Netapp
netapp
2,510 CVEs • 373 products
Products (373)
Click to collapseToggle
Products (373)
Click to collapse
CVEs (2,510)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache NetappOracle34Active Iq Unified Manager Banking ApisBanking Digital Experience+31 moreJun 17, 2026 Jul 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of serv...Show more |
3Apache NetappOracle27Active Iq Unified Manager Banking ApisBanking Digital Experience+24 moreJun 17, 2026 Jul 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of serv...Show more |
3Apache NetappOracle24Active Iq Unified Manager Banking Digital ExperienceBanking Enterprise Default Management+21 moreJun 17, 2026 Jul 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of servi...Show more |
3Apache NetappOracle26Active Iq Unified Manager Banking Digital ExperienceBanking Enterprise Default Management+23 moreJun 17, 2026 Jul 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that us...Show more |
4Netapp OracleRedhat+1 more19Active Iq Unified Manager Cloud BackupClustered Data Ontap+16 moreJun 17, 2026 Jul 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service. |
6Debian FedoraprojectLinux+3 more17Cloud Backup Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Exposure Function+14 moreJun 17, 2026 Jul 9, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or...Show more |
3Brocade LinuxNetapp21Aff 500f Firmware Aff A250 FirmwareAff A400 Firmware+18 moreJun 17, 2026 Jul 7, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space |
4Debian FedoraprojectNetapp+1 more8Active Iq Unified Manager Bootstrap OsDebian Linux+5 moreJun 17, 2026 Jul 1, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list). |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Jun 30, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configuration setting. An attacker could potentially bypass business logic to modify the appearance and behav...Show more |
2Linux Netapp10Cloud Backup H300e FirmwareH300s Firmware+7 moreJun 17, 2026 Jun 29, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with queue 0 in response to...Show more |
2Linux Netapp10Cloud Backup H300e FirmwareH300s Firmware+7 moreJun 17, 2026 Jun 24, 2021 N/A· v4 5.9 MEDIUM· v3 3.6 LOW· v2 The vgacon subsystem in the Linux kernel before 5.8.10 mishandles software scrollback. There is a vgacon_scrolldelta out-of-bounds read, aka CID-973c096f6a85. |
4Debian EclipseNetapp+1 more16Active Iq Unified Manager Autovue For Agile Product Lifecycle ManagementCommunications Element Manager+13 moreJun 17, 2026 Jun 22, 2021 N/A· v4 3.5 LOW· v3 3.6 LOW· v2 For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments w...Show more |
5Haxx NetappOracle+2 more26Active Iq Unified Manager Cloud BackupCommunications Cloud Native Core Binding Support Function+23 moreJun 17, 2026 Jun 11, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortu...Show more |
5Haxx NetappOracle+2 more22Cloud Backup Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Function Cloud Native Environment+19 moreJun 17, 2026 Jun 11, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set wa...Show more |
1Netapp 1E Series Santricity Os Controller Jun 17, 2026 Jun 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover system configuration and applicatio...Show more |
1Netapp 1E Series Santricity Os Controller Jun 17, 2026 Jun 11, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow privileged attackers to execute arbitrary code. |
1Netapp 1E Series Santricity Os Controller Jun 17, 2026 Jun 11, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to cause a partial Denial of Service (DoS) to t...Show more |
1Netapp 1E Series Santricity Os Controller Jun 17, 2026 Jun 11, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover information via error messaging whi...Show more |
2Netapp Redhat2Oncommand Insight ResteasyJun 17, 2026 Jun 10, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where it did not properly handle URL encoding when calling @javax.ws.rs.PathParam without any @Produces Med...Show more |
5Apache DebianFedoraproject+2 more8Cloud Backup Debian LinuxEnterprise Manager Ops Center+5 moreJun 17, 2026 Jun 10, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow |