 2026 Jun 11, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortu...Show more |
5Haxx NetappOracle+2 more22Cloud Backup Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Function Cloud Native Environment+19 moreJun 17, 2026 Jun 11, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set wa...Show more |
2Linux Netapp22Aff 8300 Firmware Aff 8700 FirmwareAff A400 Firmware+19 moreJun 17, 2026 Jun 7, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_state_fini panic, aka CID-dbb2483b2a46. |
3Fedoraproject LinuxNetapp12Cloud Backup FedoraH300e Firmware+9 moreJun 17, 2026 May 27, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 kernel/bpf/verifier.c in the Linux kernel through 5.12.7 enforces incorrect limits for pointer arithmetic operations, aka CID-bb01a1bba579. This can be abused to perform out-of-bounds reads and writes in kernel memory, l...Show more |
5Debian FedoraprojectIsc+2 more16Debian Linux DhcpFedora+13 moreJun 17, 2026 May 26, 2021 N/A· v4 7.4 HIGH· v3 3.3 LOW· v2 In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches of ISC DHCP (i.e., releases in the 4.0.x series or lower and releases in the 4.3.x series) are beyond their End-of-Life (EOL) and no longer s...Show more |
3Debian LinuxNetapp13Cloud Backup Debian LinuxH300e Firmware+10 moreJun 17, 2026 May 26, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability was found in the Linux Kernel where the function sunkbd_reinit having been scheduled by sunkbd_interrupt before sunkbd being freed. Though the dangling pointer is set to NULL in sunkbd_disconnect, there i...Show more |
3Debian LinuxNetapp15500f Firmware A250 FirmwareCloud Backup+12 moreJun 17, 2026 May 26, 2021 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op. |
2Linux Netapp12Cloud Backup H300e FirmwareH300s Firmware+9 moreJun 17, 2026 May 14, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the kernel context and privilege escalation, aka CID-c3e2219216c9. This is related to blk_mq_free_rqs a...Show more |
5Broadcom DebianFedoraproject+2 more15Brocade Fabric Operating System Cloud BackupDebian Linux+12 moreJun 17, 2026 Apr 22, 2021 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called w...Show more |
4Broadcom GnuNetapp+1 more6Binutils Brocade Fabric Operating System FirmwareCloud Backup+3 moreJun 17, 2026 Mar 26, 2021 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a...Show more |
2Netapp Vmware4Element Plug In For Vcenter Server Management Services For Element Software And Netapp HciSolidfire & Hci Management Node+1 moreJun 17, 2026 Mar 15, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to Remote Code Execution....Show more |
4Debian FedoraprojectLinux+1 more8Cloud Backup Debian LinuxFedora+5 moreJun 17, 2026 Feb 17, 2021 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in the Linux kernel 3.2 through 5.10.16, as used by Xen. Grant mapping operations often occur in batch hypercalls, where a number of operations are done in a single hypercall, the success or failu...Show more |
2Linux Netapp9Aff Baseboard Management Controller Baseboard Management Controller 500f FirmwareBaseboard Management Controller A250 Firmware+6 moreJun 17, 2026 Feb 5, 2021 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock/af_vsock.c. The race conditions were im...Show more |
4Broadcom GnuNetapp+1 more8Binutils Brocade Fabric Operating SystemCloud Backup+5 moreJun 17, 2026 Jan 4, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dere...Show more |