CVEs (42)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Debian FedoraprojectNetapp+3 more35A250 Firmware A700s FirmwareActive Iq Unified Manager+32 moreJun 17, 2026 May 3, 2022 N/A· v4 7.3 HIGH· v3 10.0 HIGH· v2 The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating sys...Show more |
6Apple DebianFedoraproject+3 more35Active Iq Unified Manager Bootstrap OsClustered Data Ontap+32 moreJun 17, 2026 Feb 26, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. |
4Debian NetappNodejs+1 more11Debian Linux Mysql ClusterMysql Connectors+8 moreJun 17, 2026 Feb 24, 2022 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one proper...Show more |
3Debian NodejsOracle9Debian Linux GraalvmMysql Cluster+6 moreJun 17, 2026 Feb 24, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name th...Show more |
3Debian NodejsOracle9Debian Linux GraalvmMysql Cluster+6 moreJun 17, 2026 Feb 24, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string...Show more |
2Nodejs Oracle8Graalvm Mysql ClusterMysql Connectors+5 moreJun 17, 2026 Feb 24, 2022 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, < 14.18.3, < 16.13.2...Show more |
6Debian FedoraprojectLibssh+3 more7Cloud Backup Debian LinuxEnterprise Linux+4 moreJun 17, 2026 Aug 31, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during the lifetime of the session. One of them is called secret_hash and the other session_id. Initially, bo...Show more |
7Debian McafeeNetapp+4 more32Clustered Data Ontap Clustered Data Ontap Antivirus ConnectorCommunications Cloud Native Core Console+29 moreJun 17, 2026 Aug 24, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are re...Show more |
6Debian FedoraprojectNetapp+3 more28Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+25 moreJun 17, 2026 May 19, 2021 N/A· v4 8.6 HIGH· v3 7.5 HIGH· v2 There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of...Show more |
6Debian FedoraprojectNetapp+3 more18Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+15 moreJun 17, 2026 May 18, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this fl...Show more |
6Debian FedoraprojectNetapp+3 more19Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+16 moreJun 17, 2026 May 14, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and...Show more |
10Fedoraproject FreebsdMcafee+7 more33Capture Client Cloud Volumes Ontap MediatorCommerce Guided Search+30 moreJun 17, 2026 Mar 25, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in t...Show more |
12Checkpoint DebianFedoraproject+9 more106Active Iq Unified Manager Capture ClientCloud Volumes Ontap Mediator+103 moreJun 17, 2026 Mar 25, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the...Show more |
2Oracle Sqlite7Communications Network Charging And Control Enterprise Manager For Oracle DatabaseJd Edwards Enterpriseone Tools+4 moreJun 17, 2026 Mar 23, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code exec...Show more |
6Debian FedoraprojectNetapp+3 more18Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+15 moreJun 17, 2026 Sep 4, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e. |
6Debian FedoraprojectNetapp+3 more12Cloud Backup Communications Messaging ServerCommunications Network Charging And Control+9 moreJun 17, 2026 Jun 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late. |
10Broadcom DebianFedoraproject+7 more26Active Iq Unified Manager Application ServerDebian Linux+23 moreJun 17, 2026 Apr 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert"...Show more |
6Canonical FedoraprojectLibssh+3 more6Cloud Backup Enterprise LinuxFedora+3 moreJun 17, 2026 Apr 13, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and...Show more |
5Netapp OracleSiemens+2 more12Communications Messaging Server Communications Network Charging And ControlEnterprise Manager Ops Center+9 moreJun 17, 2026 Apr 9, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement. |
7Canonical DebianNetapp+4 more18Communications Element Manager Communications Messaging ServerCommunications Network Charging And Control+15 moreJun 17, 2026 Apr 9, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled. |