CVEs (211)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
8Canonical DebianFedoraproject+5 more20Active Iq Unified Manager Communications Design StudioDebian Linux+17 moreMay 28, 2026 Sep 9, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner." |
6Canonical DebianFedoraproject+3 more22Active Iq Unified Manager Aff A700s FirmwareDebian Linux+19 moreNov 6, 2025 Jul 17, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by lev...Show more |
7Apple CanonicalFedoraproject+4 more25Active Iq Unified Manager Cloud BackupClustered Data Ontap+22 moreMay 28, 2026 Jul 1, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of...Show more |
7Debian F5Fedoraproject+4 more11Debian Linux Enterprise Manager Ops CenterFedora+8 moreApr 15, 2026 May 28, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1. |
7Canonical DebianFedoraproject+4 more22Active Iq Unified Manager Cloud BackupDebian Linux+19 moreMay 28, 2026 Apr 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is...Show more |
13Canonical DebianF5+10 more82A220 Firmware A320 FirmwareA800 Firmware+79 moreNov 21, 2024 Feb 27, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte r...Show more |
4Canonical GnuMcafee+1 more6Cloud Backup GlibcOntap Select Deploy Administration Utility+3 moreNov 21, 2024 Feb 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match. |
2Gnu Netapp4Cloud Backup GlibcOntap Select Deploy Administration Utility+1 moreNov 21, 2024 Feb 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep. |
2Gnu Netapp4Cloud Backup GlibcOntap Select Deploy Administration Utility+1 moreNov 21, 2024 Feb 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an i...Show more |
9Canonical DebianFujitsu+6 more22Cloud Backup Debian LinuxElement Software+19 moreDec 17, 2025 Jan 10, 2019 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the...Show more |
5Debian FasterxmlNetapp+2 more20Banking Platform Business Process Management SuiteClusterware+17 moreNov 21, 2024 Jan 2, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization. |
5Debian FasterxmlNetapp+2 more25Banking Platform Business Process Management SuiteCommunications Billing And Revenue Management+22 moreNov 21, 2024 Jan 2, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization. |
7Canonical DebianNetapp+4 more22Aff Baseboard Management Controller Cloud BackupClustered Data Ontap+19 moreDec 17, 2025 Aug 17, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c,...Show more |
4Hp NetappOracle+1 more20Active Iq Unified Manager Cloud BackupE Series Santricity Os Controller+17 moreNov 21, 2024 Jul 18, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Difficult to exp...Show more |
2Netapp Oracle15Active Iq Unified Manager Cloud BackupE Series Santricity Os Controller+12 moreNov 21, 2024 Jul 18, 2018 N/A· v4 8.3 HIGH· v3 5.1 MEDIUM· v2 Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u172 and 10.0.1. Difficult to exploit vulnerability allows unauthenticated attacker...Show more |
6Canonical DebianHp+3 more26Active Iq Unified Manager Cloud BackupDebian Linux+23 moreNov 21, 2024 Jul 18, 2018 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171;...Show more |
2Netapp Oracle15Active Iq Unified Manager Cloud BackupE Series Santricity Os Controller+12 moreNov 21, 2024 Jul 18, 2018 N/A· v4 8.3 HIGH· v3 5.1 MEDIUM· v2 Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). Supported versions that are affected are Java SE: 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker...Show more |
2Netapp Oracle15Active Iq Unified Manager Cloud BackupE Series Santricity Os Controller+12 moreNov 21, 2024 Jul 18, 2018 N/A· v4 8.3 HIGH· v3 5.1 MEDIUM· v2 Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u181, 8u172 and 10.0.1. Difficult to exploit vulnerability allows unauthenticated attack...Show more |
4Hp NetappOracle+1 more20Active Iq Unified Manager Cloud BackupE Series Santricity Os Controller+17 moreNov 21, 2024 Jul 18, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Easily expl...Show more |
2Netapp Oracle15Active Iq Unified Manager Cloud BackupE Series Santricity Os Controller+12 moreNov 21, 2024 Jul 18, 2018 N/A· v4 9.0 CRITICAL· v3 6.8 MEDIUM· v2 Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB). Supported versions that are affected are Java SE: 6u191, 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attack...Show more |