CVEs (117)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian FedoraprojectLxml+2 more11Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+8 moreNov 21, 2024 Dec 13, 2021 N/A· v4 7.1 HIGH· v3 6.8 MEDIUM· v2 lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedde...Show more |
5Debian F5Oracle+2 more6Debian Linux Http ServerModsecurity+3 moreJul 3, 2025 Dec 7, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a modera...Show more |
6Debian FedoraprojectIsc+3 more15Bind Cloud BackupDebian Linux+12 moreNov 21, 2024 Oct 27, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development b...Show more |
5Fedoraproject NetappOpenbsd+2 more12Active Iq Unified Manager Aff 500f FirmwareAff A250 Firmware+9 moreMay 12, 2026 Sep 26, 2021 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCom...Show more |
11Apache BroadcomDebian+8 more39Brocade Fabric Operating System Firmware Cloud BackupClustered Data Ontap+36 moreOct 27, 2025 Sep 16, 2021 N/A· v4 9.0 CRITICAL· v3 6.8 MEDIUM· v2 A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. |
6Apache DebianFedoraproject+3 more11Cloud Backup Clustered Data OntapDebian Linux+8 moreMay 1, 2025 Sep 16, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Serve...Show more |
6Apache BroadcomDebian+3 more13Brocade Fabric Operating System Firmware Cloud BackupClustered Data Ontap+10 moreMay 1, 2025 Sep 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive). |
8Apache BroadcomDebian+5 more18Brocade Fabric Operating System Firmware Cloud BackupClustered Data Ontap+15 moreNov 21, 2024 Sep 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. |
7Debian McafeeNetapp+4 more32Clustered Data Ontap Clustered Data Ontap Antivirus ConnectorCommunications Cloud Native Core Console+29 moreApr 16, 2026 Aug 24, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are re...Show more |
5Debian NetappOpenssl+2 more31Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+28 moreNov 21, 2024 Aug 24, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be...Show more |
3Apple OracleSqlite6Iphone Os MacosSqlite+3 moreNov 3, 2025 Aug 24, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because...Show more |
5Apache DebianFedoraproject+2 more6Debian Linux FedoraHttp Server+3 moreMay 1, 2025 Aug 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48. |
4Netapp OracleRedhat+1 more19Active Iq Unified Manager Cloud BackupClustered Data Ontap+16 moreNov 21, 2024 Jul 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service. |
3Fedoraproject OraclePython5Enterprise Manager Ops Center FedoraInstantis Enterprisetrack+2 moreNov 21, 2024 Jun 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of...Show more |
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreNov 21, 2024 Jun 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used for the HTTP/1 protocol as well. On violation of these restri...Show more |
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreNov 21, 2024 Jun 10, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF' |
5Apache DebianFedoraproject+2 more8Cloud Backup Debian LinuxEnterprise Manager Ops Center+5 moreNov 21, 2024 Jun 10, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow |
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreNov 21, 2024 Jun 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service |
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreNov 21, 2024 Jun 10, 2021 N/A· v4 7.3 HIGH· v3 6.8 MEDIUM· v2 Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could cre...Show more |
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreNov 21, 2024 Jun 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of...Show more |