CVEs (117)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache FedoraprojectOracle5Enterprise Manager Ops Center FedoraHttp Server+2 moreNov 21, 2024 Jun 10, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent reques...Show more |
3Debian OracleWireshark5Debian Linux Enterprise Manager Ops CenterInstantis Enterprisetrack+2 moreNov 21, 2024 Jun 7, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file |
4Lz4 Project NetappOracle+1 more7Active Iq Unified Manager Cloud BackupCommunications Cloud Native Core Policy+4 moreNov 21, 2024 Jun 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-b...Show more |
6Debian FedoraprojectNetapp+3 more9Clustered Data Ontap Clustered Data Ontap Antivirus ConnectorDebian Linux+6 moreNov 21, 2024 Jun 1, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidenti...Show more |
6Debian FedoraprojectNetapp+3 more10Cloud Backup Communications Cloud Native Core Binding Support FunctionDebian Linux+7 moreDec 18, 2025 May 20, 2021 N/A· v4 5.7 MEDIUM· v3 2.7 LOW· v2 There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive inform...Show more |
6Debian FedoraprojectNetapp+3 more28Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+25 moreDec 2, 2025 May 19, 2021 N/A· v4 8.6 HIGH· v3 7.5 HIGH· v2 There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of...Show more |
2Oracle Python6Communications Cloud Native Core Automated Test Suite Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Slice Selection Function+3 moreNov 3, 2025 May 6, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses. |
4Debian FedoraprojectOracle+1 more4Debian Linux FedoraWireshark+1 moreNov 21, 2024 Apr 23, 2021 N/A· v4 6.5 MEDIUM· v3 5.0 MEDIUM· v2 Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file |
12Checkpoint DebianFedoraproject+9 more106Active Iq Unified Manager Capture ClientCloud Volumes Ontap Mediator+103 moreNov 21, 2024 Mar 25, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the...Show more |
2Oracle Sqlite7Communications Network Charging And Control Enterprise Manager For Oracle DatabaseJd Edwards Enterpriseone Tools+4 moreNov 21, 2024 Mar 23, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code exec...Show more |
5Debian FedoraprojectLxml+2 more5Debian Linux FedoraLxml+2 moreDec 17, 2025 Mar 21, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS...Show more |
7Apple DebianNetapp+4 more23Business Intelligence Communications Cloud Native Core PolicyDebian Linux+20 moreNov 21, 2024 Feb 16, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle a...Show more |
3Openssl OracleSiemens8Business Intelligence Enterprise Manager For Storage ManagementEnterprise Manager Ops Center+5 moreNov 21, 2024 Feb 16, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configured to support both SSLv2 and more recent SSL and TLS versions then a check is made for a version rollback attack when un...Show more |
5Debian FedoraprojectNetapp+2 more10Active Iq Unified Manager Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Offline Mediation Controller+7 moreDec 18, 2025 Jan 19, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demons...Show more |
2Oracle Wireshark2Wireshark Zfs Storage Appliance KitNov 21, 2024 Dec 21, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Buffer overflow in QUIC dissector in Wireshark 3.4.0 to 3.4.1 allows denial of service via packet injection or crafted capture file |
4Debian FedoraprojectOracle+1 more4Debian Linux FedoraWireshark+1 moreNov 21, 2024 Dec 11, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file. |
3Fedoraproject OracleWireshark3Fedora WiresharkZfs Storage Appliance KitNov 21, 2024 Dec 11, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file. |
3Fedoraproject OracleWireshark3Fedora WiresharkZfs Storage Appliance KitNov 21, 2024 Dec 11, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file. |
4Debian FedoraprojectOracle+1 more4Debian Linux FedoraWireshark+1 moreNov 21, 2024 Dec 11, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file. |
3Fedoraproject OraclePytest3Fedora PyZfs Storage Appliance KitNov 3, 2025 Dec 9, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to th...Show more |