Netapp
netapp
2,507 CVEs • 371 products
Products (371)
Click to collapseToggle
Products (371)
Click to collapse
CVEs (2,507)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical FedoraprojectNetapp+1 more7Active Iq Unified Manager FedoraMysql+4 moreNov 21, 2024 Jul 15, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 5.7.30 and prior and 8.0.20 and prior. Easily exploitable vulnerability allows high privileged...Show more |
4Canonical FedoraprojectNetapp+1 more7Active Iq Unified Manager FedoraMysql+4 moreNov 21, 2024 Jul 15, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.6.48 and prior, 5.7.30 and prior and 8.0.20 and prior. Easily exploitable vulnerability...Show more |
7Apache CanonicalDebian+4 more18Agile Engineering Data Management Agile PlmBlockchain Platform+15 moreNov 21, 2024 Jul 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite lo...Show more |
6Apache CanonicalDebian+3 more14Agile Engineering Data Management Agile PlmCommunications Instant Messaging Server+11 moreNov 21, 2024 Jul 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were ma...Show more |
7Canonical DebianFedoraproject+4 more8Active Iq Unified Manager Cloud Volumes Ontap MediatorDebian Linux+5 moreNov 21, 2024 Jul 13, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation. |
2Netapp Python2Python SnapcenterNov 21, 2024 Jul 4, 2020 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native application. This occurs...Show more |
3Fedoraproject NetappSquid Cache3Cloud Manager FedoraSquidNov 21, 2024 Jun 30, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Squid before 4.12 and 5.x before 5.0.3. Due to use of a potentially dangerous function, Squid and the default certificate validation helper are vulnerable to a Denial of Service when opening a...Show more |
2Netapp Openbsd9Active Iq Unified Manager Aff A700s FirmwareHci Compute Node+6 moreDec 18, 2025 Jun 29, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where n...Show more |
3Fedoraproject NetappPutty3Fedora Oncommand Unified Manager Core PackagePuttyNov 21, 2024 Jun 29, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the...Show more |
The NetApp HCI H610C, H615C and H610S Baseboard Management Controllers (BMC) are shipped with a documented default account and password that should be changed during the initial node setup. During upgrades to Element 11....Show more |
6Apache CanonicalDebian+3 more8Debian Linux LeapMysql Enterprise Monitor+5 moreNov 21, 2024 Jun 26, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such reques...Show more |
2Apache Netapp3Activemq Artemis ArtemisOncommand Workflow AutomationJun 15, 2026 Jun 26, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properties file) when executi...Show more |
4Netapp NtpOpensuse+1 more168300 Firmware 8700 FirmwareA400 Firmware+13 moreNov 21, 2024 Jun 24, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used...Show more |
2Jsrsasign Project Netapp2Jsrsasign Max DataNov 21, 2024 Jun 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in the jsrsasign package before 8.0.17 for Node.js. Its RSASSA-PSS (RSA-PSS) implementation does not detect signature manipulation/modification by prepending '\0' bytes to a signature (it accepts...Show more |
2Jsrsasign Project Netapp2Jsrsasign Max DataNov 21, 2024 Jun 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in the jsrsasign package before 8.0.18 for Node.js. Its RSA PKCS1 v1.5 decryption implementation does not detect ciphertext modification by prepending '\0' bytes to ciphertexts (it decrypts modifi...Show more |
2Jsrsasign Project Netapp2Jsrsasign Max DataNov 21, 2024 Jun 22, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the jsrsasign package through 8.0.18 for Node.js. It allows a malleability in ECDSA signatures by not checking overflows in the length of a sequence and '0' characters appended or prepended to...Show more |
6Canonical DebianFedoraproject+3 more6Bind Debian LinuxFedora+3 moreNov 21, 2024 Jun 17, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or mor...Show more |
4Canonical IscNetapp+1 more4Bind LeapSteelstore Cloud Integrated Storage+1 moreNov 21, 2024 Jun 17, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients. |
4Debian FasterxmlNetapp+1 more14Active Iq Unified Manager Agile PlmBanking Digital Experience+11 moreNov 21, 2024 Jun 16, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity). |
3Debian NetappOpenjsf6Active Iq Unified Manager Debian LinuxDijit+3 moreNov 21, 2024 Jun 15, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8, and greater than or equal to 1.14.0 and less than 1.14.7, and greater...Show more |