CVEs (26)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Haxx Netapp8Curl Hci Baseboard Management ControllerHci H610c Firmware+5 moreJun 17, 2026 Feb 5, 2025 N/A· v4 7.3 HIGH· v3 N/A· v2 When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would ma...Show more |
2Haxx Netapp16Bootstrap Os CurlElement Software+13 moreJun 17, 2026 Feb 5, 2025 N/A· v4 3.4 LOW· v3 N/A· v2 When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itse...Show more |
2Netapp Xmlsoft9H300s Firmware H410c FirmwareH410s Firmware+6 moreJun 17, 2026 Dec 23, 2024 N/A· v4 9.1 CRITICAL· v3 N/A· v2 In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This m...Show more |
3Debian Libexpat ProjectNetapp12Active Iq Unified Manager Debian LinuxH300s Firmware+9 moreJun 17, 2026 Oct 27, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser. |
2Linux Netapp10Converged Systems Advisor Agent H300s FirmwareH410c Firmware+7 moreJun 17, 2026 May 30, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix nfsd4_encode_fattr4() crasher Ensure that args.acl is initialized early. It is used in an unconditional call to kfree() on the way out of nf...Show more |
3Debian GnuNetapp11Debian Linux Element SoftwareGlibc+8 moreJun 17, 2026 May 6, 2024 N/A· v4 7.4 HIGH· v3 N/A· v2 nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw...Show more |
3Linux NetappRedhat5Active Iq Unified Manager Enterprise LinuxLinux Kernel+2 moreJun 17, 2026 Nov 1, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-a...Show more |
3Certifi FedoraprojectNetapp8Active Iq Unified Manager CertifiFedora+5 moreJun 17, 2026 Jul 25, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certifi...Show more |
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP and SMB2_LOGOFF commands. The issue results from the lack of pro...Show more |
2Linux Netapp7H300s H410sH500s+4 moreJun 17, 2026 Jul 18, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2misc.c in ksmbd does not validate the relationship between the command payload size and the RFC1002 length specification, leading to an out-of-...Show more |
2Linux Netapp7H300s H410sH500s+4 moreJun 17, 2026 Jul 18, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ksmbd does not properly check the UserName value because it does not consider the address of security buffer, leading to an out-of-bounds re...Show more |
2Linux Netapp7H300s H410sH500s+4 moreJun 17, 2026 Jul 18, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An issue was discovered in the Linux kernel before 6.3.4. ksmbd has an out-of-bounds read in smb2_find_context_vals when create_context's name_len is larger than the tag length. |
3Debian LinuxNetapp7Active Iq Unified Manager Debian LinuxHci Compute Node+4 moreJun 17, 2026 Jul 27, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 nfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a denial of service (panic) because, in the case of an nf_queue verdict with a one-byte nfta_payload at...Show more |
4Debian EclipseJenkins+1 more8Debian Linux Element Plug In For Vcenter ServerHci Compute Node+5 moreJun 17, 2026 Jul 7, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can...Show more |
3Debian EclipseNetapp7Debian Linux Element Plug In For Vcenter ServerHci Compute Node+4 moreJun 17, 2026 Jul 7, 2022 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid inpu...Show more |
6Brocade DebianFedoraproject+3 more13Clustered Data Ontap CurlDebian Linux+10 moreJun 17, 2026 Jun 2, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number. |
5Brocade DebianHaxx+2 more12Clustered Data Ontap CurlDebian Linux+9 moreJun 17, 2026 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead. |
5Brocade DebianHaxx+2 more12Clustered Data Ontap CurlDebian Linux+9 moreJun 17, 2026 Jun 2, 2022 N/A· v4 5.7 MEDIUM· v3 3.5 LOW· v2 An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authenticat...Show more |
5Brocade DebianHaxx+2 more12Bootstrap Os Clustered Data OntapCurl+9 moreJun 17, 2026 May 26, 2022 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the...Show more |
5Debian LinuxNetapp+2 more18Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+15 moreJun 17, 2026 Mar 2, 2022 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can s...Show more |