Netapp
netapp
2,510 CVEs • 373 products
Products (373)
Click to collapseToggle
Products (373)
Click to collapse
CVEs (2,510)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Oct 15, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel user could have access to the 'New Job' page to which they should not have access to. IBM X-Force ID: 201695. |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Oct 15, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled input that could be interpreted a a server-side include (SSI) directive. I...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Oct 15, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 IBM Cognos Analytics 11.1.7 and 11.2.0 contains locally cached browser data, that could allow a local attacker to obtain sensitive information. |
4Apache DebianNetapp+1 more18Agile Engineering Data Management Big Data Spatial And GraphCommunications Diameter Signaling Router+15 moreJun 17, 2026 Oct 14, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade conne...Show more |
3Debian NetappSamba5Debian Linux Management Services For Element SoftwareManagement Services For Netapp Hci+2 moreJun 17, 2026 Oct 12, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server. |
1Netapp 1Clustered Data Ontap Jun 17, 2026 Oct 12, 2021 N/A· v4 4.7 MEDIUM· v3 4.3 MEDIUM· v2 Clustered Data ONTAP versions prior to 9.5P18, 9.6P15, 9.7P14, 9.8P5 and 9.9.1 are missing an X-Frame-Options header which could allow a clickjacking attack. |
2Linux Netapp10H300e Firmware H300s FirmwareH410c Firmware+7 moreJun 17, 2026 Oct 11, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the ker...Show more |
NetApp Cloud Manager versions prior to 3.9.10 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to retrieve sensitive data via the web proxy. |
4Apache FedoraprojectNetapp+1 more6Cloud Backup FedoraHttp Server+3 moreJun 17, 2026 Oct 7, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives....Show more |
4Debian NetappNodejs+1 more4Debian Linux Nextgen ApiNode.js+1 moreJun 17, 2026 Oct 7, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior. |
4Apache FedoraprojectNetapp+1 more4Cloud Backup FedoraHttp Server+1 moreJun 17, 2026 Oct 5, 2021 N/A· v4 9.8 CRITICAL· v3 4.3 MEDIUM· v2 A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If fil...Show more |
4Apache FedoraprojectNetapp+1 more4Cloud Backup FedoraHttp Server+1 moreJun 17, 2026 Oct 5, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability wa...Show more |
3Debian LinuxNetapp11Debian Linux H300e FirmwareH300s Firmware+8 moreJun 17, 2026 Oct 5, 2021 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input from a process that has the CAP_NET_ADMIN capability can lead to root access. |
3Debian NetappRedis3Debian Linux HiredisManagement Services For Element Software And Netapp HciJun 17, 2026 Oct 4, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Hiredis is a minimalistic C client library for the Redis database. In affected versions Hiredis is vulnurable to integer overflow if provided maliciously crafted or corrupted `RESP` `mult-bulk` protocol data. When parsin...Show more |
5Debian FedoraprojectNetapp+2 more5Communications Operations Monitor Debian LinuxFedora+2 moreJun 17, 2026 Oct 4, 2021 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the underlying string library can be used to corrupt the heap and potentially result with denial of service or remote code exe...Show more |
5Debian FedoraprojectNetapp+2 more6Communications Operations Monitor Debian LinuxFedora+3 moreJun 17, 2026 Oct 4, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Redis is an open source, in-memory database that persists on disk. The redis-cli command line tool and redis-sentinel service may be vulnerable to integer overflow when parsing specially crafted large multi-bulk network...Show more |
5Debian FedoraprojectNetapp+2 more6Communications Operations Monitor Debian LinuxFedora+3 moreJun 17, 2026 Oct 4, 2021 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 Redis is an open source, in-memory database that persists on disk. An integer overflow bug affecting all versions of Redis can be exploited to corrupt the heap and potentially be used to leak arbitrary contents of the he...Show more |
5Debian FedoraprojectNetapp+2 more6Communications Operations Monitor Debian LinuxFedora+3 moreJun 17, 2026 Oct 4, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Redis is an open source, in-memory database that persists on disk. When parsing an incoming Redis Standard Protocol (RESP) request, Redis allocates memory according to user-specified values which determine the number of...Show more |
6Debian FedoraprojectNetapp+3 more8Communications Operations Monitor Debian LinuxEnterprise Linux+5 moreJun 17, 2026 Oct 4, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer. Thi...Show more |
5Debian FedoraprojectNetapp+2 more6Communications Operations Monitor Debian LinuxFedora+3 moreJun 17, 2026 Oct 4, 2021 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the ziplist data structure used by all versions of Redis can be exploited to corrupt the heap and potentially result with remo...Show more |