Netapp
netapp
2,510 CVEs • 373 products
Products (373)
Click to collapseToggle
Products (373)
Click to collapse
CVEs (2,510)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian NetappNodejs+2 more7Debian Linux GraalvmJd Edwards Enterpriseone Tools+4 moreJun 17, 2026 Aug 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior. |
5Debian NetappNodejs+2 more8Debian Linux GraalvmJd Edwards Enterpriseone Tools+5 moreJun 17, 2026 Aug 16, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted. |
4Netapp NodejsOracle+1 more10Active Iq Unified Manager GraalvmMysql Cluster+7 moreJun 17, 2026 Aug 16, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can...Show more |
2Linux Netapp5Element Software Hci Bootstrap OsHci Management Node+2 moreJun 17, 2026 Aug 8, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the syste...Show more |
2Linux Netapp5Element Software Hci Bootstrap OsHci Management Node+2 moreJun 17, 2026 Aug 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is being used for nfsd. |
2Linux Netapp5Element Software Hci Bootstrap OsHci Management Node+2 moreJun 17, 2026 Aug 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdr_set_page_base slab-out-of-bounds access) by performing many NFS 4.2 READ_PLUS operations. |
3Debian LinuxNetapp6Debian Linux Element SoftwareHci Bootstrap Os+3 moreJun 17, 2026 Aug 8, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those server...Show more |
4Debian LinuxNetapp+1 more7Debian Linux Element SoftwareEnterprise Linux+4 moreJun 17, 2026 Aug 7, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates tha...Show more |
NetApp Cloud Manager versions prior to 3.9.9 log sensitive information when an Active Directory connection fails. The logged information is available only to authenticated users. Customers with auto-upgrade enabled shoul...Show more |
NetApp Cloud Manager versions prior to 3.9.9 log sensitive information that is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using on-prem...Show more |
4Debian NetappNettle Project+1 more4Debian Linux Enterprise LinuxNettle+1 moreJun 17, 2026 Aug 5, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service. |
5Haxx NetappOracle+2 more19Active Iq Unified Manager Clustered Data OntapCurl+16 moreJun 17, 2026 Aug 5, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is built to use the macOS n...Show more |
7Apple FedoraprojectHaxx+4 more20Cloud Backup Clustered Data OntapCurl+17 moreJun 17, 2026 Aug 5, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_EN...Show more |
7Debian FedoraprojectHaxx+4 more33Cloud Backup Clustered Data OntapDebian Linux+30 moreJun 17, 2026 Aug 5, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into ac...Show more |
6Fedoraproject HaxxNetapp+3 more16Cloud Backup Clustered Data OntapCurl+13 moreJun 17, 2026 Aug 5, 2021 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers fr...Show more |
6Fedoraproject HaxxNetapp+3 more16Cloud Backup Clustered Data OntapCurl+13 moreJun 17, 2026 Aug 5, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentf...Show more |
2Golang Netapp2Cloud Insights Telegraf Agent GoJun 17, 2026 Aug 2, 2021 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may contain an unsafe injection (e.g., XSS) that does not conform to the RFC...Show more |
2Kernel Netapp2Ontap Select Deploy Administration Utility Util LinuxJun 17, 2026 Jul 30, 2021 N/A· v4 5.5 MEDIUM· v3 1.2 LOW· v2 An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/sem file. NOTE: this is...Show more |
3Debian NetappOpenidc3Cloud Backup Debian LinuxMod Auth OpenidcJun 17, 2026 Jul 22, 2021 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. When mod_auth_openidc...Show more |
4Debian MitNetapp+1 more7Active Iq Unified Manager Debian LinuxKerberos 5+4 moreJun 17, 2026 Jul 22, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. Thi...Show more |